800-214-0957 info@blackbottleit.com

We Don't Just Guide You Through Compliance. We've Done It Ourselves.

Black Bottle IT is SOC 2 certified — and we’ve put every major compliance framework to work for real clients across Western Pennsylvania. This isn’t theory. It’s what our team does every day.

Talk to Our Compliance Team

Compliance Frameworks

SOC 2 Certified

We Hold Our Own Standard

CMMC • SOC 2 • PCI • NIST

Frameworks We Work in Every Day

Compliance 

 That’s Built into Cybersecurity

— Not Bolted On

OUR COMPETITIVE ADVANTAGE

Compliance Without Cybersecurity is Just Paperwork.  

Most compliance consultants hand you a checklist and walk away. Black Bottle IT approaches compliance the way we approach every engagement — through a security-first lens. We don’t just help you satisfy an auditor. We make sure your business is actually more protected when we’re done.

Because we’ve achieved SOC 2 certification ourselves, we know exactly where organizations struggle, what auditors look for, and how to close the gaps that matter — not just the ones that are easy to document.

  • Achieved SOC 2 certification ourselves
  • Security controls, not just documentation
  • Ongoing compliance — not just audit prep
  • Deep experience across CMMC, PCI, and NIST
  • Compliance integrated into your IT environment
  • Real remediation, not a report you’ll never use

NO COMPARISON

Compliance Without Security is Just a Binder on the Shelf.

Graph describing the differences for Black Bottle IT Compliance

📋 SOC 2 — Service Organization Control

The standard for B2B service providers. And one we hold ourselves.

SOC 2 verifies that your organization manages customer data responsibly across five trust principles: security, availability, processing integrity, confidentiality, and privacy. It’s increasingly required by enterprise clients before they’ll sign a contract.

Black Bottle IT is SOC 2 certified. We’ve been through the audit. We know what it takes — and what it takes to maintain it year over year.

What we do:

• Readiness assessments and gap analysis

• Control design and implementation

• Policy and procedure documentation

• Audit preparation and auditor coordination

• Ongoing compliance monitoring

What you gain: A certification that opens doors, satisfies vendor questionnaires, and proves — with third-party validation — that your data practices are trustworthy.

🔁 CMMC — Cybersecurity Maturity Model Certification

 

Required for defense contractors. Non-negotiable for DoD work.

If your business handles Federal Contract Information (FCI) or Controlled Unclassified Information (CUI), CMMC certification isn’t optional — it’s the price of entry. And the requirements are only getting stricter.

What we do:

• Gap assessments against CMMC Level 1 and Level 2 requirements

• Remediation planning and implementation

• Documentation and policy development

• Pre-assessment readiness review

• Ongoing monitoring to maintain certification

What’s at stake without it: Defense contractors lose eligibility for DoD contracts — full stop. We help you get certified and stay there.

📋 Payment Card Industry Data Security Standard

If you accept credit cards, this isn’t optional.

PCI DSS protects cardholder data and ensures your payment environment is secure. Non-compliance can result in fines, increased processing fees, and loss of the ability to accept card payments entirely.

What we do:

• PCI scope assessment and network segmentation review

• Vulnerability scanning and penetration testing coordination

• Policy documentation and training

• Remediation of identified gaps

• Ongoing compliance support

🔁 NIST Cybersecurity Framework

The foundation that makes every other framework easier.

NIST isn’t a certification — it’s the best-practice playbook that underpins CMMC, SOC 2, HIPAA, and most other frameworks. Getting your organization aligned to NIST means you’re building security on solid ground, and future compliance certifications become significantly less painful.

What we do:

  • NIST framework alignment assessment
  • Risk management program development
  • Security controls implementation
  • Integration with CMMC, HIPAA, and SOC 2 requirements

WHY BLACK BOTTLE IT

What Makes Our Compliance Practice Different  

Most MSPs hand you a spreadsheet and call it a gap assessment. We’re different because:

We hold our own SOC 2. We completed the audit. We know what auditors look for, where organizations fall short, and how to fix issues before they become problems.

Compliance is security, not paperwork. Every framework we work with is mapped to real security controls — not just documentation. Your organization ends up more secure, not just more certified.

We stay with you. Compliance isn’t a one-time project. We provide ongoing monitoring and support so you maintain certification between audits, not just during them.

We know your industry. Whether you’re a defense contractor, dental practice, financial firm, or B2B service provider, we understand the specific requirements that apply to you.

Ready to Know Where You Stand?

Start with a free compliance gap assessment. We’ll map your current environment against the frameworks that matter to your business and show you exactly what needs to happen next.

Schedule a Free Compliance Assessment Here

Corporate Office

7000 Stonewood Drive, Suite 222
Wexford, PA 15090

Hours

M-F: 8:30 am – 5 pm
Breach Hotline 24×7

Call Us

800-214-0957 (main)

800-214-0957 x700 (breach hotline)