The phrase is doing a lot of work, and not always honestly
“Compliance-ready” turns up in a great deal of technology marketing, including ours, and it is worth being precise about what it can and cannot mean for an organization of about twenty people.
It does not mean certified. It does not mean somebody has audited you. And for most businesses this size, it should not mean either of those things, because certification is expensive, slow, and usually irrelevant unless a specific customer or regulator is requiring it of you by name.
What it should mean is narrower and considerably more useful: that when somebody asks how you handle their information, you can anaswer accurately, and you can show your working.
Who is actually asking
Notice that the pressure here is rarely a regulator knocking on the door. For an organization your size it usually arrives from one of four directions.
- A larger client sends a vendor security questionnaire before they will sign, because their own compliance obligations now flow down to their suppliers.
- An insurer asks detailed questions at renewal about access controls, backups, and what happens when staff leave.
- A funder or grantmaker adds a data-handling section to reporting, particularly where the work touches vulnerable people.
- Your own board or leadership asks the question directly, usually after hearing about something that happened to a peer organization.
None of those parties is going to audit you. All four want the same thing, which is evidence that somebody has thought about this and can describe the arrangements without improvising.
The four questions underneath nearly every form
Vendor questionnaires vary enormously in length and hardly at all in substance. Strip out the phrasing and you are almost always being asked four things.
Who can get to what, and how do you know
Which people have access to which systems and information, how that access is granted, and how it is removed. The removal half is where most organizations are weakest, because granting access is prompted by somebody needing it and removing it is prompted by nothing at all. This is the same gap we walked through in why MFA alone does not close it.
What happens if something is lost
Not whether you have backups. Whether you have restored from one recently enough to be confident it works, and how long getting back would realistically take. An answer with a tested date in it reads completely differently from an answer that says backups run nightly. This is really a question about your data backup process rather than whether one exists.
Where the sensitive information actually lives
Which systems hold client, patient, donor, financial, or staff data, who the providers are, and what happens to it when a relationship ends. Most organizations underestimate this list, because it has grown one tool at a time.
Who else is in the chain
Your suppliers hold your data too. The payroll provider, the case management system, the cloud storage. Being asked about your vendors is now routine, and it means keeping some record of who they are and what they hold.
Readiness is mostly documentation, not technology
Here is the part that surprises people, and it is the most encouraging thing in this post.
Most twenty-person organizations are already doing a reasonable amount of the substance. Access is broadly controlled. Backups are running. Sensible people are making sensible decisions. What is missing is not the practice. It is the record of the practice, and the ability to produce that record inside a week when somebody asks for it.
That gap is why this month’s theme keeps surfacing here too. Writing things down, keeping them current, and reviewing them on a cycle is continuous work with no completion date, which is precisely the kind of work that loses to whatever is urgent when one person is doing technology alongside another job. We laid out a version of that math in what internal IT really costs earlier this month.
Where the frameworks fit
You will see specific names on these forms: HIPAA if you handle health information, PCI-DSS if you take card payments, SOC 2 if you sell to larger companies that require it of suppliers.
Two honest points about them. First, which ones apply to you is determined by what you do and who your customers are, not by what is fashionable, and a provider who cannot tell you which ones are irrelevant to your business is not being straight with you. Second, there is a real difference between working in line with a framework’s expectations and being formally certified against it. Both are legitimate. They cost very different amounts, and you should know which one is actually being asked of you before anyone spends money.
Our practices are built to be HIPAA-aware, and our team holds Microsoft and CompTIA credentials, backed by ongoing cybersecurity work and steady network management behind the scenes. You can see the full list on our partners and certifications page. Where a specific certification is genuinely required of you, we will say so plainly, including when the honest answer is that it needs a specialist rather than us.
Making it defensible upward
If you are the person who has to take this to a board, a director, or an owner, the useful output is not a technology plan. It is a short document that says what you have in place, what you are choosing not to do and why, what it costs, and what changes as you grow.
That framing tends to survive the meeting, because it presents a decision that was made rather than a gap that was found. Our compliance services page sets out the pieces that usually go into it, including access controls, encrypted backups, documented policies, and the kind of evidence that holds up in a client security review. Our managed IT services and IT guidance work both feed directly into that document. We are glad to walk through it with you and help you put your own version together.
Where to start, no obligation
CMIT Solutions of Austin East works with professional services firms and nonprofits across East Austin, Round Rock, Pflugerville, Manor, Elgin, Cedar Park, and Bastrop. Our free thirty-minute IT assessment covers the four questions above and gives you an honest read on how you would answer them today. Our IT support team is happy to walk you through it either way.
If you are in better shape than you feared, we will tell you. Call (512) 399-2982 or reach out online.
Request Your Free IT Assessment


