Onyx Blog

Insights on security and compliance

Practical, no-nonsense guidance on PCI, ISO 27001, GDPR, penetration testing, and building an audit-ready security posture.

PCI DSS Level 1: What It Takes

PCI DSS Level 1 is the highest merchant compliance level, validated by an annual QSA-led Report on Compliance plus quarterly ASV scans and penetration testing at least annually and after significant changes. What it takes to meet Level 1 requirements.

SOC 2 Readiness Assessment: What to Expect

A SOC 2 readiness assessment scopes criteria, assesses security controls, identifies gaps, and produces a remediation plan before the audit. What to expect and why it saves money.

The ISO 27001 Certification Process, Step by Step

The ISO 27001 certification process step by step: scope, gap analyses, risk assessment, Statement of Applicability, controls, internal audit, the two-stage certification audit, and surveillance.

PCI DSS SAQ Types Explained: Which One Applies to You?

PCI DSS SAQ types explained: SAQ A, A-EP, B, B-IP, C, C-VT, P2PE, and D. How to complete the right Self-Assessment Questionnaire based on how you take payments, and how to qualify for a simpler one.

HIPAA Compliance for Startups: A Practical Guide

HIPAA compliance for startups: when it applies, what HIPAA requirements to meet, and how to build safeguards in from day one without slowing your product.

SOC 2 for SaaS Companies: The Practical Guide

SOC 2 compliance for SaaS: Trust Services Criteria, cloud security controls auditors look at, and how to achieve SOC 2 with Type 1 then Type 2. A practical guide.

GDPR Compliance Checklist: The Essentials

A practical GDPR compliance checklist: data protection, personal data inventory, lawful basis, data subject rights, breach response, and transfers.

What Is an Approved Scanning Vendor (ASV)?

An Approved Scanning Vendor (ASV) is a PCI SSC-approved organisation that performs the external vulnerability scanning PCI DSS requires, at least quarterly. What a PCI ASV is, why you need one, and how ASV scans work.

ISO 27001 vs SOC 2: Which Do You Need?

ISO 27001 vs SOC 2: one is a global certificate, the other a US attestation report. Who asks for which, how they overlap, what the difference is, and how to choose.

SOC 2 Type 1 vs Type 2: Which Do You Need?

Key differences between SOC 2 Type 1 and Type 2: Type 1 proves control design at a point in time, Type 2 proves operating effectiveness over a period. Which to pursue and when.