The Frameworks Behind the Programs

Regulated businesses face a growing list of requirements, and it’s rarely obvious which ones actually apply. Here’s what each major framework requires, how our virtual CISO services — also called fractional CISO or outsourced CISO — apply it to your environment, and how Amelia Island Tech’s Harbor, Beacon, and Lighthouse programs deliver it on an ongoing, documented basis.

Schedule a Compliance Scoping Call

Frameworks We Work Against

CMMC 2.0 Compliance Consultant & Readiness

Level 2 becomes a mandatory contract requirement for Department of Defense contractors and subcontractors in November 2026. We scope your assessment boundary, run the CMMC gap analysis, remediate gaps, and document your path to certification before the deadline becomes a crisis.

Start Your CMMC Timeline →

FTC Safeguards Rule Compliance

Financial institutions and non-bank entities handling consumer financial information must maintain a written information security program. We build the risk assessment, safeguards program, and vendor oversight process the Rule requires.

Assess Your Safeguards Program →

GLBA IT Compliance

The Gramm-Leach-Bliley Act requires financial services firms to protect nonpublic personal information (NPI) with administrative, technical, and physical safeguards. We map your current controls against GLBA requirements and close the gaps.

Review Your GLBA Posture →

SOC 2 Readiness Assessment

When customers and partners ask for proof of your security controls, SOC 2 is the answer. We take you from gap assessment through audit-ready documentation, so the audit itself is a formality.

Get Audit-Ready →

NIST CSF Implementation

Not every business has a specific regulatory mandate — but every business benefits from a defensible security posture. We use the NIST Cybersecurity Framework as a baseline to identify, protect, detect, respond, and recover.

Build Your NIST Baseline →

IT Audit & Readiness Assessments

Not every engagement starts with a framework — sometimes you just need an independent set of eyes on your controls. We run fixed-fee IT audit services: IT general controls (ITGC) audits, SOC 2 readiness reviews, CMMC gap audits, vendor risk audits, and M&A IT due diligence. Each engagement produces a documented findings report your leadership, auditors, or insurers can act on.

Scope Your IT Audit →

Cyber Insurance Compliance Requirements

Carriers increasingly tie coverage and premiums to specific controls — MFA, EDR, backup testing, and documented incident response. We help you meet cyber insurance compliance requirements before renewal, so the questionnaire doesn’t become a scramble.

Prep for Your Renewal →

We also support NIST SP 800-171, ISO 27001, PCI-DSS, and ABA cybersecurity guidance depending on your industry and contractual obligations — each delivered as part of a broader GRC (governance, risk & compliance) program rather than a one-time checklist.

How This Fits Into Your Program

Framework work doesn’t happen in isolation — it’s delivered as part of our managed GRC (governance, risk & compliance) services, through your Harbor, Beacon, or Lighthouse engagement, with Lighthouse including full compliance program management across all of the frameworks above. See the full service line breakdown for how it all connects.

Compare Harbor, Beacon & Lighthouse →

Is a Virtual CISO Right-Sized for You?

A vCISO for small business works the same way a fractional CFO does elsewhere in the company: you get executive-level security leadership for a fraction of a full-time salary. Common signs it’s time to hire a vCISO include a new compliance deadline, an insurer or client requiring named security ownership, or simply not having anyone internally responsible for the security program. vCISO pricing is scoped to the size of your environment and the framework you’re working against — most clients see it bundled into their Beacon or Lighthouse program rather than billed as a separate line item.

Not Sure Which Framework Applies to You?

Most businesses aren’t — that’s what the first conversation is for. We’ll walk your environment against the same documented checklist every time, regardless of who’s on the call.

Schedule a Compliance Scoping Call