The Compliance Blind Spot: The Rules Wisconsin Small Businesses Miss
Compliance isn't only for hospitals and banks. The five rules that catch Wisconsin small businesses most often, why the gaps happen, and how to close them.

When I sit down with a new client, one of the first things I hear is "compliance doesn't really apply to us." Most owners assume it's for hospitals, banks and big companies. Then a customer asks for a security questionnaire, an insurer won't renew without proof of multi-factor sign-in, or a card processor sends a notice. That's the blind spot: rules that already apply to you, which nobody told you about.
Here are the five that catch Wisconsin small businesses most often.
1. Wisconsin's breach notification law
If you keep personal information about Wisconsin residents, section 134.98 of state law applies to you. That includes Social Security numbers, driver's license numbers, bank account or card numbers with their codes, and biometric data. If it's stolen, you must notify the people affected within a reasonable time, no more than 45 days. Almost every employer keeps some of this, in payroll and HR files if nowhere else.
2. The FTC Safeguards Rule
This federal rule covers far more businesses than its name suggests: tax preparers, auto dealers that arrange financing, mortgage brokers, and other "non-bank financial institutions". It requires a written information security program with a named person in charge, risk assessments, multi-factor sign-in and encryption. Since May 13, 2024, a breach affecting 500 or more customers must also be reported to the FTC within 30 days.
3. PCI DSS, if you take cards
Every business that accepts card payments agrees to the card industry's security standard through its processor. Version 4.0.1 became fully mandatory on March 31, 2025. Among the changes, multi-factor sign-in is now required for any access to systems that handle card data. Many small merchants are still filling out last year's self-assessment as if nothing changed.
4. HIPAA, including for the businesses that serve healthcare
Clinics and dental offices know HIPAA applies to them. Their vendors often don't. If you handle patient information for a healthcare client, you are likely a "business associate" and share the same obligations.
5. CMMC, for manufacturers in the defense supply chain
The Pentagon's Cybersecurity Maturity Model Certification rule took effect November 10, 2025. During this first phase, defense contracts can require a self-assessment at Level 1 or Level 2 as a condition of award, and the requirement tightens in later phases. Northeast Wisconsin has plenty of machine shops and fabricators a tier or two down from a defense prime. If a customer has mentioned CMMC, it's time to start.
And the one that isn't a law: your cyber insurance application
Insurers now ask about specific controls by name: multi-factor sign-in, endpoint detection, tested backups, security training. Answer "yes" to something that isn't really in place, and a claim can be denied when you need it most. In practice, the insurance questionnaire has become the compliance standard most small businesses are actually held to.
Why the gaps happen
- "We're too small for that." The rules above are triggered by the data you hold, not your headcount.
- "Our software vendor handles it." A vendor covers its own systems, not your laptops, email or file shares.
- Nothing is written down. Most rules ask for written policies and proof, not just good intentions.
How to close them
- Make a list of the sensitive data you keep and where it lives.
- Match that list to the rules above. Most businesses need two or three, not all five.
- Write the policy. For the Safeguards Rule, that's a Written Information Security Program.
- Turn on the controls that show up everywhere: multi-factor sign-in, monitored endpoint protection, encrypted devices, and tested backups.
- Keep the evidence: training records, access reviews, backup test results. That's what auditors and insurers ask for.
- Review it once a year, and whenever you add a new system or service.
Most of the businesses we work with need two or three of these rules, a few written policies and a handful of controls they mostly already have. The hard part is knowing which ones apply, and that's a conversation I'm always happy to have.
Not sure where your business stands on this?
We’ll walk through how you handle it today and tell you straight whether it needs attention.