United States

SOC 2 and HIPAA, documented as you onboard.

The US baseline is attestation-led: SOC 2 for B2B trust, HIPAA for anyone touching health data, and a patchwork of federal and state breach rules. Blueprint generates the evidence pack alongside the onboarding itself, and never collapses the patchwork into one number.

What applies in the United States

There is no single federal breach notification standard. Public companies report material incidents to the SEC via Form 8-K within 4 business days. HIPAA covered entities notify HHS and affected individuals within 60 days. NYDFS-regulated financial firms report within 72 hours. California's CCPA/CPRA and the other state privacy laws each carry their own rules, and FERPA governs student records.

For B2B trust, SOC 2 Type II is the default ask in procurement, with NIST CSF as the common risk language and CMMC for the defense supply chain.

What the generated pack covers

Each US onboarding pack includes the IR framework with the applicable notification chains listed separately per regime, a risk register in NIST CSF language, SOC 2 control mapping, and source runbooks with the retention your auditors expect.

Statutory notification deadlines

TriggerDeadlineReport to
Material cybersecurity incident at a public company4 business days from materiality determinationSEC via Form 8-K
Breach of unsecured protected health information60 daysAffected individuals and HHS
Cybersecurity event at an NYDFS-regulated entity72 hoursNYDFS
Breach of personal informationVaries by state, commonly 30 to 60 daysAffected individuals and state attorney general

Frequently asked questions

Does Blueprint generate SOC 2 evidence?
Yes. The Comply module maps generated onboarding documents against SOC 2 criteria and produces a narrative gap analysis from Starter upwards.
What breach deadlines does the IR framework include?
The regimes that apply to your client, listed separately: SEC 8-K at 4 business days for public companies, HIPAA at 60 days, NYDFS at 72 hours, plus state rules. We never merge them into a single number, because none exists.
Which SIEM platforms do US packs cover?
Splunk first, reflecting its US install base, plus Microsoft Sentinel, CrowdStrike, Google SecOps and Elastic, each documented in its own vocabulary.

Partner with us

Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in the United States.

Apply as a partner