
A hospital that buys cameras with a federal rural health grant sits inside HIPAA, federal grant procurement rules, and whatever its state adds on top. None of those frameworks were written with the others in mind. They are organized around industries and agencies, so most organizations stack physical security obligations without a clear picture of where they overlap.
The good news is that most of these obligations reduce to four control areas. Once you know which frameworks apply, you are auditing the same four things against different evidence standards.
Use the matrix below to find your industry. The sections after it cover what each framework asks for and what auditors expect to see.
Four questions narrow the field, and they work best answered in this order.
1. Do you sell to, or receive funds from, the federal government? This is the biggest fork in the road. It pulls in procurement rules that have nothing to do with your industry and everything to do with who is paying for the system.
2. What regulated data lives in the building? Health records, cardholder data, criminal justice information, and student records each carry their own physical safeguard language. That language attaches to the room or system holding the data, not to the organization as a whole.
3. What does your state impose? Increasingly the binding requirement is a state law. School mapping laws, panic alarm mandates, biometric privacy statutes, and cannabis regulations are all state-driven. They vary enough that a national organization can be compliant in one location and exposed in another.
4. Who audits you, and what evidence do they accept? Two frameworks can demand the same control and accept different proof. A retention policy that satisfies a SOC 2 auditor will not automatically satisfy a CJIS triennial audit.
Answer all four and a pattern shows up. Nearly every framework asks about perimeter and entry control, identity and authorization, monitoring and recording, and evidence and retention. What changes is the evidence each one accepts, which is why the matrix below is organized by industry.
Most teams start with Question 2 and list every type of regulated data on site, because that feels like the natural start of a security review. Question 1 changes the shape of the whole answer, so it has to come first.
Take a hospital that bought its camera system with a federal rural health grant:
Start with HIPAA, and the grant rule and the state biometric law tend to surface late, usually after the equipment is already bought.
The table maps nine industries against the four categories of obligation that show up repeatedly: federal procurement rules, data-specific frameworks, state-driven requirements, and the audit framework that typically reviews the program. Cells describe what each framework asks about, not whether any vendor satisfies it. That depends on configuration, deployment, and jurisdiction.
NDAA obligations show up in six of the nine rows. For any organization touching federal money, directly or through a grant, it is the largest single compliance question in this space. For a plain-language primer, see what NDAA compliance means.
Every framework above eventually asks the same four questions about a facility, even when the language and evidence standards differ.
Auditors want to see how the boundary of a secure area is defined and enforced, from the door hardware itself to how vestibules and mantraps handle tailgating and forced entry. This is usually the easiest area to demonstrate, since the hardware either exists or it does not.
This covers who can grant access, who can revoke it, and how quickly revocation happens after a termination or role change. Frameworks generally expect two things regardless of industry:
Most frameworks treat a stale access list as a finding on its own, whether or not anyone misused it.
Frameworks generally ask whether video covers defined entry points, whether recordings are reviewed at a regular cadence, and whether monitoring continues after hours. Teams that staff monitoring only during business hours often have a gap here that nobody notices until an after-hours incident.
This is the area teams underestimate most. Most organizations can point to cameras covering the areas that matter. Far fewer can produce a specific clip from 14 months ago, along with a retention record and a history of who accessed it and when.
Technical retention alone rarely satisfies an auditor. They need two things in writing:
For agencies and any contractor handling criminal justice information, the primary driver is Section 5.9 of the CJIS Security Policy, Physical and Environmental Protection. Version 6.0, released in December 2024, rebuilt the policy around NIST SP 800-53 control families. The core idea is unchanged: a "physically secure location" is a facility or room with physical and personnel controls sufficient to protect criminal justice information. The policy expects a current list of people authorized to enter it, visitor logs with escort requirements, and background checks for anyone with unescorted access.
Federal facilities and PIV-card environments add FIPS 201, which governs the credential rather than the door hardware behind it. Where procurement dollars are federal, NDAA Section 889 restrictions on camera and surveillance manufacturers apply on top of both.
The most common miss is an authorized-access list that was accurate at the last audit and never touched since. Auditors check it against actual staffing changes during the on-site walkthrough.
What auditors ask for:
HIPAA's Security Rule, at 45 CFR §164.310, sets standards for facility access controls, workstation security, and device and media controls. Some implementation specifications are required and some are addressable. Addressable still requires a documented, risk-based decision, and treating it as optional is a common misreading.
One 2026 caveat: HHS proposed eliminating the addressable category in January 2025. As of September 2026 that rule is still a proposal, and the current Security Rule is what OCR enforces. Where a hospital runs on federal grant funding, NDAA restrictions can apply alongside HIPAA, and state privacy statutes layer on top of both.
The requirement most often missed is the written rationale behind an addressable decision. Teams implement a control and skip the paperwork, which leaves an auditor nothing to review if the control is questioned. For camera-specific guidance, see hospital security cameras.
What auditors ask for:
Federal obligations touch K-12 mainly through FERPA and, where a district receives federal funding, NDAA. The requirements that drive budget and procurement are state laws.
Thirteen states have enacted versions of Alyssa's Law as of 2026, mandating silent panic alarms with a direct connection to law enforcement, and more bills are pending. Several states also mandate school mapping data that first responders can reach during an active incident. Georgia's version requires both.
The gap teams miss is the mapping data behind the alarm. An alarm that reaches dispatch without a current floor plan attached slows the response it was built to speed up.
What auditors ask for:
Financial institutions carry physical security obligations that rarely get reconciled with each other. PCI DSS Requirement 9 governs physical access to any system housing cardholder data. One of its more overlooked provisions, Requirement 9.5.1.2 in version 4.0.1, calls for periodic inspection of point-of-interaction devices such as card readers.
Less visible is the FTC's GLBA Safeguards Rule. It requires an information security program with administrative, technical, and physical safeguards for non-bank financial institutions, and its definition reaches auto dealers with in-house financing and other lenders that don't think of themselves as regulated.
SOC 2's Trust Services Criteria address physical access under CC6. SOC 2 is principles-based: the organization defines its own controls, and the auditor evaluates whether they satisfy the criteria.
Two misses come up most. The first is the PCI device inspection log: an undocumented visual check of a terminal does not count as evidence. The second, for non-bank lenders, is not realizing GLBA applies at all.
What auditors ask for:
Retail carries the same PCI DSS Requirement 9 obligations wherever card data is processed, plus a newer layer that has nothing to do with payments. A growing list of states regulates biometric data directly, requiring written notice and consent before fingerprint, facial, or palm data is collected from employees or customers. Illinois' BIPA also gives individuals a private right of action. A chain can pass PCI everywhere and still be exposed on biometric consent in a handful of locations.
The common mistake is treating biometric consent as a one-time IT decision instead of a per-location legal review. For how the hardware side works, see our guide to biometric access control systems.
What auditors ask for:
Data centers answer to SOC 2's CC6 criteria as a baseline. Operators tied to the Bulk Electric System add NERC CIP-006, which requires a documented physical security plan for covered systems, and CIP-014, which requires periodic risk assessments and threat and vulnerability evaluations for covered transmission facilities. Federally contracted data centers layer NDAA restrictions on top.
A data center does not carry a fixed data-specific framework of its own. HIPAA, PCI DSS, and similar frameworks attach based on what each tenant stores, so a multi-tenant facility can answer to several at once depending on the workload in each cage or rack.
The miss here is the assessment cadence. A NERC CIP plan that exists on paper is not enough; auditors want evidence it was reassessed on the schedule the standard sets.
What auditors ask for:
Manufacturers in the defense supply chain face NDAA restrictions on camera and surveillance equipment. Facilities handling defense articles or technical data add ITAR, 22 CFR Parts 120 through 130, which prohibits releasing controlled items or data to foreign persons without authorization. Most covered facilities document how they prevent that in a Technology Control Plan covering badging, escorts, and restricted areas.
Outside the defense supply chain, the binding requirement is usually whatever a customer's own audit specifies.
The common failure is a badging and visitor process that never captures whether a person is a U.S. person, which leaves the Technology Control Plan with nothing to enforce against.
What auditors ask for:
Multi-family properties rarely carry a federal or industry audit obligation, but the compliance picture is still real. State biometric and tenant privacy laws increasingly govern keyless entry that uses fingerprint or facial recognition, starting with notice to tenants and consent.
Where a property is federally assisted, HUD's National Standards for the Physical Inspection of Real Estate (NSPIRE) brings its own inspection cycle. NSPIRE is framed around habitability and life safety, but it covers systems that overlap with physical security, including door hardware condition and life-safety equipment. A failed inspection can put federal assistance at risk.
The practical gap is the tenant who declines biometric entry. A property with proper notice but no workable non-biometric option is set up for a dispute, so check local law and plan the fallback before rollout.
What auditors ask for:
Faith-based organizations and nonprofits typically have no industry audit framework, but grant funding brings its own conditions. Where a grant funds security equipment, the grantor sets the bar, and NDAA restrictions apply if the money traces back to a federal source.
The mistake is treating grant conditions as a one-time application hurdle. They are an ongoing obligation the grantor can review.
What auditors ask for:
Most teams build their audit package from four places: a badge system, a video recorder, a visitor log, and a spreadsheet tracking who asked for what. Someone reconciles them by hand before every audit.
Coram is an AI physical security platform that brings Video Security, Access Control, Guest Management, and Emergency Management into one dashboard. It works with the IP cameras you already have (any camera that streams RTSP in H.264 or H.265), so modernizing the evidence trail doesn't start with replacing hardware. Here is what that means for the four control areas:
On Coram's own posture: Coram is SOC 2 Type II audited and HIPAA compliant, and Coram-branded cameras are NDAA-compliant, with a self-attestation letter available on request. Details are on the Coram Trust Hub. Whether a specific deployment satisfies CJIS, FIPS, PCI DSS, or any other framework depends on configuration, deployment, and jurisdiction, so work through it with your auditor and our team.
Best for: security teams running video, access, and visitor management as separate systems who want one place to pull evidence before the next audit cycle.
Book a demo to map your compliance requirements against the platform.
HIPAA physical safeguards are the baseline for any covered entity. NDAA restrictions apply where federal grant funding bought the equipment, and state privacy statutes add further requirements. The Joint Commission or CMS typically reviews the program.
Section 889 binds federal agencies directly and reaches private companies through federal contracts and grants. Part A bars contractors from providing covered equipment to the government. Part B bars agencies from contracting with any entity that uses covered equipment, anywhere in its operations. Grant recipients are covered through 2 CFR 200.216, which bars spending grant funds on it. A company with no federal contract, subcontract, or grant falls outside it.
The part most organizations underestimate is Part B's reach. Keeping covered cameras in an unrelated part of the business does not preserve eligibility for a federal prime contract.
The Security Rule at 45 CFR §164.310 requires facility access controls, workstation security, and device and media controls. Some specifications are required outright. Addressable specifications require a documented, risk-based decision.
CJIS Section 5.9 requires a designated physically secure location, a maintained and periodically reviewed list of authorized personnel, visitor logging with escorts, and background checks for anyone with unescorted access to criminal justice information.
There is no single number. The binding retention period is whatever your framework, state statute, or grant agreement names, and it should be written into policy. For typical ranges by industry, see how long security cameras keep footage.
Yes. States with biometric privacy statutes generally require written notice and consent before collecting fingerprint, facial, or palm data. Illinois' BIPA adds a private right of action, so a system that is compliant everywhere else can still be exposed on consent.
Most frameworks converge on the same package: an access authorization list reviewed on a set schedule, credential issuance and revocation records, visitor logs, and video coverage of entry points with a documented retention policy.
No single federal framework governs K-12 physical security directly. FERPA and, where applicable, NDAA touch the edges. The requirements that drive procurement are state laws modeled on Alyssa's Law, covering panic alarms and school mapping data.

