Back

Physical Security Compliance: Frameworks by Industry (2026)

See which physical security compliance frameworks apply to your industry: 9 sectors mapped against HIPAA, NDAA, CJIS, PCI DSS, and the controls auditors check.

Stu Waters
Stu Waters
Published
Sep 25, 2026

A hospital that buys cameras with a federal rural health grant sits inside HIPAA, federal grant procurement rules, and whatever its state adds on top. None of those frameworks were written with the others in mind. They are organized around industries and agencies, so most organizations stack physical security obligations without a clear picture of where they overlap.

The good news is that most of these obligations reduce to four control areas. Once you know which frameworks apply, you are auditing the same four things against different evidence standards.

Use the matrix below to find your industry. The sections after it cover what each framework asks for and what auditors expect to see.

TL;DR

  • Four questions determine which frameworks apply to you: federal funding, regulated data, state law, and who audits you. Answer them in that order.
  • The matrix maps nine industries against federal, data-specific, state, and audit requirements, so you can find your row without reading every section.
  • Every framework comes back to the same four control areas: perimeter and entry, identity and authorization, monitoring, and evidence and retention. The frameworks differ on the proof they accept.
  • Each industry section names the requirement teams miss most and the evidence an auditor asks for.
  • Coram puts video, door events, visitor check-ins, and emergency activations in one dashboard, with an audit log of who viewed, searched, exported, or shared footage.

How to determine which physical security compliance frameworks apply to you

Four questions narrow the field, and they work best answered in this order.

1. Do you sell to, or receive funds from, the federal government? This is the biggest fork in the road. It pulls in procurement rules that have nothing to do with your industry and everything to do with who is paying for the system.

2. What regulated data lives in the building? Health records, cardholder data, criminal justice information, and student records each carry their own physical safeguard language. That language attaches to the room or system holding the data, not to the organization as a whole.

3. What does your state impose? Increasingly the binding requirement is a state law. School mapping laws, panic alarm mandates, biometric privacy statutes, and cannabis regulations are all state-driven. They vary enough that a national organization can be compliant in one location and exposed in another.

4. Who audits you, and what evidence do they accept? Two frameworks can demand the same control and accept different proof. A retention policy that satisfies a SOC 2 auditor will not automatically satisfy a CJIS triennial audit.

Answer all four and a pattern shows up. Nearly every framework asks about perimeter and entry control, identity and authorization, monitoring and recording, and evidence and retention. What changes is the evidence each one accepts, which is why the matrix below is organized by industry.

Why the order matters

Most teams start with Question 2 and list every type of regulated data on site, because that feels like the natural start of a security review. Question 1 changes the shape of the whole answer, so it has to come first.

Take a hospital that bought its camera system with a federal rural health grant:

  • Question 1 pulls in NDAA Section 889 through the federal grant rule at 2 CFR 200.216, which bars grant funds from buying covered video surveillance equipment. That applies before HIPAA enters the picture.
  • Question 2 pulls in HIPAA physical safeguards regardless of the grant, since that obligation attaches to the patient data, not the funding source.
  • Question 3 depends on where the hospital sits. A facility in Illinois faces biometric consent obligations under BIPA that a facility in Texas does not, with identical equipment and identical patient records.
  • Question 4 decides whether Joint Commission accreditation, a state health department survey, or both will review the program. That shapes what evidence gets collected day to day.

Start with HIPAA, and the grant rule and the state biometric law tend to surface late, usually after the equipment is already bought.

Physical security compliance framework matrix by industry

The table maps nine industries against the four categories of obligation that show up repeatedly: federal procurement rules, data-specific frameworks, state-driven requirements, and the audit framework that typically reviews the program. Cells describe what each framework asks about, not whether any vendor satisfies it. That depends on configuration, deployment, and jurisdiction.

NDAA obligations show up in six of the nine rows. For any organization touching federal money, directly or through a grant, it is the largest single compliance question in this space. For a plain-language primer, see what NDAA compliance means.

Industry Federal procurement rules Data-specific State-driven Audit framework
K-12 education NDAA where federally funded FERPA State panic alarm and mapping laws State department of education
Healthcare NDAA where federally funded HIPAA physical safeguards State privacy statutes Joint Commission, CMS
Government and public safety NDAA, FIPS 201 CJIS State procurement rules Agency audit
Financial services None typical PCI DSS, GLBA Safeguards Rule State privacy statutes SOC 2, PCI assessor
Data centers and critical infrastructure NDAA where federally contracted Inherited from tenant workloads None typical SOC 2, NERC CIP
Manufacturing and industrial NDAA for the defense supply chain ITAR where applicable None typical Customer audit
Retail None typical PCI DSS State biometric laws PCI assessor
Multi-family residential None typical None typical State biometric and tenant privacy laws HUD NSPIRE where federally assisted
Faith-based and nonprofit NDAA where federally granted None typical State grant conditions Grantor

The four control areas behind every framework

Every framework above eventually asks the same four questions about a facility, even when the language and evidence standards differ.

Perimeter and entry control

Auditors want to see how the boundary of a secure area is defined and enforced, from the door hardware itself to how vestibules and mantraps handle tailgating and forced entry. This is usually the easiest area to demonstrate, since the hardware either exists or it does not.

Identity and authorization

This covers who can grant access, who can revoke it, and how quickly revocation happens after a termination or role change. Frameworks generally expect two things regardless of industry:

  • A current, named list of who can grant or revoke access, reviewed on a set schedule
  • A revocation timeline short enough that a termination does not leave standing access behind

Most frameworks treat a stale access list as a finding on its own, whether or not anyone misused it.

Monitoring and recording

Frameworks generally ask whether video covers defined entry points, whether recordings are reviewed at a regular cadence, and whether monitoring continues after hours. Teams that staff monitoring only during business hours often have a gap here that nobody notices until an after-hours incident.

Evidence and retention

This is the area teams underestimate most. Most organizations can point to cameras covering the areas that matter. Far fewer can produce a specific clip from 14 months ago, along with a retention record and a history of who accessed it and when.

Technical retention alone rarely satisfies an auditor. They need two things in writing:

  • The retention period itself, stated in policy text and not inferred from a system's default settings
  • An access history for any footage that was pulled, showing who viewed or exported it and when

Government and public safety: CJIS and FIPS 201

For agencies and any contractor handling criminal justice information, the primary driver is Section 5.9 of the CJIS Security Policy, Physical and Environmental Protection. Version 6.0, released in December 2024, rebuilt the policy around NIST SP 800-53 control families. The core idea is unchanged: a "physically secure location" is a facility or room with physical and personnel controls sufficient to protect criminal justice information. The policy expects a current list of people authorized to enter it, visitor logs with escort requirements, and background checks for anyone with unescorted access.

Federal facilities and PIV-card environments add FIPS 201, which governs the credential rather than the door hardware behind it. Where procurement dollars are federal, NDAA Section 889 restrictions on camera and surveillance manufacturers apply on top of both.

The most common miss is an authorized-access list that was accurate at the last audit and never touched since. Auditors check it against actual staffing changes during the on-site walkthrough.

What auditors ask for:

  • The physically secure location designation itself
  • Visitor logs showing entry, exit, purpose, and escort
  • A documented process for revoking access on termination or transfer

Healthcare: HIPAA physical safeguards

HIPAA's Security Rule, at 45 CFR §164.310, sets standards for facility access controls, workstation security, and device and media controls. Some implementation specifications are required and some are addressable. Addressable still requires a documented, risk-based decision, and treating it as optional is a common misreading.

One 2026 caveat: HHS proposed eliminating the addressable category in January 2025. As of September 2026 that rule is still a proposal, and the current Security Rule is what OCR enforces. Where a hospital runs on federal grant funding, NDAA restrictions can apply alongside HIPAA, and state privacy statutes layer on top of both.

The requirement most often missed is the written rationale behind an addressable decision. Teams implement a control and skip the paperwork, which leaves an auditor nothing to review if the control is questioned. For camera-specific guidance, see hospital security cameras.

What auditors ask for:

  • Facility access logs tied to workstation locations
  • Device and media disposal records
  • The written rationale behind any addressable specification the organization chose not to implement

K-12 education: state mapping and panic alarm laws

Federal obligations touch K-12 mainly through FERPA and, where a district receives federal funding, NDAA. The requirements that drive budget and procurement are state laws.

Thirteen states have enacted versions of Alyssa's Law as of 2026, mandating silent panic alarms with a direct connection to law enforcement, and more bills are pending. Several states also mandate school mapping data that first responders can reach during an active incident. Georgia's version requires both.

The gap teams miss is the mapping data behind the alarm. An alarm that reaches dispatch without a current floor plan attached slows the response it was built to speed up.

What auditors ask for:

  • Proof of the direct law enforcement connection
  • Evidence that mapping data is kept current
  • A documented drill or test cadence for the alarm system

Financial services: PCI DSS, GLBA, and SOC 2

Financial institutions carry physical security obligations that rarely get reconciled with each other. PCI DSS Requirement 9 governs physical access to any system housing cardholder data. One of its more overlooked provisions, Requirement 9.5.1.2 in version 4.0.1, calls for periodic inspection of point-of-interaction devices such as card readers.

Less visible is the FTC's GLBA Safeguards Rule. It requires an information security program with administrative, technical, and physical safeguards for non-bank financial institutions, and its definition reaches auto dealers with in-house financing and other lenders that don't think of themselves as regulated.

SOC 2's Trust Services Criteria address physical access under CC6. SOC 2 is principles-based: the organization defines its own controls, and the auditor evaluates whether they satisfy the criteria.

Two misses come up most. The first is the PCI device inspection log: an undocumented visual check of a terminal does not count as evidence. The second, for non-bank lenders, is not realizing GLBA applies at all.

What auditors ask for:

  • Cardholder data environment access logs
  • The device inspection schedule, with dates
  • For SOC 2, a written mapping of internal controls to the CC6 criteria selected for the audit

Retail: PCI DSS and state biometric laws

Retail carries the same PCI DSS Requirement 9 obligations wherever card data is processed, plus a newer layer that has nothing to do with payments. A growing list of states regulates biometric data directly, requiring written notice and consent before fingerprint, facial, or palm data is collected from employees or customers. Illinois' BIPA also gives individuals a private right of action. A chain can pass PCI everywhere and still be exposed on biometric consent in a handful of locations.

The common mistake is treating biometric consent as a one-time IT decision instead of a per-location legal review. For how the hardware side works, see our guide to biometric access control systems.

What auditors ask for:

  • PCI device inspection records
  • Notice and consent records wherever biometric technology is deployed

Data centers and critical infrastructure: SOC 2 and NERC CIP

Data centers answer to SOC 2's CC6 criteria as a baseline. Operators tied to the Bulk Electric System add NERC CIP-006, which requires a documented physical security plan for covered systems, and CIP-014, which requires periodic risk assessments and threat and vulnerability evaluations for covered transmission facilities. Federally contracted data centers layer NDAA restrictions on top.

A data center does not carry a fixed data-specific framework of its own. HIPAA, PCI DSS, and similar frameworks attach based on what each tenant stores, so a multi-tenant facility can answer to several at once depending on the workload in each cage or rack.

The miss here is the assessment cadence. A NERC CIP plan that exists on paper is not enough; auditors want evidence it was reassessed on the schedule the standard sets.

What auditors ask for:

  • The physical security plan itself
  • Assessment records with dates
  • For SOC 2, evidence that access and monitoring controls map to the CC6 criteria the auditor selected

Manufacturing and industrial: NDAA and ITAR

Manufacturers in the defense supply chain face NDAA restrictions on camera and surveillance equipment. Facilities handling defense articles or technical data add ITAR, 22 CFR Parts 120 through 130, which prohibits releasing controlled items or data to foreign persons without authorization. Most covered facilities document how they prevent that in a Technology Control Plan covering badging, escorts, and restricted areas.

Outside the defense supply chain, the binding requirement is usually whatever a customer's own audit specifies.

The common failure is a badging and visitor process that never captures whether a person is a U.S. person, which leaves the Technology Control Plan with nothing to enforce against.

What auditors ask for:

  • NDAA-compliant equipment documentation where applicable
  • For ITAR-covered facilities, visitor records that capture U.S. person status for anyone without standing access

Multi-family residential: state biometric and tenant privacy laws

Multi-family properties rarely carry a federal or industry audit obligation, but the compliance picture is still real. State biometric and tenant privacy laws increasingly govern keyless entry that uses fingerprint or facial recognition, starting with notice to tenants and consent.

Where a property is federally assisted, HUD's National Standards for the Physical Inspection of Real Estate (NSPIRE) brings its own inspection cycle. NSPIRE is framed around habitability and life safety, but it covers systems that overlap with physical security, including door hardware condition and life-safety equipment. A failed inspection can put federal assistance at risk.

The practical gap is the tenant who declines biometric entry. A property with proper notice but no workable non-biometric option is set up for a dispute, so check local law and plan the fallback before rollout.

What auditors ask for:

  • For federally assisted properties, NSPIRE inspection results
  • For everything else, documentation a property manager can produce if a tenant or regulator asks: notice language, consent records, and the non-biometric option

Faith-based and nonprofit: grant conditions

Faith-based organizations and nonprofits typically have no industry audit framework, but grant funding brings its own conditions. Where a grant funds security equipment, the grantor sets the bar, and NDAA restrictions apply if the money traces back to a federal source.

The mistake is treating grant conditions as a one-time application hurdle. They are an ongoing obligation the grantor can review.

What auditors ask for:

  • The grant agreement's security equipment provisions
  • Records showing the funded equipment still meets those provisions after installation

How Coram fits into a physical security compliance program

Most teams build their audit package from four places: a badge system, a video recorder, a visitor log, and a spreadsheet tracking who asked for what. Someone reconciles them by hand before every audit.

Coram is an AI physical security platform that brings Video Security, Access Control, Guest Management, and Emergency Management into one dashboard. It works with the IP cameras you already have (any camera that streams RTSP in H.264 or H.265), so modernizing the evidence trail doesn't start with replacing hardware. Here is what that means for the four control areas:

  • Door events next to door video. Access Control logs door events and raises held-open, forced-entry, and tailgating alerts, with video from that door in the same view.
  • An audit log of who touched the footage. Logins, live views, searches, playback, exports, shared links, deletions, and user and permission changes are all logged, and the log is protected against modification.
  • Exports an auditor can open. Clips export to standard MP4 with timestamp, camera, and time zone metadata. The audit log records who exported or shared them, and shared links can be set to expire.
  • Retention past the recorder. Footage records on site to a Coram Point appliance, sized to 30, 60, or 90 days, and keeps recording through internet outages. Clips archived to Video Vault stay available for as long as your organization is active, so the 14-month-old clip still exists.
  • Visitor records with context. Guest Management captures each visitor's name, photo, verified ID, host, signed NDA, and check-in and check-out times, with entrance camera playback on the guest record. It never stores ID images or dates of birth.
  • Emergency records and drills. Emergency Management logs who activated an emergency, from where, and every action that followed. Drills are marked as exercises, and Automatic Dispatch to 911 is available per organization on request.
  • Biometrics off until you choose. Facial recognition ships off by default and an admin has to enable it, which matters wherever state biometric privacy laws apply.

On Coram's own posture: Coram is SOC 2 Type II audited and HIPAA compliant, and Coram-branded cameras are NDAA-compliant, with a self-attestation letter available on request. Details are on the Coram Trust Hub. Whether a specific deployment satisfies CJIS, FIPS, PCI DSS, or any other framework depends on configuration, deployment, and jurisdiction, so work through it with your auditor and our team.

Best for: security teams running video, access, and visitor management as separate systems who want one place to pull evidence before the next audit cycle.

Book a demo to map your compliance requirements against the platform.

FAQ

Which physical security frameworks apply to a hospital?
Does NDAA Section 889 apply to a private company, or only to government agencies?
What does HIPAA require for physical security?
What physical security controls does CJIS require?
How long do we need to retain security camera footage for compliance?
Do state biometric privacy laws affect access control that uses fingerprints or faces?
What evidence does an auditor ask for on physical access controls?
Which framework governs school security requirements?

Get an Instant Quote