Compliance Is a Pulse, Not a Cycle
March 24, 2026 · 14 min read
“All problems in computer science can be solved by another level of abstraction.” — David Wheeler
Most of what an operator calls “compliance” isn’t a regulatory obligation. It’s a commercial one. For small and mid-market businesses — roughly, anyone under 2,500 employees and under a billion in revenue — the binding constraint on the security investment calendar is not what a regulator demands. It’s what your customers, their insurers, and their acquirers demand, in ways that recur every quarter and recompose every eighteen months as the frameworks shift.
This is a different problem than the one the compliance industry was built to solve. The industry was built around annual attestations: the auditor comes in, runs a scope, issues a report, and leaves. The SOC 2 Type II in the drawer is the artifact. The ISO 27001 certificate on the wall is the artifact. The idea was that compliance is a cycle — once a year, you close the books.
That model no longer describes how compliance actually operates on a mid-market business. Compliance is now a pulse. It fires on a mix of contracted schedules (your vendor reassessment every quarter), event triggers (an incident at your largest customer, which triggers a reassessment of every vendor), and calendar deadlines (the new CMMC Level 2 requirement that lands on November 10, 2026, or the PCI-DSS v4.0.1 provisions that have been mandatory since March 2025, or the next state privacy law that takes effect January first). You cannot close the books on compliance in 2026 because the books keep being re-opened by actors outside the regulator.
Understanding this shift — and what it demands of an operator’s infrastructure — is the difference between running a security program that clears deals and running one that keeps losing them.
How compliance pressure actually reaches a small operator
Start with the mechanism. Look at who forces what, in practice, on a non-regulated small business in 2026.
The direct regulator is rarely the lead actor. The Federal Trade Commission’s amended Safeguards Rule now imposes a thirty-day breach-notification requirement on non-bank financial institutions, and that matters if you’re a fintech or a tax preparer, but it doesn’t reach most SMBs. The HHS Office for Civil Rights announced twenty-two HIPAA enforcement actions in 2024 totaling $9.9 million in civil monetary penalties — up from sixteen actions the prior year — but those penalties land on covered entities and business associates, not on the SaaS vendor three layers down who happens to touch healthcare data. The SEC’s cyber disclosure rule, which requires 8-K filings within four business days of a material incident, produced roughly $7 million in settled enforcement against four SolarWinds-affected companies in October 2024 — but the direct addressee is a public company, not the private supplier the public company contracts with.
What reaches the operator is the cascade of those regulator obligations. And the underlying pressure is not subtle: the Verizon 2025 Data Breach Investigations Report found that the share of breaches involving a third party doubled year over year, from 15 percent to 30 percent. That doubling is what drives everything that follows. A Fortune 500 public company is now on the hook for a four-day materiality disclosure, and its general counsel reads that doubling as a reason to tighten every contract it offers to a vendor. The contract language now includes specific clauses: access controls, encryption at rest and in transit, breach notification within twenty-four or seventy-two hours, sub-processor approval, right to audit, data location restrictions, exit obligations, limits on AI use. The New York Department of Financial Services’ October 2025 industry letter enumerates exactly these clauses as expected practice for its regulated entities. The mid-market supplier, in turn, passes these obligations to its own sub-vendors, and so the pressure propagates downward until it terminates on a small business that nobody at the SEC has ever heard of but which is now contractually obligated to maintain controls commensurate with a publicly-traded customer four layers up the chain.
This cascade explains more of the compliance burden on a small operator than any single regulator does. The best empirical estimate we have comes from the FTI Consulting CISO Redefined III report, published March 2026, which surveyed 278 senior leaders (100 CISOs, 78 heads of M&A, 100 general counsel) at firms of $500 million market capitalization and up — a sample skewed toward upper-mid-market and enterprise, with direct relevance to how acquirers, customers, and partners treat smaller vendors in their orbit. The pattern across that sample, combined with West Monroe’s ongoing due-diligence research and the adoption data from the trust-platform ecosystem, is that roughly seventy percent of the compliance pressure on a non-regulated small or mid-market business is deal-driven rather than regulator-driven. Regulator-driven pressure sets a floor. Deal-driven pressure sets the actual calendar, the actual scope, and the actual investment level. For regulated businesses — healthcare business associates, financial sub-processors, defense contractors — the regulator share rises, but the deal-driven share does not fall.
The second cascade: insurance
There is a second pressure mechanism that compounds the commercial cascade and that most operators underweight. Cyber liability insurance.
A cyber insurance carrier in 2026 no longer writes a policy on the basis of a questionnaire alone. The carrier demands evidence — screenshots of MFA enrollment reports, logs showing backup restore tests within the last twelve months, attestation of EDR coverage across endpoints, documentation of a tested incident response plan. Cyber policy applications across the market now include MFA-specific questioning as a matter of course, and carriers impose sub-limits or outright exclusions when the evidence is weak — particularly for ransomware, unpatched known CVEs, unencrypted data at rest, and privileged accounts without phishing-resistant multi-factor authentication.
The carrier also asks the insured about its vendors’ controls. If a small business’s enterprise customer has weak vendor governance, the enterprise customer’s cyber policy premium rises. So the enterprise customer tightens its vendor mandates to control its own premium. The insurance pressure therefore runs through two mechanisms simultaneously: direct pressure on the small business’s own policy, and indirect pressure through the customer’s policy.
West Monroe found that 63 percent of dealmakers cite representations-and-warranties insurance as among the most important protections for mitigating data-security risk in an acquisition. The R&W carrier evaluates target cyber posture during underwriting and carves out cyber reps or imposes heightened retentions when posture is weak. An R&W carve-out for cyber is, in practice, a deal modifier. A target’s weak MFA or unencrypted at-rest data doesn’t just increase the actuarial risk; it reduces the acquirer’s insurance coverage against that risk, which reduces the price the acquirer is willing to pay for the target.
The third cascade: due diligence
The third pressure is the acquirer’s technical and cyber due diligence itself. This is where the biggest single discoveries of the last five years have lived.
The Change Healthcare ransomware incident of February 2024 is the current fear case. UnitedHealth Group acquired Change Healthcare for approximately $13 billion, closed in October 2022. In February 2024, attackers compromised a Citrix remote-access portal that did not have multi-factor authentication enabled, exfiltrated protected health information affecting 192.7 million individuals, and inflicted approximately $2.5 billion in total impact on UnitedHealth through the third quarter of 2024 alone. CEO Andrew Witty testified before the Senate Finance Committee in May 2024 that the compromised Change Healthcare systems “dated back 40 years” and that UnitedHealth had been “in the process of upgrading and modernizing” the acquired infrastructure — which is the polite version of our pre-acquisition cyber due diligence missed it.
Change Healthcare has reshaped how PE and strategic acquirers do cyber due diligence on mid-market targets. The FTI survey cited earlier found that twenty-five percent of leaders experienced a cyber incident during or shortly after a deal, forty-two percent saw significant deal value reduction, fifty-eight percent saw impaired financial targets, and twenty percent had deals delayed or paused outright. West Monroe’s own due-diligence research finds that 77 percent of dealmakers have never walked from a deal purely on cyber grounds — which means the overwhelmingly dominant outcome when posture is weak is repricing and escrow holdbacks, not collapse. The deal closes. The price adjusts. The seller absorbs the adjustment through lower proceeds or specific indemnities.
The canonical case for price adjustment, still cited in every PE deal book, is Verizon’s 2017 acquisition of Yahoo. The original $4.83 billion deal reduced by $350 million after two previously undisclosed 2013 and 2014 breaches surfaced during due diligence. The price adjustment reflected the uncertainty of long-tail legal liability. Since then, the shape of the adjustment has changed — today it’s less often a lump-sum reduction and more often a combination of escrow holdback, reps-and-warranties insurance carve-out, and specific cyber indemnity — but the underlying mechanism is identical. Material cyber findings translate into deal economics.
The math on that mechanism is blunt. A $10 million EBITDA target at a six-times multiplier is a $60 million valuation. A documented need for a $1 to $2 million annual remediation program — security tooling, added staffing, audit remediation — flows through as recurring operating expense and trims $6 to $12 million off the valuation. EBITDA adjustments are multiplied by the purchase multiple, and mid-market multiples in 2026 are higher than they were five years ago, which makes the sensitivity to cyber findings correspondingly higher.
What the pulse actually looks like
These three cascades — commercial, insurance, and acquisition — each have their own pulse. The union of their schedules is what an operator experiences as “compliance.”
The commercial cascade pulses on the reassessment cadence your largest customers impose. The 2025 update to the Shared Assessments SIG questionnaire introduced dedicated Governance controls and mappings to DORA, NIS2, and NIST CSF 2.0. The SIG Core questionnaire contains 627 questions; SIG Lite contains 128; SIG Detail contains 1,936. The CAIQ v4 from the Cloud Security Alliance contains 261 questions across seventeen control domains. Critical vendors — those with privileged access or sensitive data — are now reassessed quarterly at most Fortune 500 organizations. High-risk vendors are reassessed semi-annually. Low-risk vendors are reassessed annually. These are periodic assessments, not one-time events. Between them, continuous-monitoring ratings from BitSight and SecurityScorecard are watched in real time, and a rating drop from a B to a C can trigger an unplanned reassessment that lands on the operator with days, not weeks, of notice.
The insurance cascade pulses on policy renewal, which is annual, and on claim-triggering events, which are unpredictable. Renewals in 2026 are increasingly demanding evidence artifacts — the screenshots, logs, restore-test results mentioned earlier — rather than questionnaire answers. The operator who can hand the carrier a packaged evidence bundle at renewal keeps the policy. The operator who cannot is uninsurable or pays a premium that prices their services out of the market.
The due-diligence cascade pulses on deal events. The operator can go eighteen quiet months and then spend the next six weeks in a PE firm’s data room, responding to cyber DD requests, hoping that the controls they have look the way the DD team expects them to look. A deal can pass or fail on whether the answer to ten specific questions is yes. MFA enforced on all privileged and remote access. EDR on at least ninety-five percent of endpoints with twenty-four seven monitoring. Immutable offsite backups with a documented restore test within the last twelve months. No critical CVEs unpatched for more than thirty days on internet-facing assets. A tested incident response plan with at least one tabletop in the past twelve months. A written third-party risk management program with an actual vendor inventory. A SOC 2 Type II, or ISO 27001:2022, or a clean third-party penetration test with a remediation log. A clean breach history, or full pre-LOI disclosure of any prior incident.
This is roughly the 2026 minimum viable posture to clear both a Fortune 500 TPRM and a mid-market PE due diligence. Ten items. Most of them are not controversial. Many operators will recognize most of them as ambitions rather than facts.
What changes in the next eighteen months
The pulse is not stable. It’s getting faster.
The Department of Defense’s CMMC 2.0 framework entered its first phase of DFARS-contractual enforcement on November 10, 2025, via final rule published in the Federal Register in September. Phase two, which requires Level 2 third-party assessor (C3PAO) certification on a widening set of defense contracts, flips on November 10, 2026. The current assessor ecosystem is not sized for the queue this will produce. Any infrastructure-services firm that works, even at a distance, with defense subcontractors will feel this within the year. Phase three, which adds Level 3, arrives November 10, 2027.
The HIPAA Security Rule is on track for its first prescriptive overhaul since 2003. The notice of proposed rulemaking, published December 27, 2024, would mandate multi-factor authentication, encryption of PHI at rest and in transit, seventy-two-hour restoration from contingency, annual penetration testing, and asset inventories with documented controls. The final rule is targeted for May of 2026. If it lands roughly as proposed, every business associate agreement in the country gets technical teeth it has not had before.
The state privacy regime continues to fragment. Twenty states have comprehensive consumer privacy laws in effect by the end of 2026 — California, Virginia, Colorado, Connecticut, Utah, Texas, Florida, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. The California Privacy Protection Agency’s new regulations, effective January 1, 2026, include rules on automated decisionmaking technology, mandatory cybersecurity audits tiered by revenue, and annual risk assessments. The first cybersecurity audits are due April 1, 2028, for the largest tier, but the programmatic obligations ramp before that.
The EU’s DORA regime for digital operational resilience in financial services has been in effect since January 17, 2025. The first register-of-information submissions were due April 30, 2025. NIS2 continues its uneven national transposition across EU member states. The EU AI Act’s high-risk Annex III provisions take effect August 2, 2026, with fines up to €35 million or seven percent of global turnover. Colorado’s SB 24-205 — the first comprehensive US state AI law — takes effect June 30, 2026, after a delay from the original February 2026 date. California, New York, Connecticut, and Texas have bills in various stages that track Colorado’s template.
For any US operator doing business internationally, or touching EU persons, or selling AI-adjacent capabilities, the compliance map keeps getting larger. For any US operator in regulated sectors, the domestic map keeps getting more prescriptive. For any US operator selling to larger customers, the commercial cascade keeps getting faster.
What this demands of operational infrastructure
The response that works is not a new governance document or a bigger policy binder. It is a specific shift in where the work happens — at the configuration and evidence-trail level, where systems live, not at the governance level where policies do.
Compliance, under continuous pressure, is not achieved by writing a better description of your controls. It is achieved by building systems that produce the evidence of their own controls — and by building them in a way that keeps producing the evidence as the systems evolve. MFA is not a policy; it is a deployed technology with enrollment reports, failure logs, and exception-handling. Observability is not a dashboard; it is an instrumented system whose logs are admissible as evidence for the eight different regimes that might ask to see them.
The operator who needs, in a given year, to satisfy a SOC 2 Type II assessor, pass a Fortune 500 TPRM renewal, respond to a PE-driven due-diligence request, maintain eligibility for a cyber insurance policy, and document controls that map to two or three state privacy regimes plus DORA plus the updated HIPAA Security Rule plus whatever CMMC level applies, does not need a different policy for each. They need a system whose artifacts can be shown to each one, with minimal additional work. That system is an engineering deliverable, not an advisory deliverable. It is built by operators, not by auditors. And it is handed over to the client’s own team once it exists, not retained as a billing dependency.
That distinction — between the engineered posture and the advised posture — is the one most worth making at this moment. The market is saturated with firms selling advice about compliance and thin with firms that actually build and maintain the systems that satisfy it. A credible mid-market practice is on the engineering side of that line. It treats the regulator as one requirement among several; it treats the customer’s TPRM program, the insurer’s renewal checklist, and the acquirer’s DD questionnaire as the set of assessors who actually control the calendar; and it builds what needs to be built so that the answer to all of them is yes, with the evidence in hand, every time the pulse fires.
If you have a compliance calendar that’s starting to look less like a cycle and more like a pulse, or a set of customer reassessment requirements that keep expanding, or a due-diligence cycle coming up for the first time — tell us about it.
Sources
- FTI Consulting, CISO Redefined III: Navigating Transactions in an Evolving Cybersecurity Landscape, March 2026 — report page · press release
- Verizon, 2025 Data Breach Investigations Report — report hub · press release
- West Monroe, Cybersecurity Due Diligence in M&A — research page
- HHS Office for Civil Rights, 2024 Enforcement Highlights — OCR page
- SEC enforcement actions re: SolarWinds-affected disclosure failures, October 2024 — data protection report summary
- UnitedHealth Group 8-K filed February 22, 2024 — SEC filing · CEO Andrew Witty Senate Finance Committee testimony, May 1, 2024 — testimony · HHS OCR Change Healthcare FAQ — HHS page
- Yahoo acquisition price reduction, February 2017 — Bloomberg · TechCrunch
- NYDFS Industry Letter on Third-Party Risk Management, October 21, 2025 — NYDFS
- CMMC 2.0 DFARS clause final rule — Federal Register
- Shared Assessments SIG 2025 — SA announcement
- Cloud Security Alliance CAIQ v4 — CSA