| track | frontier-platforms |
|---|---|
| status | published |
43% of cyberattacks target small businesses. 60% go out of business within 6 months of a breach. 33M US SMBs need affordable compliance β but existing open-source tools focus only on tech startups and SOC 2/ISO 27001.
Regulations exploding: CCPA, GDPR, HIPAA, PCI-DSS, CMMC, 15+ state privacy laws. Traditional tools (Vanta, Drata, Secureframe) cost $10K-$50K+/year. Open-source tools (Comp AI, Probo) serve VC-funded tech startups, not Main Street (retail, construction, professional services). No platform provides a compliance navigator that maps an SMB's specific obligations and automates evidence collection from their tech stack.
| Solution | Limitation |
|---|---|
| Vanta | $10K+/year, SOC 2 only, startup focused |
| Drata | $15K+/year, startup focused |
| Comp AI | Open-source, SOC 2/ISO 27001 only, startup focused |
| Probo | Open-source GRC, engineering team focused |
| DIY spreadsheets | Can't produce evidence; unreliable |
- Regulatory obligation mapper β business type + size + location + revenue β applicable regulations
- Control framework generator β tailored from applicable regs (no over/under-compliance)
- Evidence collection agents β connectors for Google Workspace, QuickBooks, Square, Shopify, AWS
- Risk-based prioritizer β highest-risk controls first given SMB budget constraints
- Audit report automation β regulator-ready documentation
- AI policy writer β context-specific security policies for non-technical owners
MVP (2-3 months solo): Regulatory KB (20+ regulations) β compliance questionnaire β control framework β basic connectors β audit reports
- 33M US small businesses (99.9% of all businesses)
- 62M+ US SMB employees
- 300K+ defense contractors affected by CMMC
- Every healthcare practice (HIPAA), every business with CA customers (CCPA)
- Cyber insurance industry ($30B+ market)
| Source | Description |
|---|---|
| CVE / NIST NVD | Common vulnerabilities |
| CISA KEV | Known Exploited Vulnerabilities |
| NIST CSF | Cybersecurity Framework (free) |
| NIST SP 800-53 | Control catalog |
| CMMC Model (DoD) | Cybersecurity maturity model (free) |
| GDPR / CCPA/CPRA | Regulatory text (free) |
- SMB Cybersecurity Challenges (2023) β IEEE Access. 500+ SMBs: 87% no dedicated security staff
- Automated Compliance Framework (2022) β J Cybersecurity and Privacy
- Lallie et al. (2021) β "Cyber security in the age of COVID-19" β Computers & Security
- CMMC Analysis (2024) β J Strategic Security. SMB defense contractor burden
- AI for Regulatory Compliance Review (2023) β Artificial Intelligence and Law
- Comp AI β AGPLv3, SOC 2/ISO 27001/GDPR. Most mature OS compliance tool
- Probo β MIT, Go GRC with MCP API
- Bubba AI β SOC 2/ISO 27001 for startups
- OpenSCAP β NIST-certified security automation
- Regulatory knowledge (GDPR, CCPA, HIPAA, CMMC, PCI-DSS)
- Full-stack web dev (React + Python/FastAPI)
- API integration (Google Workspace, QuickBooks, Shopify)
- Document generation (PDF forms)
- LLM integration (policy writer)
- Comp AI has strong momentum β need differentiation on SMB breadth not startup depth
- SMBs are notoriously low-spending on software
- Compliance β security β risk of false sense of security
- Fast-changing regulations = ongoing maintenance burden
- MSSPs bundle compliance for $500-5K/month