CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
      • IT Help Desk
      • 24/7 Emergency Support
      • Co-Managed IT
    • Cybersecurity
      • Network Security
      • Managed Firewall
      • Email Security
      • Phishing Protection
      • Security Awareness Training
      • Dark Web Monitoring
      • Penetration Testing
    • Business Continuity & Disaster Recovery (BCDR)
      • Backup & Disaster Recovery
      • Microsoft 365 Backup
      • Cloud Disaster Recovery
      • Backup & DR Audit
    • Cloud Services
      • Microsoft 365
      • Microsoft Azure
      • Cloud Migration
      • SharePoint
      • Virtual Desktop
    • Compliance
      • SOC 2
      • HIPAA
      • CMMC
      • NIST CSF
      • PCI DSS
      • FTC Safeguards
      • CIS Controls
      • Cyber Insurance
      • Compliance Audit
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Virtual CTO & CIO Services
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Texas Breach Notice Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Three interlocking gears representing the IT provider, the business and the outside auditor in a compliance process
Shane Stevens
Shane Stevens October 5th, 2026

Which Compliance Rules Apply to a Houston Small Business?

A Plain Guide To Compliance Rules For Houston Small Businesses – The Controls Are Running. Can You Prove It?

Houston Compliance Guide
Which Compliance Rules Apply to a Houston Small Business? The Same Few Controls Sit Under Every Rulebook.

Which rules reach a Houston business your size, what each one asks for, and how much of it an IT provider can carry.

TL;DR
A Houston business picks up compliance rules from the data it holds and the customers it serves. HIPAA, PCI DSS, SOC 2, CMMC, NIST CSF and the FTC Safeguards Rule each ask for proof of the same core IT controls. An IT provider runs those controls. Auditors, assessors and attorneys sign off.
🧭 Which Rules Apply 🏥 HIPAA 💳 PCI DSS 📄 SOC 2 🛡️ CMMC 🧱 NIST CSF 🧾 FTC Safeguards 📑 Insurance and Texas Law 🚀 How CinchOps Helps

Which compliance rules apply to a Houston small business depends on the data the business holds and the customers it serves. HIPAA, PCI DSS, SOC 2, CMMC, the NIST Cybersecurity Framework and the FTC Safeguards Rule each ask for proof of the same technical controls: access, encryption, monitoring, backups and written evidence.

The request usually arrives sideways. A customer's vendor questionnaire, a cyber insurance renewal form or one line in a contract names a rule the owner has never read, and a deadline comes with it. Two questions follow every time: which rules reach a company this size, and how much of the work an IT provider can carry.

CinchOps provides compliance services specifically for regulated businesses with 10 to 200 employees in the Houston area, covering the IT controls behind 7 rulebooks with 24/7 threat monitoring and a named engineer who knows the network.

The gap shows from the outside. The CinchOps Houston Area Security Index graded 4,393 small and mid-sized businesses on external security signals, and 49.6% earned a D or an F.

BY THE NUMBERSCompliance at a Glance for Houston Businesses8rulebooks a Houstonbusiness commonly meets49.6%of 4,393 Houston SMBsgraded D or F on security30 daysto notify the Texas AGwhen 250+ Texans are affected60 daysto notify patientsafter a HIPAA breachCinchOps · cinchops.com
The short version: Pick your rulebooks by the data you hold and who is asking, run one set of controls under all of them, and keep the evidence. The CinchOps compliance services page lists each rulebook, and a compliance audit is the fastest way to see where you stand.

What Decides Which Compliance Rules Apply?

The data you hold and the customers you serve decide the list. Headcount does not.

A Houston small business falls under a compliance rule because of the data it holds or the customer it serves, whatever its headcount. Patient records bring HIPAA, card payments bring PCI DSS, tax and lending work brings the FTC Safeguards Rule, and Department of Defense contracts bring CMMC.

Most regulated businesses answer to more than one. A CPA practice in Sugar Land that takes card payments and carries a cyber policy has three sets of requirements before any customer sends a questionnaire. In onboarding audits, CinchOps regularly finds Houston businesses that prepared for one rulebook and never noticed a second one applied.

The table below lists 8 rulebooks a Houston business commonly meets, the event that brings each one into play, and the party that asks for proof.

COMPLIANCE MAP Which Rulebook Reaches Your Business Rulebook It reaches you when Who asks for proof HIPAA You handle patient health information HHS Office for Civil Rights PCI DSS You store, process or transmit card data Your acquiring bank SOC 2 A customer asks for an audit report An independent CPA firm CMMC You hold Defense Department contract data Department of Defense NIST CSF A customer or insurer asks what you follow Nobody - it is voluntary FTC Safeguards Rule You prepare taxes or run a covered financial firm Federal Trade Commission Cyber insurance You apply for or renew a policy Your carrier's underwriter Texas breach law You hold Texans' sensitive personal data Texas Attorney General CinchOps · cinchops.com

Two rows on that map are not laws. SOC 2 is a report a customer asks for, and the NIST Cybersecurity Framework is voluntary. Both still decide contracts, because a buyer or an insurer can make either one a condition of doing business.

HIPAA Covers the Practice and Every Vendor That Touches Patient Data

For Houston medical, dental and specialty practices, and the firms that serve them.

HIPAA is the federal law that protects patient health information, and its Security Rule requires administrative, physical and technical safeguards for electronic records. The law applies to healthcare providers in Houston and to their business associates, which includes an IT provider with access to systems that hold patient data.

The U.S. Department of Health and Human Services says a practice may share patient data with a vendor only after it obtains a written business associate agreement. Ask any IT provider for that agreement before granting access. CinchOps signs one with its healthcare clients. After a breach, HIPAA sets a clock: affected individuals are notified within 60 days of discovery, and a breach involving 500 or more people is reported to HHS within the same 60 days.

HIPAA CLOCKWhat HIPAA Expects Before and After a BreachBefore accessA signed business associateagreement with every vendorWithin 60 daysAffected individuals notifiedafter the breach is discoveredSame 60 daysHHS notified when 500 ormore people are involvedCinchOps · cinchops.com

The IT work under HIPAA is specific. CinchOps performs and updates the security risk analysis, encrypts patient data at rest and in transit, gives every person a unique login with least-privilege access, and keeps the evidence ready for an Office for Civil Rights request. Details are on the HIPAA compliance for Houston healthcare page.

PCI DSS Applies the Day You Accept a Card Payment

For any Houston business that takes credit or debit cards, at a counter, online or over the phone.

PCI DSS is the payment card industry's data security standard. The standard applies to every business that stores, processes or transmits cardholder data, whatever its size, and PCI DSS v4.0.1 has been the only active version since the PCI Security Standards Council retired v4.0 on 31 December 2024.

Scope decides the cost. Every system that can reach card data falls inside the assessment, so the cheapest PCI project is the one that shrinks that set first. CinchOps maps where card data enters, moves and rests, then segments payment systems away from the office network so fewer machines are in scope.

PCI SCOPEScope Decides the Cost of PCI DSSMapTrace where card dataenters, moves and restsSegmentIsolate payment systemsfrom the office networkResultFewer machines fallinside the assessmentCinchOps · cinchops.com

Card brands also set their own clocks. Visa's current guidance requires a suspected or confirmed compromise to be reported within 3 calendar days. The scanning, monitoring and documentation an acquiring bank asks for are covered on the PCI DSS compliance for Houston businesses page.

SOC 2 Is a Customer Requirement, and an Auditor Issues the Report

For Houston software, services and data-handling firms selling to larger customers.

SOC 2 is an independent auditor's report on a service organization's controls, built on 5 trust services categories: security, availability, processing integrity, confidentiality and privacy. No law requires SOC 2. Houston businesses meet it when a customer's vendor-risk team asks for the report as a condition of a contract.

An IT provider cannot issue a SOC 2 report, and neither can the business being audited. A CPA firm examines the controls and writes the opinion. What an IT provider does is run the technical controls the auditor will test, such as access reviews, patching, monitoring and backup, and produce the records that show each one happened on schedule.

SOC 25 Trust Services Categories in a SOC 2 ReportSecurityAvailabilityProcessing integrityConfidentialityPrivacyExamined and reported by an independent CPA firmCinchOps · cinchops.com

Most of the effort is evidence. A control that ran every week but left no record counts for nothing in an audit. The split between what your company owns and what your IT provider owns is laid out in what SOC 2 requires from your Houston IT provider.

Not sure which rulebooks apply to you?

A short conversation sorts the list by the data you hold and the customers you serve.

Talk to CinchOps

CMMC Follows the Contract Into Your Network

For Houston manufacturers, fabricators and engineering firms in the defense supply chain.

CMMC is the Department of Defense program that verifies contractors protect federal contract information and controlled unclassified information. Level 1 of CMMC carries 15 security requirements, and under 32 CFR 170.14 the Level 2 requirements are identical to NIST SP 800-171 Revision 2.

A Houston machine shop does not need a contract with the Pentagon to be covered. The requirement flows down from a prime contractor to its suppliers, and it arrives with the data: a controlled drawing in an inbox puts the systems that store it in scope. CMMC has been phasing into defense contracts since November 2025, and the rollout schedule has shifted along the way, so read the clause in your own contract before planning around a published date.

CMMC FLOW-DOWNThe Requirement Follows the Contract DataDepartment of DefenseWrites the requirementinto the contractPrime contractorPasses it down toevery supplierHouston supplierSystems that store thedata are in scopeLevel 1: 15 requirements · Level 2: identical to NIST SP 800-171 Revision 2CinchOps · cinchops.com

CinchOps starts by defining where contract data lives and keeping that boundary small, then assesses the environment against NIST SP 800-171 and documents every gap in a system security plan. The CMMC compliance for Houston DoD contractors page covers the process, and this guide for Houston manufacturers covers the cost question.

The NIST Cybersecurity Framework Is Voluntary, and Texas Rewards Using It

For any Houston business that needs a recognized structure for its security program.

The NIST Cybersecurity Framework is a voluntary guide from the National Institute of Standards and Technology for managing cybersecurity risk. CSF 2.0, released February 26, 2024, is organized around 6 functions: Govern, Identify, Protect, Detect, Respond and Recover, and it is written for organizations of every size.

Texas gives a small business a reason to adopt one. Texas SB 2610, in effect since September 1, 2025, bars exemplary damages in a breach lawsuit against a business with fewer than 250 employees that maintained a conforming cybersecurity program. The bar rises with size: password policies and training below 20 employees, CIS Controls Implementation Group 1 from 20 to 99, and a recognized framework such as NIST from 100 to 249. The protection has to be in place before the breach, and compensatory damages are not affected.

TEXAS SB 2610What Texas SB 2610 Asks by Company SizeFewer than 20 employeesPassword policiesand training20 to 99 employeesCIS ControlsImplementation Group 1100 to 249 employeesA recognized frameworksuch as NISTCinchOps · cinchops.com

CinchOps maps a client's real environment to the 6 functions, ranks the gaps, and then operates the controls month after month. See NIST Cybersecurity Framework for Houston businesses and the plain-language walkthrough of Texas SB 2610.

The FTC Safeguards Rule Reaches CPA Firms and Other Financial Businesses

For Houston tax preparers, CPA practices, lenders and other covered financial firms.

The FTC Safeguards Rule requires covered financial institutions to keep a written information security program. Federal Trade Commission guidance names tax preparation firms among them, and the rule requires multi-factor authentication for anyone accessing customer information, plus encryption of that information on your systems and in transit.

The rule also names a person. A Qualified Individual owns the program and reports to the board at least annually. Since May 2024, a security event involving the unencrypted information of 500 or more consumers must be reported to the FTC no later than 30 days after discovery.

FTC SAFEGUARDSWhat the FTC Safeguards Rule RequiresWritten programAn information securityprogram on paperMFAFor anyone accessingcustomer informationEncryptionOn your systemsand in transit30 daysTo report an event affecting500 or more consumersCinchOps · cinchops.com

Houston accounting practices have ground to make up. In the CinchOps Houston Area Security Index, CPA practices ranked last of 5 industries, with a 1.32 GPA and 55.5% earning a failing grade on external signals. CinchOps builds the written program, puts the named controls in place and supports the Qualified Individual role. See FTC Safeguards Rule compliance for Houston businesses.

Cyber Insurance and Texas Law Add Two More Sets of Proof

For every Houston business that carries a cyber policy or holds personal data on Texans.

Cyber insurance is a contract, and its application works as a security questionnaire: the carrier asks which controls are in place and relies on the answers. Texas law adds a breach notice duty. Individuals are notified within 60 days, and the Texas Attorney General within 30 days when at least 250 Texas residents are affected.

An application answered from memory is a liability. Answering yes to a control that is not fully deployed gives a carrier grounds to contest a claim later. CinchOps puts multi-factor authentication on email, remote access and privileged accounts, deploys monitored endpoint detection, keeps immutable offsite backup copies, and backs each answer with evidence. The cyber insurance readiness for Houston businesses page covers the controls underwriters ask about first.

CYBER INSURANCEControls Underwriters Ask About FirstMFAEmail, remote access andprivileged accountsEndpoint detectionDeployed andmonitoredBackupsImmutable copieskept offsiteEvidenceA record behindevery answerCinchOps · cinchops.com

The Texas statute carries its own penalties, from $2,000 to $50,000 per violation. Notice decisions belong with an attorney and the insurance carrier. The IT provider's part is knowing, quickly and with logs to prove it, what was accessed and when.

Every one of these rulebooks asks the same thing in different words: show me. Most Houston businesses we audit already run half the controls. What they can't do is hand over the proof.
Shane Stevens, CEO, CinchOps - LinkedIn

One Team for the IT Side of Every Rulebook

CinchOps runs the controls behind HIPAA, PCI DSS, CMMC, NIST CSF and the FTC Safeguards Rule and keeps the evidence. Most engagements start with a compliance audit that maps your controls and ranks every gap.

See CinchOps compliance services

How CinchOps Can Help With Compliance in Houston

CinchOps is a managed IT services provider based in Katy, Texas, serving small and mid-sized businesses across the Houston metro area. CinchOps specializes in cybersecurity, network security, managed IT support, VoIP, and SD-WAN for businesses with 10 to 200 employees.

No IT provider can make a business compliant alone, and one that says otherwise is selling a logo. CinchOps is not a law firm, an audit firm or a CMMC assessor. The work splits three ways, shown below.

WHO DOES WHAT Three Parties Share Every Framework CinchOps runs Multi-factor authentication Patching and hardening 24/7 threat monitoring Immutable offsite backups Evidence collection Your business owns Policies and sign-off Staff following the policies Vendor contracts The risk you choose to accept An outside party signs The auditor's SOC 2 opinion The CMMC assessment result The carrier's coverage terms An attorney's legal advice CinchOps · cinchops.com
  • Compliance services bring the rulebooks together: one team runs the controls behind HIPAA, PCI DSS, CMMC, NIST CSF and the FTC Safeguards Rule, and keeps the evidence.
  • Through managed IT support, a named engineer who knows your network keeps patching, access and device standards current, the routine work every framework checks.
  • Cybersecurity services add 24/7 threat monitoring, so the detection and response sections of a questionnaire have a real answer.
  • Business continuity and disaster recovery keeps immutable, verified backup copies offsite, the control ransomware and insurers both test first.
  • Industry pages cover the rulebooks by vertical: CPA firms, manufacturing and wealth management.
  • Local coverage runs from Houston and Katy to Sugar Land and The Woodlands.

CinchOps works on Zero-Zero-Zero terms: no long-term contracts, no hidden fees, no cancellation penalties. If a questionnaire, a renewal form or a contract clause just landed on your desk, start with the list of rules that apply and work backward from the proof each one wants. Then talk to CinchOps about the IT half.

100% Free

Know Your Business Security Score

Get a FREE comprehensive security assessment for your Houston area business. Understand vulnerabilities across your network, applications, DNS, and more.

Get Your Free Assessment

Frequently Asked Questions

Which compliance regulations apply to a small business in Houston?

The answer depends on the data the business holds. Patient records bring HIPAA. Card payments bring PCI DSS. Tax preparation and lending bring the FTC Safeguards Rule. Department of Defense contracts bring CMMC. Customers may ask for SOC 2, and Texas breach notice law applies to any business holding sensitive personal information on Texans.

What should a HIPAA compliant IT provider in Houston offer?

A HIPAA compliant IT provider in Houston signs a business associate agreement before touching patient systems, then runs the Security Rule's technical safeguards: a current risk analysis, encryption, unique logins and access logs. CinchOps does this work for Houston healthcare practices and keeps the evidence ready for an Office for Civil Rights request.

What do compliance services cost in Houston?

Compliance work has no single price, because the scope depends on which rules apply and what an audit finds. CinchOps quotes readiness work after that audit. For reference, the published CinchOps rate for managed IT and security is a flat $100 to $250 per user per month. Auditor, assessor and attorney fees are separate.

Can a managed IT provider make my business compliant?

No single party can. A managed IT provider runs the technical controls and collects the evidence. The business owns its policies, its staff behavior and its risk decisions. An outside party signs off: a CPA firm for SOC 2, an assessor for CMMC, an underwriter for cyber insurance. CinchOps handles the first part.

What are the cyber insurance requirements for IT support in Houston?

Cyber insurance applications ask an IT team to prove specific controls. The questions CinchOps sees most on Houston renewals cover multi-factor authentication on email and remote access, monitored endpoint detection, offline or immutable backups, and patching. Each yes on the form should be backed by a record that shows the control is running.

Does CinchOps provide PCI compliance IT support for Houston small business?

Yes. CinchOps provides PCI compliance IT support for Houston small businesses that accept card payments. The work covers mapping where card data flows, segmenting payment systems to reduce scope, putting the PCI DSS v4.0.1 authentication, scanning and monitoring controls in place, and preparing the documentation an acquiring bank requests.

Discover More

What SOC 2 Actually Requires From Your Houston IT Provider
Can a Houston Manufacturer Pass CMMC Without a Compliance Hire?
FTC Safeguards Rule Requirements for 10 to 50 Employee CPA Firms in Houston
Texas SB 2610: The Cybersecurity Safe Harbor Every Houston SMB Should Know About
9 Things to Do After Your Cyber Insurance Renewal Questionnaire Arrives
Security Compliance: What Regulations Mean for Your IT Infrastructure

Resource

Infographic: which compliance rules apply to a Houston small business, including HIPAA, PCI DSS, FTC Safeguards and CMMC, reporting timelines, and the three parties that share the work
Which Compliance Rules Apply to a Houston Small Business Open Full Size

Sources

  • U.S. Department of Health and Human Services - Summary of the HIPAA Security Rule
  • HHS Office for Civil Rights guidance - Business Associates
  • HHS - Breach Notification Rule
  • PCI Security Standards Council - PCI DSS
  • PCI Security Standards Council - Just Published: PCI DSS v4.0.1 (June 11, 2024)
  • Visa - What To Do If Compromised, Version 10.0 (effective June 25, 2026)
  • AICPA and CIMA - SOC 2: Reporting on Controls at a Service Organization
  • 32 CFR 170.14 - CMMC Model (Cornell Legal Information Institute)
  • Black Kite Research Group - 2026 Manufacturing and Distribution Ransomware Report
  • NIST - NIST Releases Version 2.0 of Landmark Cybersecurity Framework (February 26, 2024)
  • Texas Legislature - SB 2610, enrolled text (89th Regular Session)
  • Federal Trade Commission - FTC Safeguards Rule: What Your Business Needs to Know
  • Texas Business and Commerce Code, Chapter 521 - Sections 521.053 and 521.151
  • CinchOps - Houston Area Security Index 2026
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

July 23rd, 2026
AI Governance Houston
AI Governance for Small Business: A Practical 2026 Guide

Real Guidance For Real Businesses – How Houston Small Businesses Actually Govern AI

March 20th, 2026
Construction Cybersecurity
What Cybersecurity Threats Are Unique to Construction Companies, and How Do MSPs Protect Against Them?

Why Construction Firms Need Industry-Specific IT Security – Why Ransomware Attackers Love Targeting Contractors

October 7th, 2025
Managed Service Provider Houston Cybersecurity
Comcast 2025 Cybersecurity Threat Report: What Houston Businesses Need to Know

From Reconnaissance To Ransomware: Understanding The Four Stages Of Modern Cyber Attacks – How Attackers Use AI, Proxies, And Valid Accounts To Breach Houston Companies

July 16th, 2026
IT Support Houston
24/7 Help Desk in Houston: Does Your Business Need One?

Match Your IT Coverage To How Your Business Actually Runs

October 23rd, 2025
Managed Service Provider Houston Cybersecurity
2025 Cybersecurity Threats Demand Immediate Action for Houston Businesses

Phishing Continues As Most Common Initial Access Method For Cyberattacks – Study Reveals Attackers Maintain Undetected Network Access For Approximately Two Weeks On Average

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Business Continuity & Disaster Recovery
  • Cloud Services
  • Compliance
  • Virtual CTO & CIO
  • Business Process Automation
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy