We Don't Just Guide You Through Compliance. We've Done It Ourselves.
Black Bottle IT is SOC 2 certified — and we’ve put every major compliance framework to work for real clients across Western Pennsylvania. This isn’t theory. It’s what our team does every day.
Compliance Frameworks
SOC 2 Certified
— We Hold Our Own Standard
CMMC • SOC 2 • PCI • NIST
— Frameworks We Work in Every Day
Compliance
That’s Built into Cybersecurity
— Not Bolted On
OUR COMPETITIVE ADVANTAGE
Compliance Without Cybersecurity is Just Paperwork.
Most compliance consultants hand you a checklist and walk away. Black Bottle IT approaches compliance the way we approach every engagement — through a security-first lens. We don’t just help you satisfy an auditor. We make sure your business is actually more protected when we’re done.
Because we’ve achieved SOC 2 certification ourselves, we know exactly where organizations struggle, what auditors look for, and how to close the gaps that matter — not just the ones that are easy to document.
- Achieved SOC 2 certification ourselves
- Security controls, not just documentation
- Ongoing compliance — not just audit prep
- Deep experience across CMMC, PCI, and NIST
- Compliance integrated into your IT environment
- Real remediation, not a report you’ll never use
NO COMPARISON
Compliance Without Security is Just a Binder on the Shelf.
📋 SOC 2 — Service Organization Control
The standard for B2B service providers. And one we hold ourselves.
SOC 2 verifies that your organization manages customer data responsibly across five trust principles: security, availability, processing integrity, confidentiality, and privacy. It’s increasingly required by enterprise clients before they’ll sign a contract.
Black Bottle IT is SOC 2 certified. We’ve been through the audit. We know what it takes — and what it takes to maintain it year over year.
What we do:
• Readiness assessments and gap analysis
• Control design and implementation
• Policy and procedure documentation
• Audit preparation and auditor coordination
• Ongoing compliance monitoring
What you gain: A certification that opens doors, satisfies vendor questionnaires, and proves — with third-party validation — that your data practices are trustworthy.
🔁 CMMC — Cybersecurity Maturity Model Certification
Required for defense contractors. Non-negotiable for DoD work.
If your business handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), CMMC certification isn’t optional — it’s the price of entry. And the requirements are only getting stricter.
What we do:
• Gap assessments against CMMC Level 1 and Level 2 requirements
• Remediation planning and implementation
• Documentation and policy development
• Pre-assessment readiness review
• Ongoing monitoring to maintain certification
What’s at stake without it: Defense contractors lose eligibility for DoD contracts — full stop. We help you get certified and stay there.
📋 Payment Card Industry Data Security Standard
If you accept credit cards, this isn’t optional.
PCI DSS protects cardholder data and ensures your payment environment is secure. Non-compliance can result in fines, increased processing fees, and loss of the ability to accept card payments entirely.
What we do:
• PCI scope assessment and network segmentation review
• Vulnerability scanning and penetration testing coordination
• Policy documentation and training
• Remediation of identified gaps
• Ongoing compliance support
🔁 NIST Cybersecurity Framework
The foundation that makes every other framework easier.
NIST isn’t a certification — it’s the best-practice playbook that underpins CMMC, SOC 2, HIPAA, and most other frameworks. Getting your organization aligned to NIST means you’re building security on solid ground, and future compliance certifications become significantly less painful.
What we do:
- NIST framework alignment assessment
- Risk management program development
- Security controls implementation
- Integration with CMMC, HIPAA, and SOC 2 requirements
WHY BLACK BOTTLE IT
What Makes Our Compliance Practice Different
Most MSPs hand you a spreadsheet and call it a gap assessment. We’re different because:
We hold our own SOC 2. We completed the audit. We know what auditors look for, where organizations fall short, and how to fix issues before they become problems.
Compliance is security, not paperwork. Every framework we work with is mapped to real security controls — not just documentation. Your organization ends up more secure, not just more certified.
We stay with you. Compliance isn’t a one-time project. We provide ongoing monitoring and support so you maintain certification between audits, not just during them.
We know your industry. Whether you’re a defense contractor, dental practice, financial firm, or B2B service provider, we understand the specific requirements that apply to you.
Ready to Know Where You Stand?
Start with a free compliance gap assessment. We’ll map your current environment against the frameworks that matter to your business and show you exactly what needs to happen next.
Corporate Office
7000 Stonewood Drive, Suite 222
Wexford, PA 15090
Hours
M-F: 8:30 am – 5 pm
Breach Hotline 24×7
Call Us
800-214-0957 (main)
800-214-0957 x700 (breach hotline)