United States

SOC onboarding built for the United States.

Client-ready onboarding packs for US MSPs, MSSPs and security teams: Splunk-first, mapped to SOC 2 and HIPAA, with sector breach timelines kept separate because there is no single federal standard.

The SIEM platforms we onboard to here

Blueprint generates the full onboarding pack in each platform's own vocabulary - sources, runbooks, detection priorities and validation steps. These are the platforms we see most in this market.

Splunk Enterprise Security
Roughly 46 percent market share, the largest community and integration ecosystem
Microsoft Sentinel
Native first-party connectors for the entire Microsoft estate
CrowdStrike Falcon Next-Gen SIEM
Very strong where Falcon EDR is already deployed
Google Security Operations (Chronicle)
Flat-rate pricing removes volume cost risk
Cortex XSIAM
Deep integration with the Palo Alto estate
Migrating off QRadar?
Palo Alto Networks acquired IBM's QRadar SaaS business in late 2024, and 2026 is the year most QRadar estates pick their migration path. Blueprint treats QRadar as a migration source: it generates the complete onboarding pack for your target platform, in that platform's own terms.

The security stack we document

Source runbooks are generated per vendor. The global core is always available; vendors with real share in this market are included by default.

Identity
Microsoft Entra ID
Okta
Google Workspace
Active Directory (on-premises)
JumpCloud
Duo
Ping Identity
Endpoint
Microsoft Defender for Endpoint
CrowdStrike
SentinelOne
Sophos
ESET
Trend Micro
Bitdefender
Huntress
Email
Microsoft 365
Google Workspace
Mimecast
Proofpoint
Barracuda
Abnormal Security
Network Perimeter
Palo Alto
Fortinet
Check Point
Cisco
Juniper
Sophos
WatchGuard
SonicWall
Meraki
Network Internal
DNS query logs
DHCP logs
Zscaler
Netskope
Cisco Umbrella
Cloud Control Plane
Microsoft Azure
Amazon Web Services
Google Cloud Platform
Vulnerability
Tenable
Qualys
Rapid7
OpenVAS
Microsoft Defender Vulnerability Management
Backup
Veeam
Acronis
Datto
Rubrik
Commvault
Saas Audit
Salesforce
ServiceNow
Atlassian
Slack
Zoom
Epic
Cerner
Workday
Data Protection
Microsoft Purview
Forcepoint
Netskope
Ot Ics
OSIsoft PI Historian
Honeywell
Siemens
Rockwell Automation
Schneider Electric
Claroty
Nozomi Networks
Dragos
Change Management
Microsoft Intune
Jamf
Ansible
Puppet

Collectors and gateways

Where logs cannot go straight to the platform, the pack covers the collector layer:

Bindplane
Cribl Stream
NXLog Platform
Vector
Fluent Bit and Fluentd
OpenTelemetry Collector

Frameworks and regulation

Every pack maps onboarding evidence against the frameworks that matter in this market.

NIST SP 800-53
NIST SP 800-171
CMMC
HIPAA Security Rule
HITRUST CSF
FedRAMP
StateRAMP
GLBA Safeguards Rule
NYDFS Part 500
SEC cyber disclosure rules
NERC CIP
CJIS Security Policy
FERPA
CCPA / CPRA and state privacy laws
ISO/IEC 27001
ISO/IEC 27017
ISO/IEC 27018
ISO 22301
SOC 2
PCI DSS
CIS Controls
NIST CSF
MITRE ATT&CK
IEC 62443
SWIFT CSP
CSA STAR

Statutory notification deadlines

TriggerDeadlineReport to
Material cybersecurity incident at a public company4 business days from materiality determinationSEC via Form 8-K
Breach of unsecured protected health information60 daysAffected individuals and HHS
Cybersecurity event at an NYDFS-regulated entity72 hoursNYDFS
Breach of personal informationVaries by state, commonly 30 to 60 daysAffected individuals and state attorney general

Regulators

  • FTC - Consumer protection and data security enforcement
  • CISA - National cyber defence and critical infrastructure
  • OCR - HIPAA enforcement
  • SEC - Public company cyber disclosure
  • NYDFS - New York financial services
Regulation guide

Partner with us

Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in the United States.

Apply as a partner