Regulatory Compliance for Regulated Industries

The question came in.
Now you need an answer.

The Compliance Snapshot is a 5-minute scoping tool that maps which frameworks apply. The Compliance Risk Diagnostic that follows is where you find out where you really stand — with a detailed report, no cost, no obligation.

img s2 We have Done This Work In

We’ve Done This Work In

35+ Healthcare Practices

HIPAA-compliant managed IT, examination readiness, and post-2026 Security Rule alignment.

28 Credit Unions

NCUA examination prep, FFIEC CAT documentation, ACET readiness across NC, GA, AL, FL, SC, LA, VA.

CMMC L2 Certified

DQ itself passed the 110-control NIST 800-171 audit. We’ve done what we ask our defense clients to do.

256 Clients · 25+ Years

In business since 1999. MSP 501 #210. Spire Capital-backed. SOC 1/2 II, HIPAA, CJIS, ITAR.

What’s Changed in the Last 12 Months

Four shifts worth knowing about before your next renewal.

The enforcement, insurance, and client-questionnaire landscape moved meaningfully in 2025. 

None of this is theoretical. Here’s what we’re seeing in the market, with sources:

$51,744

FTC Safeguards Rule penalty ceiling

The dollar figure matters less than what it signals: the FTC has shifted from publishing guidance to enforcing it. Non-bank financial institutions — CPA firms, tax preparers, financial advisors, mortgage brokers, RIAs — are now expected to document their information security program, not just have one. The standard is “can you show your work,” not “did you intend to comply.”

Source: FTC, 2024 inflation-adjusted civil penalty ceiling

15–20%

forecast cyber insurance premium movement in 2026

After two years of softening rates, S&P Global is projecting market-wide premium growth of 15–20% in 2026. The driver is loss experience — a 126% 
rise in ransomware incidents and an 800% jump in credential theft during 
Q1 2025. The good news: firms with documented, mature controls are seeing meaningfully better outcomes than the market average. Posture and proof now matter more than they used to. 

Source: S&P Global Ratings, 2026 Cyber Insurance Outlook

99%

of cyber insurance applications now ask specific MFA questions

A few years ago, underwriters asked “do you have MFA?” Now they ask “where is it enforced, who’s exempted, and can you produce the coverage report?” The bar moved from policy to evidence. Per Marsh McLennan, about 41% of applications come back for revisions on first submission — usually because the documentation wasn’t ready, not because the controls weren’t there. 

Source: Marsh McLennan Cyber Insurance Market Report 2025 

Q1–Q2

when most cyber insurance renewals fall

Most renewals concentrate in the first half of the year. The shift to evidence-based underwriting means brokers are recommending a 60–90 day pre-submission window for documentation prep — MFA coverage reports, EDR agent health, IR tabletop documentation, backup test logs. Firms that plan for that window tend to have a smoother renewal conversation.

Source: Aon 2026 Cyber Market Report 

The pattern across all four: compliance isn’t being asked about — it’s being verified. The shift from “do you have these controls?” to “can you show they were running on the day in question?” is the most consequential change in regulated-industry IT in the last few years. The Compliance Snapshot below is where we usually start when a client wants to map their picture against this new bar.

“From an IT leadership perspective, this was one of the more valuable engagements we’ve done. They connected the dots between our technical controls and the actual compliance requirements — CISv8, FTC Safeguards, and state regulations. The process was detailed without being overwhelming. They validated what we were doing well, identified gaps, and helped us translate everything into policies and procedures that auditors and regulators will actually understand. It’s rare to find a team that can operate at both the technical and compliance level this effectively.”

Director of Technology

Who We Serve

If your industry is regulated, 
we’ve been here before.

Dynamic Quest specializes in heavily regulated industries — not as a marketing claim, but as a delivery practice with proof points in each one.

img s5 Who We Serve
ic industry CPA Tax
CPA & Tax

top 25 NC CPA firm 
moved off Rightworks onto Azure VDI with DQ. We’ve done that migration. We know the path.

FTC Safeguards · IRS 4557 · GLBA · State data laws

ic industry Healthcare
Healthcare

35+ healthcare practices
across the Southeast and beyond. After the 2026 HIPAA Security Rule update, we added formal HIPAA compliance management 
as a named service.

HIPAA Security & Privacy · HITECH · State health data laws

ic industry Credit Unions
Credit Unions

28 credit union clients
across NC, GA, AL, FL, SC, LA, 
VA — one of the densest CU concentrations of any regional MSP. NCUA examination prep, FFIEC CAT, ACET, all in production.

NCUA · FFIEC · GLBA · State CU regulations 

ic industry Law Firms
Law Firms

Client-confidentiality-
driven compliance work for regional firms. Outside counsel guidelines, ABA Formal Opinion 477R, and increasingly — state bar cybersecurity expectations.

ABA 477R/483 · State bar · Client OCGs · State data laws

ic industry RIA Wealth Management
RIA / Wealth Management

SEC Regulation S-P 
obligations, DOL fiduciary cybersecurity guidance, and the documentation your custodian and broker-dealer partners now expect at every annual review.

SEC Reg S-P · DOL Fiduciary · GLBA · FINRA 

ic industry Manufacturing
Manufacturing

18 manufacturing clients
anchored by a national packaging manufacturer 
(27 plants across the US) 
and a North American heavy-equipment subsidiary. Defense subcontractors are part of this mix; non-defense manufacturers face SOC 2 and customer-driven security requirements.

SOC 2 · ITAR · CMMC (defense subset) · Customer security questionnaires 

ic industry Hospitality
Hospitality

Card payment processing, loyalty data, and franchise-level security requirements. 
PCI DSS 4.0 enforcement 
and card-brand attestation deadlines are the most immediate pressure points.

PCI DSS 4.0 · State data laws · Franchise security requirements

ic industry Manufacturing
Defense Contractors

DQ is CMMC Level 2 certified
— we passed the same 110-control NIST 800-171 audit your DoD contracts now require. 
For defense work, our SPRS Calculator and CMMC Readiness Assessment are 
the right starting points.

CMMC · NIST 800-171 · DFARS 252.204-7012/7019/7020 · ITAR

Not seeing your industry? Compliance for accountants, attorneys, consultants, advisors, healthcare administrators, and operations leaders in many regulated businesses are often broadly similar at the framework level, so feel free to take the Compliance Snapshot. Or better yet, reach out to discuss your specific needs, and we can walk through and tailor the snapshot with you.

Compliance Snapshot
About 5 minutes
Step 1 of 5 — Industry

What kind of firm are you?

This determines the baseline compliance frameworks that apply to your business.

What We’ll Ask For

Eight documents. Most firms have some. That’s the point.

After the 15-minute intro call, we’ll ask for the eight documents below. Most firms only have three or four — and the ones they do have are usually of varying age and quality. That gap between what you have, what you don’t, and what’s actually current is the first thing the Diagnostic surfaces. You don’t need to have them all to start.

ic number 01

Employee Manual

How your firm operates day-to-day — the baseline against which security and compliance practices are evaluated.

ic number 02

Written Information Security Plan (WISP)

Required by FTC Safeguards, IRS 4557, and most state laws. Most firms have one — few have one that’s current and defensible.

ic number 03

Incident Response Plan

What happens when something goes wrong. Increasingly required by insurers and regulators; rarely tested.

ic number 04

Vendor Management Plan

How you assess and manage third-party risk — one of the fastest-growing exposure areas in regulated industries.

ic number 05

Cyber Insurance Policy

Your current policy and any application materials. Often reveals where your insurer expects you to be vs. where you actually are.

ic number 06

Latest Penetration Test

If you have one. Many firms haven’t had a pen test in 18+ months — or have never had one at all.

ic number 07

Current Cybersecurity Policies

Access Control, Encryption, BYOD, Acceptable Use, etc. Whatever you have, in whatever state it’s in.

ic number 08

Anything else you’d like reviewed

Audit findings, client questionnaires you couldn’t fully answer, prior consulting reports, regulator correspondence. If it’s relevant, we’ll review it.

What if I don’t have most of these?

That’s common — and exactly why the Diagnostic is worth doing. The pattern of what you have, what’s missing, and what’s outdated tells us more than any single document ever could. Many of our most useful engagements have started with firms who had only two or three documents to share. 

What if I do have all of these?

Even better — but still worth a look. Documents written 2–3 years ago likely predate the 2025 FTC Safeguards amendments, the 2026 HIPAA Security Rule updates, NCUA’s ACET expectations, and the evidence-based shift in cyber insurance underwriting. The most common pattern we see in well-documented firms isn’t missing documents — it’s documents that are technically present but no longer aligned to current requirements. The Diagnostic is the fastest way to confirm what’s still current and what needs an update.

img s7 Compliance Risk Diagnostic

Where the Diagnostic Leads

The Diagnostic is the framework. This is what gets built from it.

Your readout deliverables — the gap analysis, executive deck, and leadership summary — name exactly which gaps 
need to close. From there, the work takes a clear shape: a fixed-price Managed Compliance project that builds a documented, defensible program, then Continuous Compliance to keep it current. Any technical gaps the readout surfaces are closed through DQ’s Managed IT, Cybersecurity, Cloud, and CMMC service lines. Everything is scoped 
and quoted against the specific findings in your readout — not against generic frameworks.

The Build · Managed Compliance

A fixed-price project — roughly 8 weeks, about one hour of your team’s time per week — that takes you from scattered documents to a compliance matrix at all greens: a documented, defensible program.

ic s8 Risk Security Foundation
Risk & Security Foundation

Where every program starts

Your enterprise cyber risk assessment, business impact analysis, and security charter — 
the documents that anchor every downstream compliance decision.

ic s8 Compliance Policy Build
Compliance Policy Build

The documentation regulators 
ask for

Your Written Information Security Program (WISP), Incident Response Plan across six breach scenarios, vendor risk management, and SOP updates aligned to your frameworks. 

ic s8 Team Readiness Training
Team Readiness 
& Training

Compliance only works if people execute

Executive briefings for leadership, employee security training, and a facilitated tabletop breach exercise so your team has actually rehearsed a real scenario before they need to. 

The project gets you to all greens. Then, because compliance done once decays
img s8 The quarterly program
ic s8 The quarterly program
Ongoing · Continuous Compliance

The quarterly program that keeps you audit-ready.

A light, recurring program that keeps your documented posture current quarter after quarter — so your next insurance renewal, regulatory exam, or client questionnaire is a defensible submission, not a scramble. 

The Technical Side

When the readout surfaces IT 
and security gaps, we close them.

A real gap analysis almost always uncovers technical work that has to happen alongside policy and governance. Missing MFA. Outdated backups. Endpoint controls that don’t match the policy on paper. Identity gaps. Cloud misconfigurations. We don’t hand you a list and walk away — we quote and deliver the remediation through the same DQ service lines our 256 clients rely on every day.  

img s9 The Technical Side
ic s9 Managed IT Services
Managed IT Services

Endpoint management, patching, helpdesk, infrastructure — the operational backbone of every compliance program.

ic s9 Cybersecurity Services
Cybersecurity Services

24/7 SIEM/SOC, MDR, 
email defense, vulnerability management. The controls regulators and insurers actually want to see.

ic s9 Cloud Services
Cloud Services

Azure, Microsoft 365, AVD, 
backup & DR. Configured to 
your framework requirements, 
not generic defaults.

ic s9 CMMC Services
CMMC Services

Defense contractors 
specifically: SPRS scoring, 
NIST 800-171 readiness, C3PAO coordination. DQ is itself CMMC Level 2 certified.

“We’ve had a WISP in place for years, but going through this process showed us where we really stood. They didn’t just hand us a checklist—they walked through how our firm actually operates and aligned everything to IRS 4557, FTC Safeguards, and CIS in a way that made sense. What I appreciated most was how practical it was. Every policy, every recommendation tied back to something we’re doing day-to-day. At the end, we walked away not just with updated documents, but with real confidence that we’re compliant—and that we’ll stay that way”

Director of Technology

Compliance isn't getting easier.
Start where it's easiest.

Five minutes to see what applies. Then the Compliance Risk Diagnostic to see where you really stand. Both at no cost. 
No obligation. The clearest path to knowing.