United States
SOC 2 and HIPAA, documented as you onboard.
The US baseline is attestation-led: SOC 2 for B2B trust, HIPAA for anyone touching health data, and a patchwork of federal and state breach rules. Blueprint generates the evidence pack alongside the onboarding itself, and never collapses the patchwork into one number.
What applies in the United States
There is no single federal breach notification standard. Public companies report material incidents to the SEC via Form 8-K within 4 business days. HIPAA covered entities notify HHS and affected individuals within 60 days. NYDFS-regulated financial firms report within 72 hours. California's CCPA/CPRA and the other state privacy laws each carry their own rules, and FERPA governs student records.
For B2B trust, SOC 2 Type II is the default ask in procurement, with NIST CSF as the common risk language and CMMC for the defense supply chain.
What the generated pack covers
Each US onboarding pack includes the IR framework with the applicable notification chains listed separately per regime, a risk register in NIST CSF language, SOC 2 control mapping, and source runbooks with the retention your auditors expect.
Statutory notification deadlines
| Trigger | Deadline | Report to |
|---|---|---|
| Material cybersecurity incident at a public company | 4 business days from materiality determination | SEC via Form 8-K |
| Breach of unsecured protected health information | 60 days | Affected individuals and HHS |
| Cybersecurity event at an NYDFS-regulated entity | 72 hours | NYDFS |
| Breach of personal information | Varies by state, commonly 30 to 60 days | Affected individuals and state attorney general |
Frequently asked questions
Partner with us
Blueprint is white-label first: your branding on every generated pack, your domain on the client portal. We are looking for our first delivery partner in the United States.
Apply as a partner