Most professional services firms assume compliance standards apply to somebody else. Then a client sends a security questionnaire before signing a new engagement, or a cyber insurance renewal asks for documentation nobody in the office has seen before.
That is usually the first time compliance readiness for a small business stops being an abstract phrase and turns into a deadline. Accounting practices, law offices, and property management firms handle financial records, personal information, and sometimes payment data every day. That activity puts many of them within the scope of HIPAA, PCI DSS, or SOC 2 requirements, even though no one at the firm set out to become a regulated business.
These firms aren’t careless. Nobody explained which rules actually apply, what those rules require in practice, or where a firm this size should start.
Why Compliance Is Showing Up in More Conversations
Insurance carriers tightened their underwriting standards over the past few years. Cyber liability policies now ask pointed questions about multi-factor authentication, backup testing, and incident response plans before a carrier issues or renews coverage. A firm that can’t answer those questions in writing risks a higher premium or a denied claim.
Clients are asking the same questions. Banks, private equity firms, and larger corporate clients increasingly require a completed security questionnaire or a SOC 2 report before they hand a vendor sensitive data. A law firm handling a corporate client’s litigation, or an accounting firm managing a private equity portfolio company’s books, can lose the engagement over a missing document, not a missing capability.
Professional services firms have also become a bigger target than most owners realize. Ransomware groups shifted their attention toward legal, accounting, and consulting firms, which accounted for close to one in five ransomware attacks in a recent quarter, according to the ransomware recovery firm Coveware. Attackers know these firms hold client financial records, case files, and personal data, and that most run leaner security than hospitals or banks do.
None of this means a fifty-person accounting firm needs a compliance department. It means understanding which standards apply to the business and building a short list of documented practices that satisfy most of what insurers, clients, and auditors ask for.
What HIPAA, PCI, and SOC 2 Actually Cover
HIPAA governs protected health information and applies to healthcare providers, as well as vendors and business partners that handle health data on their behalf. A property management firm running a medical office building, or an accounting practice with healthcare clients who share patient billing data for reconciliation, can find HIPAA obligations attached to work that never looked medical on the surface.
PCI DSS applies to any business that processes, stores, or transmits credit card data. Property management firms collecting rent through an online portal, and law firms accepting card payments for retainers, both fall under PCI requirements the moment a card number touches their systems, even indirectly through a payment processor.
SOC 2 is different from the other two. It isn’t a law. It’s an audit standard that proves an organization has real controls around the security, availability, and confidentiality of data. Firms don’t usually pursue SOC 2 because a regulator demands it. They pursue it because a client, a bank, or an insurer asked for the report, and without it, the deal stalls.
This plays out constantly: an accounting firm picks up outsourced payroll work for a physician client and signs on to keep handling billing reconciliation, then realizes months later that arrangement pulled HIPAA obligations into scope. That kind of realization arrives late more often than it should, usually attached to a deadline.
How to Figure Out Which Ones Apply to You
Start with three questions instead of the full text of each standard.
- Does the firm handle protected health information, directly or through a client relationship? If yes, HIPAA obligations are worth reviewing with someone who understands both the technology and the legal exposure.
- Does the firm accept, store, or transmit credit card numbers in any form, including through a client portal or a property management platform? If yes, PCI DSS requirements apply, even at a small scale.
- Has a client, bank, or insurer ever asked for a completed security questionnaire or a SOC 2 report? If this keeps happening, formal readiness work will save more time than answering the same fifteen-page questionnaire from scratch every quarter.
Most firms find they touch at least one of these standards without ever intending to.
What Readiness Actually Looks Like
Compliance readiness for a fifty- to one hundred fifty-person professional services firm rarely means a five-hundred-page policy binder. It means having documented, working answers to the questions insurers and clients keep asking: multi-factor authentication on every account, tested backups, a written incident response plan, defined access controls, and a basic record of how vendors who touch client data are vetted.
Firms that build these practices once tend to stop dreading every renewal and every new client questionnaire, because the answers already exist. The alternative, scrambling to document controls under deadline pressure, costs more time and usually produces weaker documentation than doing the work upfront.
If you want a structured way to see where your firm stands, our Cyber Liability Insurance Readiness Checklist walks through the eight security categories insurers and compliance frameworks care about most, and shows you exactly where professional services firms typically fall short. Download it, work through it with your team, and you’ll know within an hour which of these standards deserve real attention.




