The applicability map: which frameworks touch a Hawaii SMB
Compliance frameworks are triggered by what the business does, not by what industry it says it is in. Start every compliance conversation with an applicability map:
- PCI DSS 4.0.1 — storing, processing, or transmitting cardholder data.
- Reg S-P — SEC-registered investment adviser, broker-dealer, investment company, or transfer agent.
- HIPAA — handling protected health information as a covered entity or business associate.
- DFARS 252.204-7012 and CMMC — Department of War prime or subcontract handling Federal Contract Information or Controlled Unclassified Information.
- Chapter 487N, 487J, 487R — holding personal information on any Hawaii resident. Every Hawaii SMB touches this floor.
- SOC 2 — not a regulation; triggered by a contractual commitment to a customer.
A single Hawaii business often triggers three or four frameworks at once. A downtown Honolulu law firm handling personal-injury cases for medical clients hits HIPAA (business associate), Chapter 487N, PCI DSS (card retainers), and sometimes Reg S-P. Building the applicability map first prevents budgeting for one framework and being surprised by the second at year-end audit.
The dated 2026 and 2027 calendar
PCI DSS 4.0.1 — already fully in force
PCI DSS v4.0.1 has been the only active version since v4.0 retired December 31, 2024. The 51 future-dated requirements became mandatory on March 31, 2025. Any 2026 ROC or SAQ is scored against the full v4.0.1 baseline. Controls that catch most Hawaii merchants unprepared: 8.3.1 (MFA for all non-console access into the CDE), 7.2.4 (six-month CDE access reviews, tightened from annual), 6.4.3 (payment-page script inventory), 11.6.1 (change-and-tamper detection on payment pages). 2026 is the first full year of active enforcement.
Regulation S-P — both deadlines past
The SEC's May 2024 amendments to Regulation S-P took effect August 2, 2024. Larger entities ($1.5B+ AUM RIAs, $1B+ net-asset investment companies) had to comply by December 3, 2025. All other covered institutions, including smaller SEC-registered Hawaii RIAs, by June 3, 2026. The rule requires a written incident response program, 30-day customer breach notification, service provider oversight, and records that prove all of it. A covered Hawaii firm that has not stood up the written program is out of compliance today.
Fund Names Rule — smaller-entity deadline still coming
Compliance deadline for larger fund groups ($1B+ net assets) was June 11, 2026. Smaller fund groups: December 11, 2026. Hawaii fund sponsors under $1B need the 80% investment policy documentation and quarterly compliance review process locked in before December.
HIPAA Security Rule overhaul — still proposed, projected July 2027
The HIPAA Security Rule NPRM (RIN 0945-AA22) was published January 6, 2025; comments closed March 7, 2025 with over 4,700 submitted. The Fall 2026 Unified Agenda moved final action from May 2026 to July 2027 and reclassified the rulemaking under Long-Term Actions — HHS's own signal it does not expect to advance the rule within 12 months. Once final, effective 60 days later, compliance 180 days after that. If July 2027 holds, compliance lands early-to-mid 2028. Nothing in the proposal is enforceable today. The current rule remains in force.
HIPAA Privacy Rule — final action projected August 2026
HHS's Fall 2026 Unified Agenda projects August 2026 for final action on the pending HIPAA Privacy Rule changes (primarily reproductive-health-related). If the date holds, effective 60 days after publication, compliance ~180 days after — roughly April 2027. Notice of Privacy Practices updates would be required by then.
42 CFR Part 2 — NPP update deadline past
Revised 42 CFR Part 2 rules required Notice of Privacy Practices updates by February 16, 2026 for entities handling substance-use-disorder records. Hawaii behavioral-health providers should have completed the NPP update by that date.
CMMC Phase II — suspended
CMMC Phase II was suspended by Department of War memo 26-P-1023 on July 13, 2026 pending revision. Phase II obligations are not being enforced through DoD contract awards while the revision is written. Hawaii defense contractors continue to meet DFARS 252.204-7012 and NIST SP 800-171 controls, which remain fully in force. See our CMMC Phase II suspension post for context.
Hawaii Chapter 487N, 487J, 487R — always live
Chapter 487N requires notification to affected residents without unreasonable delay after any breach of personal information, plus notice to the Hawaii Office of Consumer Protection when 1,000+ Hawaii residents are affected. Chapter 487J covers Social Security number use. Chapter 487R covers destruction of records containing personal information. Every Hawaii business regardless of size must comply. None sunsets in 2026.
How a Hawaii SMB actually operationalizes the calendar
The calendar is not the program — the calendar keeps the program from going stale between assessments. A workable Hawaii SMB rhythm:
- Once a year: refresh applicability map, documented risk assessment, incident response plan.
- Every quarter: evidence checkpoint. PCI DSS vulnerability scans, Reg S-P vendor oversight review, HIPAA security reminder, access review.
- Twice a year: board or ownership compliance review covering control failures, near-miss incidents, regulatory updates.
- Every month: patch cadence review, backup restore test on rotating sample, access-change log review.
Every one of those checkpoints throws off audit evidence that has to be captured and stored. The Hawaii businesses that survive an audit cleanly are the ones that treat evidence capture as a normal operational output, not as a scramble in the two weeks before an assessor arrives. See our post on SOC 2 Type II readiness for a Hawaii SMB for the evidence-capture pattern in detail.
What this looks like at a Kakaako professional services firm
A Kakaako accounting and advisory firm, 68 employees across two islands, mixed book including audit work for a small SEC-registered RIA, tax work for two Hawaii medical practices, and business advisory for retail merchants. Applicability map: Reg S-P (as RIA vendor), HIPAA (business associate of the practices), PCI DSS 4.0.1 (card payments for fees), Chapter 487N, and SOC 2 (RIA contract). Five frameworks live at once.
The firm's 2026 calendar: January — applicability map refresh, risk assessment refresh, PCI attestation window opens. March 31 — PCI DSS 4.0.1 SAQ-D completed. April — SOC 2 Type II observation opens; Q1 evidence roll-up. June 3 — Reg S-P documentation refresh; firm supplies RIA client with updated incident response summary. July and October — Q2/Q3 roll-ups; mid-year board review; annual penetration test late October. December — Q4 roll-up, year-end board review, policy refresh.
The calendar takes ~320 hours of internal effort and ~$47,000 in outside spend (SOC 2 observation, PCI scanning, penetration test, fractional compliance advisor). The firm avoided a July fire drill when the RIA's SEC examiner asked for the Reg S-P vendor attestation — document on hand, dated within 30 days. The scramble version costs one to two weeks of billable capacity.
What Hawaii SMBs usually get wrong on the calendar
- Treating proposed rules as live obligations. Vendors have been selling HIPAA Security Rule NPRM implementation packages since January 2025 as if legally required. They are not. Prepare for the proposal, implement against the current rule.
- Missing the second framework. A firm builds a HIPAA program and forgets Chapter 487N still applies. Or builds a Reg S-P program and forgets 487R. Overlap is the norm.
- Running the calendar as a spreadsheet only. A calendar without underlying policy, control ownership, and evidence capture is a to-do list, not a compliance program. Auditors do not accept a to-do list.
Why HI Tech Hui is publishing this
HI Tech Hui has been the managed IT and cybersecurity provider for Hawaii businesses since 2014, operating from 401 Kamakee Street in Kakaako with a Cyberuptive-run security operations capability. If you take one thing from this post: build the applicability map first, calendar the live deadlines, treat proposed rules as expected future controls rather than current obligations.
Frequently asked questions about the Hawaii SMB compliance calendar
What compliance deadlines does a Hawaii SMB actually need to plan for in 2026 and 2027?
The live 2026 deadlines are PCI DSS 4.0.1 (all 51 future-dated requirements mandatory since March 31, 2025 and fully enforced against 2026 assessments), Reg S-P for smaller SEC-registered advisers (June 3, 2026), Fund Names Rule for larger fund groups (June 11, 2026) and smaller (December 11, 2026), and 42 CFR Part 2 Notice of Privacy Practices updates (February 16, 2026). CMMC Phase II is suspended pending revision. The HIPAA Security Rule overhaul is still proposed — final action now projected for July 2027.
Is PCI DSS 4.0.1 already in force for a Hawaii merchant in 2026?
Yes. PCI DSS 4.0.1 has been the only active version since December 31, 2024, and all 51 future-dated requirements became mandatory on March 31, 2025. Any 2026 assessment is scored against the full v4.0.1 baseline, including MFA for all non-console access into the cardholder data environment, six-month access reviews, and payment-page script inventory under requirement 6.4.3. There is no separate 2026 PCI DSS deadline — 2026 is simply the first full year of active enforcement.
Does Regulation S-P apply to a Hawaii investment adviser and when did the deadline hit?
Yes if the firm is a SEC-registered investment adviser, broker-dealer, investment company, or transfer agent. The amended Reg S-P compliance deadlines were December 3, 2025 for larger entities (RIAs with $1.5B+ AUM) and June 3, 2026 for all other covered institutions, including smaller Hawaii RIAs. Every covered Hawaii firm must now have a written incident response program, 30-day customer breach notification, and documented service-provider oversight. Both dates are past.
Is the new HIPAA Security Rule final and does a Hawaii medical practice need to comply in 2026?
No. The HIPAA Security Rule overhaul (RIN 0945-AA22) remains a proposed rule as of July 2026. The Office of Management and Budget moved final action from May 2026 to July 2027 and reclassified it under Long-Term Actions. The current HIPAA Security Rule remains fully enforceable. A Hawaii medical practice should keep meeting the existing rule and treat the proposed MFA, encryption, and asset-inventory requirements as expected future controls, not live obligations.
What is the CMMC Phase II status for a Hawaii defense contractor in 2026?
CMMC Phase II was suspended by a Department of War memo on July 13, 2026 (memo 26-P-1023) pending revision. New Phase II obligations are not being enforced through DoD contract awards while the revision is written. Hawaii defense contractors should continue to meet DFARS 252.204-7012 and NIST SP 800-171 controls, which remain fully in force, and monitor for the revised Phase II rule text expected later in 2026 or 2027.
What Hawaii state compliance obligations does an SMB have on top of the federal frameworks?
Hawaii Revised Statutes Chapter 487N requires notification to affected residents without unreasonable delay after any breach involving personal information, with additional notice to the Hawaii Office of Consumer Protection when 1,000 or more Hawaii residents are affected. Chapter 487J covers Social Security number use and disclosure. Chapter 487R covers destruction of records containing personal information. All three apply to any Hawaii business regardless of size, and none has a 2026 sunset.
How should a Hawaii SMB actually build a compliance calendar for 2026 and 2027?
Start with an applicability map: list every framework triggered by the business type — PCI DSS if you take cards, Reg S-P if SEC-registered, HIPAA if you handle protected health information, DFARS/CMMC if you have a DoD contract, and Chapter 487N always. For each, calendar the annual assessment window, quarterly evidence checkpoints, and any new deadline. Tie the calendar to a documented risk assessment refreshed at least yearly, and to board or ownership review at least twice a year.
What compliance deadlines are still landing in the second half of 2026?
For SEC-registered advisers and funds, the Fund Names Rule compliance deadlines are June 11, 2026 for larger fund groups and December 11, 2026 for smaller fund groups. Form N-PORT and Form N-CEN reporting for smaller entities was May 18, 2026. The HIPAA Privacy Rule final action is now projected for August 2026 rather than May, which would push compliance into 2027. Beyond those, most 2026-active deadlines have already passed.
Bottom line for Hawaii SMBs planning 2027
PCI DSS 4.0.1 is fully enforced. Reg S-P is live for every covered Hawaii firm. HIPAA Security Rule changes are still proposed — not a live obligation before early 2028 at earliest. CMMC Phase II is on hold. Chapter 487N is always on. Build the applicability map, calendar the dated obligations, run quarterly evidence checkpoints. Related: which frameworks apply, CMMC vs SOC 2 vs HIPAA, and the PCI DSS 4.0.1 checklist for Hawaii merchants.