@* Reviewed by counsel? Not yet. Have an attorney licensed in Florida review this page before launch. *@

These notices apply to this website and to the general descriptions of services published on it. They are provided by PlainScore IT Compliance and Security Group, LLC (“PlainScore,” “we,” “us”), a Florida limited liability company. When we perform work for a client, the signed engagement letter or statement of work governs that engagement. Where this page and an engagement letter differ, the engagement letter controls.

No professional advice

The content on this website is general information about information technology, security, and compliance. It is not legal advice, accounting advice, or an attestation opinion, and it is not a substitute for advice from a qualified professional who knows your facts. Reading this website, sending us a message, or receiving a proposal from us does not create an attorney-client, accountant-client, or fiduciary relationship. PlainScore is not a law firm and is not a licensed CPA firm.

Questions that turn on how a statute or regulation applies to your specific situation, such as whether a particular lawful basis is available under the GDPR, whether a given data flow is a “sale” under California law, or what a contract or regulator will accept, should be put to licensed counsel. We will tell you when a question is one of those, and we are glad to work alongside your counsel or CPA.

Assessment, attestation, and certification are different things

Our compliance work consists of assessments: we examine your controls, policies, and evidence against the requirements of a framework and report what we found. The words below have specific meanings, and we use them deliberately.

Assessment
We examined controls against stated requirements and reported findings, gaps, and recommendations. This is what PlainScore delivers.
Attestation
A qualified party formally attests to specified subject matter under a professional or industry scheme, for example a SOC 2 report issued by a licensed CPA firm under AICPA standards.
Certification
A recognized certification body formally certifies conformity, for example an accredited ISO/IEC 27001 certificate.
Self-attestation
Management itself declares compliance under an applicable process, for example a PCI DSS Self-Assessment Questionnaire or the executive certification required by California's cybersecurity audit regulations.
Audit opinion
A conclusion issued under a governing audit or attestation standard by someone licensed or qualified to issue it.
Attestation of Assessment
PlainScore's own deliverable. A signed letter and accompanying report in which PlainScore attests that it performed a defined assessment, describes the procedures performed and evidence examined, and states its findings and conclusion within the agreed scope. It is PlainScore's attestation to its own work, not a certification or an attestation report under an external scheme.

For every framework we work with, PlainScore issues an Attestation of Assessment letter and report. Clients use them to show customers, partners, insurers, and regulators that an independent assessment was performed and what it found. Unless a signed engagement letter expressly says otherwise and identifies the qualification under which we are acting, PlainScore does not issue certifications, attestation reports, or audit opinions under any external scheme. A PlainScore Attestation of Assessment, however favorable, does not make an organization “certified” under a scheme that requires a recognized third party, and we do not describe it that way.

Framework-specific disclaimers

The table summarizes the position for each framework we work with: what we assess, what we issue, and who provides the recognized sign-off where one exists. The sections that follow give the detail.

SOC 2

We perform SOC 2 readiness assessments, gap analyses, control mapping to the Trust Services Criteria, evidence collection, remediation, and mock audits. A SOC 2 Type I or Type II report is an attestation that must be issued by a licensed, independent CPA or CPA firm under AICPA attestation standards. PlainScore is not a CPA firm and does not issue SOC 2 reports. What PlainScore issues is an Attestation of Assessment letter and report: our signed attestation that we assessed your controls against the Trust Services Criteria, the procedures we performed, and what we found. It documents readiness for a SOC 2 examination and is not a substitute for one, and a clean result does not mean an organization “is SOC 2 compliant.” The usual path is: PlainScore assessment, Attestation of Assessment, and remediation, then an independent CPA firm's examination and report.

ISO/IEC 27001

We perform ISO/IEC 27001 gap assessments, ISMS design and implementation, Statement of Applicability development, internal audits, supplier audits, and certification readiness reviews. Accredited ISO/IEC 27001 certification can only be issued by a certification body, ideally one accredited by the applicable national accreditation body under ISO/IEC 17021. PlainScore is not a certification body. Holding an individual Lead Auditor or Lead Implementer credential does not allow us to issue accredited certificates. What PlainScore issues is an Attestation of Assessment letter and report covering the gap assessment or internal audit we performed, the clauses and Annex A controls examined, and our findings. Many organizations use it as the internal audit evidence a certification body expects to see, but it does not constitute certification.

HIPAA

We perform HIPAA Privacy Rule, Security Rule, and Breach Notification Rule assessments, including the Security Rule risk analysis, and we issue an Attestation of Assessment letter and report stating whether, based on our procedures, your implemented controls conform to the applicable requirements within scope. Because there is no official HIPAA certification, this independent attestation is often the strongest third-party evidence of compliance an organization can hold. The U.S. Department of Health and Human Services does not certify organizations and does not endorse or recognize private “HIPAA certified” programs, so PlainScore does not describe any organization as HIPAA certified. Covered entities and business associates remain responsible for their own HIPAA obligations, which are ongoing rather than point-in-time.

PCI DSS

We perform PCI DSS scoping, readiness and gap assessments, and remediation planning ahead of formal validation. PCI DSS validation is documented through the official mechanisms recognized by the PCI Security Standards Council: a Self-Assessment Questionnaire with an Attestation of Compliance where the organization is eligible, or a Report on Compliance with an Attestation of Compliance completed by a Qualified Security Assessor. A generic “PCI compliance certificate” is not an official validation mechanism. What PlainScore issues is an Attestation of Assessment letter and report documenting the scope we examined, the requirements assessed, and our findings; it supports your SAQ or your QSA's Report on Compliance but is not itself an Attestation of Compliance, Report on Compliance, or Self-Assessment Questionnaire. Unless a signed engagement letter states that we are acting as a Qualified Security Assessor, Internal Security Assessor, or Approved Scanning Vendor, PlainScore is not acting in any of those roles. Which validation route applies to you depends on your merchant or service-provider level and on your acquirer's and the payment brands' requirements, which we will help you identify but do not set.

GDPR

We perform GDPR privacy assessments, including review of Article 30 records of processing, data protection impact assessments, data protection officer programs, data-subject rights handling, controller and processor arrangements, breach management, Article 32 technical and organizational measures, international transfer arrangements, and privacy notices. There is no universal “GDPR certified” status. Certification mechanisms contemplated by Article 42 exist only where an approved scheme and accredited body apply, and PlainScore is not such a body. GDPR compliance is a legal accountability obligation of the controller or processor. What PlainScore issues is an Attestation of Assessment letter and report documenting the accountability measures, security controls, and processes we examined and our findings; it is evidence of the assessment for your records, supervisory authority, and counterparties. It is not a legal opinion. Determinations about lawful bases, cross-border transfer mechanisms, regulatory exposure, and similar questions of law should be made with qualified privacy counsel.

CCPA / CPRA

We perform California Consumer Privacy Act and California Privacy Rights Act assessments covering consumer rights handling, notices, contracts with service providers and contractors, and the cybersecurity, risk assessment, and automated decision-making requirements in the California Privacy Protection Agency's regulations. There is no general CCPA or CPRA compliance certificate. Regulations effective January 1, 2026 require certain businesses to complete a qualifying annual cybersecurity audit and to have an appropriate member of executive management certify its completion electronically under penalty of perjury. That certification is made by the business, not by its assessor. What PlainScore issues is an Attestation of Assessment letter and report documenting the requirements examined and our findings, which the business can rely on in preparing its own certification and in responding to consumers, counterparties, and the Agency. Unless a signed engagement letter states that PlainScore has confirmed it meets the regulations' independence and qualification requirements and is performing the cybersecurity audit itself, our work is a readiness assessment and not the regulatory audit.

NIST Cybersecurity Framework 2.0 and NIST SP 800-53

We perform independent NIST CSF 2.0 assessments across the Govern, Identify, Protect, Detect, Respond, and Recover functions, develop Current and Target Profiles, evaluate outcomes and subcategories under a defined methodology, and document gaps, evidence, and remediation plans. We perform the same work against NIST SP 800-53 control baselines. NIST does not certify organizations, products, or services against the CSF or SP 800-53, offers no endorsements, and has said it does not plan to establish a conformity assessment program. “NIST certified” is not a status any organization can hold, and PlainScore does not use the phrase. What PlainScore issues is an Attestation of Assessment letter and report: our signed attestation that an independent NIST assessment was performed, the profile and methodology used, and the results by function and subcategory. Because NIST offers no certification, this attestation is typically what customers, insurers, and contracting officers ask to see. NIST also cautions that the CSF is an outcome-based risk framework rather than a checklist, and our assessments treat it that way.

How our Attestation of Assessment letters and reports are worded

An Attestation of Assessment letter is signed by PlainScore, identifies the client, framework, scope, and assessment period, and attests that the assessment described in the accompanying report was performed. The report sets out the procedures performed, the evidence examined, the findings, and the conclusion. Consistent with the above, neither document declares an organization “fully compliant” or “certified.” A PlainScore conclusion is worded along these lines:

Based upon the procedures performed and the evidence examined, the assessment determined that the organization's implemented controls conform to the applicable requirements identified within the scope of this assessment, subject to the findings, limitations, and exclusions contained in this report.

Where a recognized external certification or attestation mechanism exists, the letter and report say so and state that they are not that mechanism. If you wish, we will help you engage the CPA firm, certification body, or assessor that can provide it.

No guarantee of outcomes

An assessment describes the state of your controls at a point in time, based on the information and evidence made available to us, and against the scope agreed in the engagement letter. It is not a guarantee that you will pass a later audit or examination, that a regulator, customer, acquirer, or insurer will accept your compliance posture, or that a security incident will not occur. Controls that were effective when we examined them can stop being effective. Frameworks, regulations, and their interpretation also change, and our findings speak to the requirements in force at the time of the assessment.

Client responsibilities

Our conclusions depend on the completeness and accuracy of what we are shown. Clients are responsible for providing accurate information and access, for the design and operation of their own controls, for deciding which findings to act on, and for their own compliance with the laws, regulations, contracts, and standards that apply to them. Nothing in an assessment transfers those responsibilities to PlainScore.

Website terms

This website is provided “as is” and “as available.” We try to keep its content accurate and current but make no warranty of any kind, express or implied, about its accuracy, completeness, reliability, or fitness for a particular purpose, and we may change or remove content at any time without notice. To the fullest extent permitted by applicable law, PlainScore and its members, managers, employees, and contractors are not liable for any direct, indirect, incidental, consequential, or other loss arising from your use of, or reliance on, this website or its content. Liability for services we perform under an engagement is governed by that engagement's terms, not by this page.

The site may link to third-party websites, including the sites of standards bodies and regulators. Those sites are not under our control, we are not responsible for their content or practices, and a link is not an endorsement. Our handling of information collected through this site is described in the Privacy Policy.

Third-party names and marks

SOC 2 and the Trust Services Criteria are associated with the American Institute of Certified Public Accountants. ISO and ISO/IEC 27001 are marks of the International Organization for Standardization. PCI DSS, QSA, ISA, and ASV are marks or program designations of PCI Security Standards Council, LLC. NIST, the NIST Cybersecurity Framework, and SP 800-53 are associated with the U.S. National Institute of Standards and Technology. HIPAA, the GDPR, and the CCPA/CPRA are laws of the United States, the European Union, and the State of California respectively. All names and marks belong to their owners. Their use on this site identifies the frameworks we work with and does not imply that any of those organizations endorses, sponsors, accredits, or is affiliated with PlainScore.

Governing law

These notices and any dispute about this website are governed by the laws of the State of Florida and applicable federal law of the United States, without regard to conflict-of-laws principles. Any such dispute shall be brought in the state or federal courts located in St. Johns County, Florida, and you consent to their jurisdiction. If any part of these notices is held unenforceable, the rest remains in effect.

Changes and contact

We may update these notices from time to time; the date at the top of the page shows the current version. Questions can be sent to info@plainscore.net, by phone at 904-257-6241, or by mail to PlainScore IT Compliance and Security Group, LLC, 432 Mallowbranch Dr, Saint Johns, FL 32259.