Resources — VerdoCo
Compliance Resources

Regulatory Guides,
References & Tools

Plain-language regulatory guides, compliance checklists, and statutory reference materials — built to help you understand your mandate before you purchase your documentation series.

Plain-Language Framework Guides

One guide per regulatory framework — what it is, who it applies to, what it requires, and the consequences of non-compliance. Each guide ends with a direct path to the corresponding VerdoCo series.

Healthcare Compliance
What is HIPAA and Who Does It Apply To?

A plain-language explanation of the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule — including who qualifies as a covered entity vs. a Business Associate, what constitutes ePHI, and what a written security program must contain.

Related: VCO-HIPAA Series
Read the Mandate Reference
Defense Contracting
Understanding CMMC Level 2 and NIST 800-171

A breakdown of the 110 security controls in NIST SP 800-171 Rev 2, what a System Security Plan (SSP) and Plan of Action & Milestones (POA&M) must contain, and how CMMC assessments evaluate documentation maturity.

Related: VCO-CYBER Series
Read the Mandate Reference
Financial Services
The FTC Safeguards Rule Explained

The 2023 amended Safeguards Rule requires a written information security program covering risk assessment, access controls, encryption, multi-factor authentication, vendor oversight, and board-level reporting. This guide explains each requirement in plain terms.

Related: VCO-GLBA Series
Read the Mandate Reference
Digital Accessibility
ADA Title II Digital Accessibility — What the 2024 DOJ Rule Requires

DOJ's 2024 final rule made WCAG 2.1 Level AA the enforceable standard for state and local government digital services. This guide explains the compliance timeline, what WCAG 2.1 AA requires, and what a written accessibility program must document.

Related: VCO-ADA Series
Read the Mandate Reference
State Privacy Law
Multi-State Privacy Law: California, Colorado, Virginia & Texas

A comparative guide to the four most significant U.S. state privacy laws — CPRA, CPA, VCDPA, and TDPSA — covering applicability thresholds, consumer rights obligations, DPIA requirements, and the differences between them.

Related: VCO-PRIV Series
Read the Mandate Reference
AI Governance
NIST AI RMF 1.0 — What It Is and Why It Matters

The NIST AI Risk Management Framework introduced four core functions — GOVERN, MAP, MEASURE, MANAGE — for responsible AI deployment. This guide explains each function, OMB M-24-10's federal agency requirements, and why private sector adoption is accelerating.

Related: VCO-AI Series
Read the Mandate Reference
Workplace Safety
OSHA Written Program Requirements — What Your Industry Needs

OSHA requires written safety programs for hazard communication, lockout/tagout, PPE, bloodborne pathogens, emergency action, and many other standards. This guide maps required written programs by industry type and hazard exposure.

Related: VCO-OSHA Series
Read the Mandate Reference
Investment Advisers & Broker-Dealers
Regulation S-P — The 2024 Amendments Explained

The SEC's 2024 Reg S-P amendments expanded data breach notification requirements and information security obligations for registered investment advisers, broker-dealers, investment companies, and transfer agents. This guide explains what changed and what is now required.

Related: VCO-REGSP Series
Read the Mandate Reference
VerdoCo Platform
VerdoCo Document Legend & User Reference Guide (VCO-REF-00)

The complete visual grammar guide for all VerdoCo documents — explaining teal editable fields, locked statutory content, silver italic references, and the implementation sequence for Phase 1 and Phase 2. Required reading before completing any VerdoCo document.

Included with all purchases
See How It Works

Quick Reference Checklists

Use these checklists to assess your current compliance posture before purchasing a VerdoCo series. Each checklist identifies the key documentation gaps the corresponding series is built to close.

HIPAA Documentation Readiness Checklist

Do you have these foundational HIPAA documents in place?

Written Information Security Program / Security Policy
ePHI Asset & System Inventory
Security Rule Gap Analysis
Risk Analysis and Risk Management Plan
Business Associate Agreement (BAA) Inventory
Breach Notification Plan and Response Procedure
Workforce Training Log with completion dates
Annual HIPAA Compliance Review and Report

CMMC Level 2 Documentation Readiness Checklist

Do you have these foundational CMMC documents in place?

System Security Plan (SSP) covering all 110 controls
Plan of Action & Milestones (POA&M)
CUI Asset and System Inventory
CMMC Assessment Readiness Checklist
Incident Response Plan
Configuration Management Plan
Vendor / Third-Party Security Tracker
Annual Security Program Review

State Privacy Law Readiness Checklist

Do you have these foundational privacy program documents in place?

Personal Data Inventory and Data Flow Map
Consumer Rights Request Procedures (access, deletion, opt-out)
Data Protection Impact Assessment (DPIA) process
Consent Management Framework
Vendor / Data Processor Agreement Tracker
Privacy Breach Response Plan
Privacy Policy (external-facing, compliant)
Annual Privacy Program Review

FTC Safeguards Rule (GLBA) Readiness Checklist

Do you have these foundational GLBA documents in place?

Written Information Security Program (WISP)
Customer Information Asset Inventory
Risk Assessment covering all required domains
MFA Assessment and Implementation Record
Service Provider Oversight and Agreement Log
Incident Response Plan
Employee Training Log
Board / Senior Management Annual Report

ADA Title II Digital Accessibility Readiness Checklist

Do you have these foundational accessibility program documents in place?

Written Accessibility Policy (public-facing)
Digital Asset Inventory (websites, apps, documents)
WCAG 2.1 AA Gap Analysis by asset
Accessibility Complaint / Grievance Procedure
Remediation Action Plan with owners and deadlines
Vendor Accessibility Review Tracker
Staff Training Log on accessibility requirements
Annual Accessibility Program Report

AI Governance Readiness Checklist

Do you have these foundational AI governance documents in place?

AI Governance Policy with Board-level adoption
AI System Inventory (all deployed models and tools)
AI Risk Classification Framework
AI Impact Assessment for high-risk systems
AI Deployment Readiness Checklist per system
AI Incident Response Plan
Chief AI Officer designation (if federal agency)
Annual AI Governance Program Report

Official U.S. Government Sources

Every VerdoCo document is derived from these official primary sources. Use these links to verify regulatory requirements directly against the authoritative government publication.

HHS / OCR

HIPAA Regulations

45 CFR Parts 160, 162, and 164 — the complete HIPAA regulatory text including Security Rule, Privacy Rule, and Breach Notification Rule.

hhs.gov/hipaa →
NIST

NIST SP 800-171 Rev 2

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations — the 110-control framework underlying CMMC Level 2.

csrc.nist.gov →
FTC

Safeguards Rule (16 CFR Part 314)

Standards for Safeguarding Customer Information — the 2023 amended rule requiring written information security programs for financial institutions.

ftc.gov →
DOJ

ADA Title II Final Rule (2024)

28 CFR Part 35 — DOJ's 2024 final rule establishing WCAG 2.1 AA as the enforceable digital accessibility standard for state and local governments.

ada.gov →
NIST

AI Risk Management Framework 1.0

NIST AI RMF 1.0 — the GOVERN, MAP, MEASURE, MANAGE framework for responsible AI development and deployment.

nist.gov →
SEC

Regulation S-P (17 CFR Part 248)

Privacy of Consumer Financial Information and Safeguarding Customer Information — including 2024 amendments to breach notification requirements.

sec.gov →
OSHA

29 CFR Parts 1904, 1910, 1926

OSHA recordkeeping requirements, general industry standards, and construction standards — the statutory basis for written program requirements.

osha.gov →
CPPA / State AGs

State Privacy Laws

California Privacy Rights Act (CPRA), Colorado Privacy Act (CPA), Virginia CDPA, and Texas Data Privacy and Security Act — the primary state privacy frameworks.

cppa.ca.gov →

Ready to Close the Gap?

Browse the complete VerdoCo catalogue and select the series that addresses your organization's documentation gap.

Browse All Series Read the FAQ

Resources provided for general informational purposes only. Regulatory guidance changes frequently — always verify requirements against current primary sources and consult qualified legal counsel. VerdoCo · A Product Line of Nexosprop Logistics Corp · All Rights Reserved.