2026-09-21 · Equipo editorial KeXinMaterials
ISO/IEC 20243 O-TTPS + SOC 2 + HIPAA Cadena Suministro + SaaS + Datos Médicos Familia Maletín B2B Guía
ISO/IEC 20243 O-TTPS, SOC 2 y HIPAA son las tres principales normas de datos + privacidad + seguridad cadena suministro.
ISO/IEC 20243 O-TTPS Supply Chain Integrity
ISO/IEC 20243 O-TTPS "Open Trusted Technology Provider Standard" - supply chain integrity for hardware + software + services + cloud.
ISO/IEC 20243:2018: "Open Trusted Technology Provider Standard (O-TTPS)". Edition 1 (2018) replaces O-TTPS 1.0 (2014) + 2.0 (2015). Published by ISO/IEC + O-TTPS Working Group + The Open Group.
Scope: Trusted Technology Provider (TTP) for Information + Communication Technology (ICT) products + services. Covers hardware + software + services + cloud. Includes OEM + ODM + service providers + integrators + resellers.
Threats addressed: Counterfeit + tamper + malicious + unauthorized insertion + backdoor + malware + supply chain interruption + quality + delivery + integrity.
Supply chain integrity scope: Design + development + production + delivery + sustainment + end-of-life. End-to-end supply chain.
O-TTPS core practices: 44 best practices in 4 categories: (1) Product Development + Engineering. (2) Supply Chain Security. (3) Supply Chain Quality. (4) Personnel + Service Provider Management.
O-TTPS certification: Self-assessment or third-party certification by accredited assessor (The Open Group). Two assessment tiers: Tier 1 (self-attestation) + Tier 2 (third-party attestation).
O-TTPS certification scope: Entire organization or specific product line / business unit / supply chain.
Geographic adoption: Globally adopted. Required by major defense + intelligence customers (US DoD + UK MoD + NATO) + commercial enterprises. Part of US Federal C-SCRM (Cyber Supply Chain Risk Management) framework.
US DoD Defense Federal Acquisition Regulation Supplement (DFARS) + NIST SP 800-161: US C-SCRM framework. ISO/IEC 20243 O-TTPS aligned with NIST SP 800-161.
China GB/T 36637 (2022) + China GB/T 36643 (2023): China supply chain integrity standards. Aligned with ISO/IEC 20243 O-TTPS.
EU NIS 2 Directive (EU 2022/2555): EU-wide cybersecurity directive. Includes supply chain security per EN ISO/IEC 27001 + EN ISO/IEC 20243 O-TTPS.
B2B relevance: For B2B protective cases containing IT / OT / IoT / cloud hardware + software + services, ISO/IEC 20243 O-TTPS compliance is procurement requirement for DoD + NATO + EU + commercial enterprise supply chain security.
SOC 2 SaaS + Cloud + Data Center Security
SOC 2 "Service Organization Control 2" - AICPA Trust Services Criteria (TSC) for SaaS + cloud + data center + BPO + third-party service organizations.
SOC 2 (Service Organization Control 2): "AICPA Trust Services Criteria". Published by AICPA (American Institute of Certified Public Accountants). Version 2017 + 2022 update. TSC (Trust Services Criteria) replaced SSAE 18 SOC 2 with five principles.
Trust Services Criteria (TSC) per AICPA: Five criteria. (1) Security (Common Criteria CC). (2) Availability (A). (3) Processing Integrity (PI). (4) Confidentiality (C). (5) Privacy (P).
SOC 2 Type 1: Point-in-time report. Auditor opinion on design of controls + their implementation as of a specific date. Faster (typically 4-6 weeks).
SOC 2 Type 2: Period report. Auditor opinion on design + implementation + operating effectiveness of controls over a period (typically 6 or 12 months). More rigorous + comprehensive.
TSC Common Criteria (CC): Series A1-A8 (Control Environment + Risk Assessment + Communication + Information + Monitoring + Change Management + Logical + Physical). Common to all five principles.
TSC Availability (A): A1 (Capacity + Recovery + Backup + Environmental + Maintenance + Testing) + Additional A criteria. Focus on availability commitments + system requirements.
TSC Processing Integrity (PI): PI1 (Definition + Capture + Processing + Output) + PI2 + PI3 + PI4 + PI5. Focus on processing integrity + accuracy + timeliness.
TSC Confidentiality (C): C1 (Confidential Information Identification + Protection + Disposal). Focus on confidentiality commitments + system requirements.
TSC Privacy (P): P1-P8 (Notice + Consent + Collection + Use + Retention + Disclosure + Quality + Monitoring + Enforcement). Focus on personal information commitments + system requirements.
SOC 2 + GDPR alignment: SOC 2 Privacy criteria (P) aligned with GDPR. Some organizations use SOC 2 as GDPR evidence.
SOC 2 + ISO 27001: Combined approach common. SOC 2 Type 2 + ISO 27001 certification provides comprehensive trust services.
Geographic adoption: Globally adopted. Required by major enterprise customers + SaaS procurement. De facto standard for SaaS / cloud service organizations.
Cost: SOC 2 Type 1 EUR 20,000-50,000. SOC 2 Type 2 EUR 50,000-150,000 depending on scope + complexity + service organization size. Recertification annual.
SOC 2 attestation reports: Confidential to service organization + customer + customer auditor. SOC 3 (general public report) is condensed version.
Service auditor: Pavlov (10K). AICPA-registered. Examples: Big 4 (Deloitte + PwC + EY + KPMG) + Big 4+2 (BDO + Grant Thornton) + mid-tier + boutique (Crant, Cochran, DeLoitte).
B2B relevance: For B2B SaaS / cloud / data center / BPO / third-party service organizations, SOC 2 Type 2 attestation is procurement requirement for enterprise customers.
HIPAA + GDPR + CCPA + PCI DSS Privacy + Data Security
HIPAA (US medical data) + GDPR (EU personal data) + CCPA (California consumer data) + PCI DSS (payment card data) - global data privacy framework.
HIPAA (Health Insurance Portability and Accountability Act): US federal law. Effective 1996. Privacy Rule + Security Rule + Breach Notification Rule + Enforcement Rule + HITECH Act (2009).
HIPAA Privacy Rule (45 CFR Part 164 Subpart E): Standards for protection of individually identifiable health information (PHI). Permitted uses + disclosures + patient rights + administrative requirements.
HIPAA Security Rule (45 CFR Part 164 Subpart C): Standards for protection of electronic PHI (ePHI). Administrative + physical + technical safeguards. Required safeguards + addressable safeguards.
HIPAA Administrative Safeguards: Security management + workforce security + information access management + training + incident procedures + contingency plan + evaluation + business associate contracts.
HIPAA Physical Safeguards: Facility access controls + workstation use + workstation security + device + media controls.
HIPAA Technical Safeguards: Access control + audit controls + integrity + person authentication + transmission security.
HIPAA Breach Notification Rule: Notify affected individuals + HHS Secretary + media (for breach affecting 500+ individuals) within 60 days.
HITECH Act 2009: Strengthens HIPAA enforcement + breach notification + business associate requirements + penalty tiers. HIPAA penalties: Tier 1 (unknowing) $137-$68K per violation + Tier 2 (reasonable cause) $1.4M + Tier 3 (willful neglect corrected) $1.5M + Tier 4 (willful neglect uncorrected) $1.5M per violation + Tier criminal penalties up to $250K + 10 years prison.
GDPR (General Data Protection Regulation): EU Regulation (EU) 2016/679. Effective 25 May 2018. Replaces Directive 95/46/EC. EU-wide personal data protection.
GDPR scope: All organizations processing personal data of EU residents. Cross-border data transfer + DPO + data subject rights + lawful basis + accountability.
GDPR principles: Lawfulness + fairness + transparency + purpose limitation + data minimization + accuracy + storage limitation + integrity + confidentiality + accountability.
GDPR data subject rights: Right to information + access + rectification + erasure (right to be forgotten) + restriction + portability + objection + automated decision-making + consent withdrawal.
GDPR fines: Up to EUR 20M or 4% global annual turnover (whichever higher). Tier 1 (max EUR 10M or 2% turnover) for procedural violations. Tier 2 (max EUR 20M or 4% turnover) for substantive violations.
CCPA (California Consumer Privacy Act): California state law. Effective 1 January 2020. CCPA 2.0 (CPRA - California Privacy Rights Act) 2023. Consumer rights + business obligations.
CCPA scope: For-profit organizations meeting thresholds (annual gross $25M + 100K+ consumers + 50%+ revenue from selling personal info).
CCPA consumer rights: Right to know + right to delete + right to opt-out of sale + right to non-discrimination + right to limit use of sensitive PI (CPRA).
CCPA fines: Up to $2,500 per violation + $7,500 per intentional violation. Per California Privacy Protection Agency enforcement.
PCI DSS (Payment Card Industry Data Security Standard): Released by PCPA. Version 4.0 (March 2022 + future-dated requirements April 2025). 4 main + 12 sub-requirements.
PCI DSS 4.0 main requirements: (1) Install + maintain network security controls. (2) Apply secure configurations to all system components. (3) Protect stored account data. (4) Protect cardholder data with strong cryptography during transmission. (5) Protect all systems + networks from malicious software. (6) Develop + maintain secure systems + software. (7) Restrict access to system components + cardholder data by business need to know. (8) Identify users + authenticate access to system components. (9) Restrict physical access to cardholder data. (10) Log + monitor all access to system components + cardholder data. (11) Test security of systems + networks regularly. (12) Support information security with organizational policies + programs.
PCI DSS compliance levels: Level 1 (6M+ transactions/year, full audit) + Level 2 (1M-6M, SAQ or full audit) + Level 3 (20K-1M, SAQ) + Level 4 (< 20K, SAQ).
PCI DSS fines: Per card brand (Visa + Mastercard + Amex + Discover + JCB) + acquirer bank. Fines up to $100K/month + loss of merchant account + forensic investigation + remediation + security audit.
B2B relevance: For B2B protective cases containing personal data + medical data + payment card data, HIPAA + GDPR + CCPA + PCI DSS compliance is procurement requirement for US + EU + California + payment brands.
Cross-Standard Mapping + Supply Chain Privacy Family + B2B
Cross-standard mapping: O-TTPS + SOC 2 + HIPAA + GDPR + CCPA + PCI DSS + ISO 27001 + ISO 27701. Integrated B2B procurement.
Cross-standard mapping: ISO/IEC 20243 O-TTPS (supply chain integrity) + ISO/IEC 27001 (ISMS) + ISO/IEC 27002 (IS controls) + ISO/IEC 27701 (Privacy Information Management). Aligned with NIST SP 800-161 + NIST CSF 2.0 + EU NIS 2.
SOC 2 + ISO 27001 + ISO 27701: Combined approach. SOC 2 attestation + ISO 27001 ISMS + ISO 27701 PIMS provides comprehensive trust services + global compliance.
SOC 2 + HIPAA: SOC 2 + HIPAA Security Rule + Privacy Rule for service organizations handling medical PHI. Required for B2B SaaS / cloud serving healthcare.
GDPR + ISO 27001 + ISO 27701: GDPR compliance via PIMS (Privacy Information Management System) per ISO 27701 + ISMS per ISO 27001.
CCPA + ISO 27701: CCPA compliance via PIMS per ISO 27701.
HIPAA + SOC 2 + ISO 27001: Combined. Common for medical SaaS / cloud.
ISO/IEC 20243 + ISO/IEC 27001: Combined for supply chain + ISMS. Aligned with EU NIS 2 supply chain security.
NIST SP 800-161: US C-SCRM framework. Aligned with ISO/IEC 20243 O-TTPS + ISO/IEC 27001.
NIST CSF 2.0 (2024): Framework for Improving Critical Infrastructure Cybersecurity. Five functions: Identify + Protect + Detect + Respond + Recover + Govern. Aligns with ISO 27001 + ISO/IEC 20243 + IEC 62443.
ISO/IEC 27400 (2022): Security and Privacy techniques for IoT security and privacy guidelines. Required for IoT cases.
Common B2B mistakes: (1) Missing ISO/IEC 20243 O-TTPS for supply chain integrity. (2) Missing SOC 2 for SaaS / cloud. (3) Missing HIPAA for medical data. (4) Missing GDPR for EU personal data. (5) Missing CCPA for California. (6) Missing PCI DSS for payment cards. (7) Missing ISO 27001 + ISO 27701.
B2B procurement workflow: (1) Identify data type + supply chain scope + applicable standards. (2) Verify ISO/IEC 20243 O-TTPS for supply chain. (3) Verify SOC 2 for SaaS / cloud. (4) Verify HIPAA + GDPR + CCPA + PCI DSS for data. (5) Verify ISO 27001 + ISO 27701 ISMS + PIMS. (6) Verify NIST CSF 2.0 framework. (7) Verify supply chain + privacy + security controls.
B2B recommendation: For B2B protective case with supply chain + SaaS + medical / personal / payment data, require ISO/IEC 20243 O-TTPS + SOC 2 + HIPAA + GDPR + CCPA + PCI DSS + ISO 27001 + ISO 27701 + NIST CSF 2.0 + supply chain integrity + data privacy + breach notification.
Puntos clave
- ISO/IEC 20243:2018 O-TTPS is supply chain integrity standard. Threats: counterfeit + tamper + malicious. 44 best practices in 4 categories. Aligned with NIST SP 800-161 + EU NIS 2.
- SOC 2 per AICPA. Five Trust Services Criteria: Security (CC) + Availability (A) + Processing Integrity (PI) + Confidentiality (C) + Privacy (P). Type 1 (point-in-time) + Type 2 (period).
- HIPAA per US federal law. Privacy Rule + Security Rule + Breach Notification Rule + Enforcement Rule + HITECH Act. PHI / ePHI. Penalties up to $1.5M per violation + criminal penalties.
- GDPR per (EU) 2016/679. Data subject rights + DPO + accountability + cross-border data transfer. Fines up to EUR 20M or 4% global annual turnover.
- CCPA per California state law (2020 + CPRA 2023). Consumer rights + business obligations. Up to $2,500 per violation + $7,500 per intentional. PCI DSS v4.0 (2022) + 12 main requirements.
- B2B recommendation: For B2B protective case with supply chain + SaaS + medical / personal / payment data, require ISO/IEC 20243 + SOC 2 + HIPAA + GDPR + CCPA + PCI DSS + ISO 27001 + ISO 27701 + NIST CSF 2.0.
Preguntas frecuentes
q
a
q
a
q
a
q
a
q
a
q
a