{"id":1341,"date":"2026-09-20T20:53:54","date_gmt":"2026-09-20T20:53:54","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=1341"},"modified":"2026-09-20T20:53:54","modified_gmt":"2026-09-20T20:53:54","slug":"saas-compliance-requirements-us","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/blog\/saas-compliance-requirements-us\/","title":{"rendered":"What Compliances Does a SaaS Startup Need to Sell in the US?"},"content":{"rendered":"\n<!DOCTYPE html>\n<html lang=\"en\">\n<head>\n<meta charset=\"UTF-8\">\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\n<title>SaaS Compliance Requirements: 6 US Frameworks | Osto<\/title>\n<meta name=\"description\" content=\"SaaS compliance requirements to sell in the US explained: SOC 2, ISO 27001, state privacy laws, HIPAA, PCI DSS, and how to know which ones apply to you.\">\n<style>\n  :root{\n    --ink:#0e1330;\n    --brand:#1c267a;\n    --brand-2:#3a46c0;\n    --accent:#00c2a8;\n    --accent-soft:#e6f7f4;\n    --paper:#ffffff;\n    --mist:#f4f6fb;\n    --line:#e3e7f2;\n    --muted:#5a6284;\n    --danger:#e2564d;\n    --radius:16px;\n    --shadow:0 1px 2px rgba(16,19,48,.04),0 12px 40px rgba(16,19,48,.06);\n    --maxw:860px;\n  }\n  *{box-sizing:border-box}\n  html{scroll-behavior:smooth}\n  body{\n    margin:0;\n    font-family:-apple-system,BlinkMacSystemFont,\"Segoe UI\",Inter,Roboto,Helvetica,Arial,sans-serif;\n    color:var(--ink);background:var(--paper);line-height:1.65;-webkit-font-smoothing:antialiased;\n  }\n  a{color:var(--brand-2);text-decoration:none}\n  a:hover{text-decoration:underline}\n\n  .topbar{border-bottom:1px solid var(--line);background:rgba(255,255,255,.9);backdrop-filter:saturate(160%) blur(8px);position:sticky;top:0;z-index:20}\n  .topbar-inner{max-width:1120px;margin:0 auto;padding:14px 24px;display:flex;align-items:center;justify-content:space-between;gap:16px}\n  .logo{display:flex;align-items:center;gap:9px;font-weight:800;letter-spacing:-.02em;color:var(--brand);font-size:20px}\n  .logo-mark{width:26px;height:26px;border-radius:8px;background:linear-gradient(135deg,var(--brand),var(--brand-2));display:grid;place-items:center;color:#fff;font-size:14px;font-weight:800}\n  .nav-cta{background:var(--brand);color:#fff;padding:9px 18px;border-radius:10px;font-weight:600;font-size:14px;white-space:nowrap}\n  .nav-cta:hover{background:var(--brand-2);text-decoration:none}\n\n  .wrap{max-width:var(--maxw);margin:0 auto;padding:0 24px}\n  .breadcrumb{font-size:13px;color:var(--muted);padding:26px 0 6px}\n  .breadcrumb a{color:var(--muted)}\n  .eyebrow{display:inline-block;margin:22px 0 14px;font-size:12px;font-weight:700;letter-spacing:.14em;text-transform:uppercase;color:var(--brand-2);background:var(--mist);padding:6px 12px;border-radius:999px;border:1px solid var(--line)}\n  h1{font-size:clamp(30px,5vw,46px);line-height:1.1;letter-spacing:-.03em;margin:0 0 18px;font-weight:800}\n  .dek{font-size:19px;color:var(--muted);margin:0 0 8px}\n\n  .meta{display:flex;flex-wrap:wrap;gap:8px 20px;align-items:center;font-size:13px;color:var(--muted);margin:22px 0 4px;padding-bottom:26px;border-bottom:1px solid var(--line)}\n  .meta .dot{width:4px;height:4px;border-radius:50%;background:var(--line)}\n\n  .tldr{margin:30px 0;border:1px solid var(--line);background:linear-gradient(180deg,var(--accent-soft),#fff 70%);border-radius:var(--radius);padding:22px 24px}\n  .tldr h2{margin:0 0 8px;font-size:13px;letter-spacing:.14em;text-transform:uppercase;color:var(--brand)}\n  .tldr p{margin:0 0 10px;font-size:16.5px}\n  .tldr p:last-child{margin:0}\n\n  h2.sec{font-size:27px;letter-spacing:-.02em;margin:52px 0 14px;font-weight:800;scroll-margin-top:80px}\n  h3{font-size:20px;margin:34px 0 10px;letter-spacing:-.01em;font-weight:700}\n  p{margin:0 0 16px;font-size:16.5px}\n  .lead-in{color:var(--muted)}\n  em{font-style:italic}\n\n  .jump{background:var(--mist);border:1px solid var(--line);border-radius:var(--radius);padding:20px 24px;margin:30px 0}\n  .jump h4{margin:0 0 12px;font-size:13px;letter-spacing:.1em;text-transform:uppercase;color:var(--muted)}\n  .jump ol{margin:0;padding-left:20px;columns:2;column-gap:32px}\n  .jump li{margin:6px 0;font-size:15px}\n  @media(max-width:560px){.jump ol{columns:1}}\n\n  .analogy{background:var(--mist);border-radius:var(--radius);padding:20px 22px;margin:22px 0;border:1px solid var(--line);font-size:16.5px}\n  .analogy strong{color:var(--brand)}\n\n  ul.clean{padding-left:0;list-style:none;margin:16px 0}\n  ul.clean li{position:relative;padding:6px 0 6px 30px;font-size:16px;border-bottom:1px solid var(--mist)}\n  ul.clean li:last-child{border-bottom:none}\n  ul.clean li::before{content:\"\";position:absolute;left:4px;top:14px;width:9px;height:9px;border-radius:3px;background:var(--accent)}\n  ul.warn li::before{background:var(--danger)}\n\n  \/* TSC cards *\/\n  .tsc{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:22px 0}\n  .tsc-card{border:1px solid var(--line);border-radius:14px;padding:18px;background:#fff}\n  .tsc-card.req{border-color:var(--brand);background:#f6f8ff}\n  .tsc-card .tag{font-size:11px;font-weight:700;letter-spacing:.08em;text-transform:uppercase;color:var(--muted)}\n  .tsc-card.req .tag{color:var(--brand)}\n  .tsc-card h4{margin:6px 0 6px;font-size:16px;color:var(--ink)}\n  .tsc-card p{font-size:14px;color:var(--muted);margin:0}\n  @media(max-width:720px){.tsc{grid-template-columns:1fr 1fr}}\n  @media(max-width:480px){.tsc{grid-template-columns:1fr}}\n\n  \/* stat band *\/\n  .fig{margin:30px 0;border:1px solid var(--line);border-radius:var(--radius);overflow:hidden;box-shadow:var(--shadow)}\n  .fig-head{padding:16px 22px;background:var(--brand);color:#fff;display:flex;align-items:baseline;justify-content:space-between;gap:12px;flex-wrap:wrap}\n  .fig-head .ttl{font-weight:700;font-size:15px;letter-spacing:.02em}\n  .fig-head .src{font-size:11.5px;color:#b9c0f0}\n  .fig-foot{padding:14px 22px;border-top:1px solid var(--line);font-size:12.5px;color:var(--muted);background:#fbfcfe}\n  .stat-band{display:grid;grid-template-columns:repeat(3,1fr)}\n  .stat-cell{padding:24px 16px;text-align:center;border-right:1px solid var(--line)}\n  .stat-cell:last-child{border-right:none}\n  .stat-cell .num{font-size:30px;font-weight:800;color:var(--brand);letter-spacing:-.02em;line-height:1.05}\n  .stat-cell .num.accent{color:var(--accent)}\n  .stat-cell .lab{font-size:12.5px;color:var(--muted);margin-top:8px;line-height:1.4}\n  @media(max-width:560px){.stat-band{grid-template-columns:1fr}.stat-cell{border-right:none;border-bottom:1px solid var(--line)}.stat-cell:last-child{border-bottom:none}}\n\n  \/* timeline *\/\n  .timeline{padding:8px 24px 4px}\n  .tl-item{display:grid;grid-template-columns:130px 1fr;gap:16px;padding:14px 0;border-bottom:1px solid var(--mist)}\n  .tl-item:last-child{border-bottom:none}\n  .tl-date{font-weight:800;color:var(--brand);font-size:14px}\n  .tl-what{font-size:14.5px}\n  .tl-what b{display:block;margin-bottom:2px}\n  @media(max-width:520px){.tl-item{grid-template-columns:1fr;gap:2px}}\n\n  .tablewrap{overflow-x:auto;margin:22px 0;border:1px solid var(--line);border-radius:var(--radius);box-shadow:var(--shadow)}\n  table{border-collapse:collapse;width:100%;min-width:600px;font-size:14.5px}\n  thead th{background:var(--mist);text-align:left;padding:14px 16px;font-size:12.5px;text-transform:uppercase;letter-spacing:.05em;color:var(--muted);border-bottom:1px solid var(--line);font-weight:700}\n  thead th.osto{background:var(--brand);color:#fff}\n  tbody td{padding:14px 16px;border-bottom:1px solid var(--line);vertical-align:top}\n  tbody tr:last-child td{border-bottom:none}\n  tbody td:first-child{font-weight:600;color:var(--ink)}\n  td.osto{background:#f6f8ff;font-weight:600}\n  .yes{color:var(--accent);font-weight:700}\n  .no{color:var(--danger);font-weight:700}\n\n  .callout{border:1px solid var(--line);border-radius:var(--radius);padding:24px;margin:44px 0;background:linear-gradient(135deg,#141b52,#2a34a0);color:#fff;box-shadow:var(--shadow)}\n  .callout h3{margin:0 0 8px;color:#fff}\n  .callout p{color:#cfd4f5;margin:0 0 18px}\n  .callout a.btn{display:inline-block;background:#fff;color:var(--brand);font-weight:700;padding:11px 22px;border-radius:10px;font-size:15px}\n  .callout a.btn:hover{text-decoration:none;background:#eef0ff}\n\n  .disclaimer{font-size:13.5px;color:var(--muted);background:var(--mist);border:1px solid var(--line);border-radius:12px;padding:16px 18px;margin:34px 0}\n\n  .faq{border-top:1px solid var(--line);margin-top:48px;padding-top:8px}\n  details{border-bottom:1px solid var(--line);padding:6px 0}\n  summary{cursor:pointer;list-style:none;padding:16px 4px;font-weight:600;font-size:17px;display:flex;justify-content:space-between;align-items:center;gap:16px}\n  summary::-webkit-details-marker{display:none}\n  summary::after{content:\"+\";color:var(--brand-2);font-size:22px;font-weight:400}\n  details[open] summary::after{content:\"\u2013\"}\n  details p{padding:0 4px 18px;color:var(--muted);margin:0}\n\n  footer{border-top:1px solid var(--line);margin-top:60px;background:var(--mist)}\n  .foot-inner{max-width:1120px;margin:0 auto;padding:36px 24px;display:flex;flex-wrap:wrap;gap:16px;justify-content:space-between;align-items:center;font-size:14px;color:var(--muted)}\n  .foot-inner .logo{font-size:17px}\n\n  .related{margin:42px 0 0}\n  .related h3{margin-bottom:14px}\n  .related-grid{display:grid;grid-template-columns:1fr 1fr;gap:14px}\n  .rc{border:1px solid var(--line);border-radius:12px;padding:16px 18px;background:#fff}\n  .rc .k{font-size:11px;letter-spacing:.1em;color:var(--brand-2);font-weight:700;text-transform:uppercase}\n  .rc a{font-weight:600;color:var(--ink);display:block;margin-top:6px;font-size:15.5px}\n  @media(max-width:640px){.related-grid{grid-template-columns:1fr}}\n\n  \/* --- bright, clean additions --- *\/\n  .bright-strip{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:30px 0}\n  .bright-strip .bcard{border-radius:16px;padding:22px 20px;color:#fff}\n  .bright-strip .bcard .n{font-size:26px;font-weight:800;line-height:1.1}\n  .bright-strip .bcard .l{font-size:13px;margin-top:6px;opacity:.95;font-weight:500}\n  .bc-navy{background:linear-gradient(135deg,#1c267a,#3a46c0)}\n  .bc-teal{background:linear-gradient(135deg,#00c2a8,#12b3d6)}\n  .bc-indigo{background:linear-gradient(135deg,#3a46c0,#5a63d6)}\n  @media(max-width:640px){.bright-strip{grid-template-columns:1fr}}\n\n  .pillrow{display:flex;gap:10px;flex-wrap:wrap;margin:22px 0}\n  .pill{border-radius:999px;padding:9px 16px;font-size:14px;font-weight:600;background:var(--accent-soft);color:#0a7a68;border:1px solid #bfece4}\n  .pill.i{background:#eef0ff;color:#3a46c0;border-color:#d6dbff}\n\n  .bigcards{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:26px 0}\n  .bigcard{border-radius:16px;padding:22px;background:#fff;border:1px solid var(--line);box-shadow:0 8px 30px rgba(16,19,48,.05)}\n  .bigcard .ic{width:44px;height:44px;border-radius:12px;display:grid;place-items:center;font-size:20px;font-weight:800;color:#fff;margin-bottom:12px}\n  .bigcard h4{margin:0 0 6px;font-size:16px;color:var(--ink)}\n  .bigcard p{margin:0;font-size:13.5px;color:var(--muted)}\n  @media(max-width:720px){.bigcards{grid-template-columns:1fr}}\n\n  .keyrow{display:grid;grid-template-columns:1fr 1fr;gap:0;border-radius:16px;overflow:hidden;border:1px solid var(--line);margin:26px 0}\n  .keyrow>div{padding:20px 22px}\n  .keyrow .k1{background:#eef0ff}\n  .keyrow .k2{background:var(--accent-soft)}\n  .keyrow .lab{font-size:11px;font-weight:800;letter-spacing:.08em;text-transform:uppercase;margin-bottom:6px}\n  .keyrow .k1 .lab{color:#3a46c0}.keyrow .k2 .lab{color:#0a7a68}\n  .keyrow .big{font-size:19px;font-weight:800;color:var(--brand);margin-bottom:4px}\n  .keyrow .sm{font-size:13.5px;color:var(--muted)}\n  @media(max-width:560px){.keyrow{grid-template-columns:1fr}}\n\n  .flow{display:flex;gap:8px;flex-wrap:wrap;align-items:stretch;margin:26px 0}\n  .flow .step{flex:1;min-width:130px;border-radius:14px;padding:16px 14px;text-align:center}\n  .flow .step .t{font-weight:800;font-size:14px}\n  .flow .step .d{font-size:12px;margin-top:4px;opacity:.9}\n  .flow .arrow{align-self:center;color:#c3c9e6;font-size:20px;font-weight:700}\n\n\n  .bbox{border-radius:14px;background:#fff;padding:16px 20px;margin:22px 0;font-size:14.5px;line-height:1.6}\n  .bbox strong{color:var(--brand)}\n  .bbox.navy{border:2px solid #1c267a}.bbox.indigo{border:2px solid #3a46c0}.bbox.teal{border:2px solid #00c2a8}\n  .bbox .bt{font-size:11px;font-weight:800;letter-spacing:.06em;text-transform:uppercase;margin-bottom:5px}\n  .bbox.navy .bt{color:#1c267a}.bbox.indigo .bt{color:#3a46c0}.bbox.teal .bt{color:#0a7a68}\n  .checkgrid{display:grid;grid-template-columns:repeat(2,1fr);gap:12px;margin:24px 0}\n  .checkarea{border:1px solid var(--line);border-radius:14px;padding:16px 18px;background:#fff;box-shadow:0 6px 24px rgba(16,19,48,.04)}\n  .checkarea .h{display:flex;align-items:center;gap:10px;margin-bottom:8px}\n  .checkarea .num{width:28px;height:28px;border-radius:8px;background:linear-gradient(135deg,#1c267a,#3a46c0);color:#fff;font-weight:800;font-size:13px;display:grid;place-items:center;flex:none}\n  .checkarea h4{margin:0;font-size:14.5px;color:var(--ink)}\n  .checkarea ul{margin:0;padding:0;list-style:none}\n  .checkarea li{font-size:12.8px;color:var(--muted);padding:4px 0 4px 18px;position:relative}\n  .checkarea li:before{content:\"\";position:absolute;left:0;top:9px;width:9px;height:9px;border:2px solid var(--accent);border-radius:3px}\n  @media(max-width:640px){.checkgrid{grid-template-columns:1fr}}\n  .sampleflow{display:flex;align-items:center;gap:0;flex-wrap:wrap;margin:22px 0;border:1px solid var(--line);border-radius:14px;overflow:hidden}\n  .sampleflow .sf{flex:1;min-width:150px;padding:16px 18px;text-align:center}\n  .sampleflow .sf .t{font-weight:800;font-size:14px;color:var(--brand)}\n  .sampleflow .sf .d{font-size:12.5px;color:var(--muted);margin-top:4px}\n  .sampleflow .sf.a{background:#eef0ff}.sampleflow .sf.b{background:#f4f6fb}.sampleflow .sf.c{background:#fdeceb}\n  .sampleflow .sarr{color:#c3c9e6;font-size:18px;font-weight:700;padding:0 6px}\n  @media(max-width:640px){.sampleflow{flex-direction:column}.sampleflow .sarr{display:none}.sampleflow .sf{border-bottom:1px solid var(--line)}}\n  .docpills{display:flex;gap:8px;flex-wrap:wrap;margin:10px 0}\n  .docpills .dp{font-size:12.5px;padding:7px 13px;border-radius:999px;background:var(--mist);color:var(--brand);border:1px solid var(--line);font-weight:500}\n\n  .callout a[href*=\"book-demo\"]{color:#ffffff !important;font-weight:700;text-decoration:underline}\n  .callout a[href*=\"book-demo\"] span{color:#ffffff !important}\n  \/* Osto branded comparison table *\/\n  .otable{overflow-x:auto;margin:26px 0;border-radius:16px;border:1px solid #e3e6f5;box-shadow:0 10px 34px rgba(28,38,122,.10)}\n  table.regtable{border-collapse:separate;border-spacing:0;width:100%;min-width:520px;font-size:14.5px;background:#fff;margin:0}\n  table.regtable thead tr,table.regtable tr:first-child{background:linear-gradient(135deg,#1c267a,#3a46c0)}\n  table.regtable th,table.regtable tr:first-child td{background:transparent;color:#fff;text-align:left;padding:15px 18px;font-size:13px;font-weight:800;letter-spacing:.03em;border:none}\n  table.regtable td{padding:14px 18px;border-bottom:1px solid #eef0f7;vertical-align:top;color:#33384f}\n  table.regtable tr:nth-child(even):not(:first-child){background:#f7f9ff}\n  table.regtable tr:last-child td{border-bottom:none}\n  table.regtable td:first-child{font-weight:700;color:#0e1330}\n  table.regtable tr td:first-child{border-right:1px solid #eef0f7}\n  table.regtable tr:first-child td:first-child,table.regtable th:first-child{border-right:1px solid rgba(255,255,255,.18)}\n  table.regtable tr:first-child td{border-bottom:none}\n\n<\/style>\n<\/head>\n<body>\n<div class=\"wrap\">\n  <p class=\"dek\">SaaS compliance requirements are the first thing a US enterprise buyer checks, and getting them wrong stalls the deal. This guide breaks down exactly what a SaaS startup needs to sell in the US: what buyers demand, what the law demands, and how to tell which applies to you.<\/p>\n\n  <div class=\"meta\"><span>Osto Security Team<\/span><span class=\"dot\"><\/span><span>11 min read<\/span><span class=\"dot\"><\/span><span>Compliance<\/span><\/div>\n\n  <div class=\"tldr\">\n    <h2>The short answer<\/h2>\n    <p>The SaaS compliance requirements to sell in the US fall into two groups. The first is buyer-driven: SOC 2 is the near-universal enterprise ask, and ISO 27001 matters for international buyers. Neither is a law, but you will not close enterprise deals without them. The second is legally required and triggered by your data and customers: US state privacy laws (20 states now have comprehensive laws, led by California), HIPAA if you touch health data, PCI DSS if you handle card payments, and FedRAMP or CMMC if you sell to the federal government. There is no single federal privacy law, so the state patchwork is the map most SaaS startups work from.<\/p>\n  <\/div>\n\n  <div class=\"jump\">\n    <h4>On this page<\/h4>\n    <ol>\n      <li><a href=\"#model\">The two-bucket model<\/a><\/li>\n      <li><a href=\"#buyer\">What buyers require<\/a><\/li>\n      <li><a href=\"#legal\">What the law requires<\/a><\/li>\n      <li><a href=\"#frameworks\">The frameworks that may apply<\/a><\/li>\n      <li><a href=\"#scope\">How to scope your own list<\/a><\/li>\n      <li><a href=\"#osto\">How Osto helps you get ready<\/a><\/li>\n    <\/ol>\n  <\/div>\n\n  <h2 class=\"sec c-sky\" id=\"model\">The two-bucket model for SaaS compliance requirements<\/h2>\n  <p>Before naming a single framework, it helps to see the shape of the problem. The SaaS compliance requirements for the US are not one list, they are two very different kinds of obligation that founders routinely blur together. Getting the distinction right tells you what to prioritise and what you can safely defer.<\/p>\n\n  <div style=\"background:#f6f8ff;border:1px solid #e3e6f5;border-radius:20px;padding:30px 32px;margin:30px 0;box-shadow:0 12px 40px rgba(28,38,122,.08)\">\n  <div style=\"font-size:11px;font-weight:800;letter-spacing:.14em;text-transform:uppercase;color:#1C267A;margin-bottom:6px;text-align:left\">The mental model<\/div>\n  <div style=\"font-size:20px;font-weight:800;color:#0e1330;margin-bottom:8px;text-align:left\">Buyer-driven versus legally required<\/div>\n  <div style=\"font-size:14px;line-height:1.7;color:#5b6178;margin-bottom:24px;text-align:left\">The SaaS compliance requirements for selling in the US split cleanly into two buckets, and confusing them is the most common mistake founders make. One bucket is what buyers demand, the other is what the law demands.<\/div>\n  <svg viewBox=\"0 0 800 276\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:100%;height:auto;display:block\" role=\"img\" aria-label=\"Buyer-driven versus legally required SaaS compliance in the US\">\n<g font-family=\"Inter,Arial,sans-serif\">\n <text x=\"400\" y=\"34\" text-anchor=\"middle\" fill=\"#0e1330\" font-size=\"16\" font-weight=\"800\">Two kinds of compliance, do not confuse them<\/text>\n <rect x=\"16\" y=\"60\" width=\"372\" height=\"200\" rx=\"16\" fill=\"#eef1fb\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/>\n <text x=\"46\" y=\"94\" fill=\"#1C267A\" font-size=\"14.5\" font-weight=\"800\">Buyer-driven<\/text>\n <text x=\"46\" y=\"114\" fill=\"#5b6178\" font-size=\"11\">Not laws. Enterprise buyers demand them.<\/text>\n <line x1=\"46\" y1=\"128\" x2=\"358\" y2=\"128\" stroke=\"#d3d9f2\" stroke-width=\"1\"\/>\n <text x=\"46\" y=\"154\" fill=\"#20324f\" font-size=\"12.5\" font-weight=\"700\">SOC 2<\/text><text x=\"120\" y=\"154\" fill=\"#4a5170\" font-size=\"12\">the near-universal ask<\/text>\n <text x=\"46\" y=\"182\" fill=\"#20324f\" font-size=\"12.5\" font-weight=\"700\">ISO 27001<\/text><text x=\"140\" y=\"182\" fill=\"#4a5170\" font-size=\"12\">for international buyers<\/text>\n <text x=\"46\" y=\"222\" fill=\"#2b3596\" font-size=\"11.5\">You choose to get these to win deals<\/text>\n <text x=\"46\" y=\"242\" fill=\"#2b3596\" font-size=\"11.5\">and pass security reviews.<\/text>\n <rect x=\"412\" y=\"60\" width=\"372\" height=\"200\" rx=\"16\" fill=\"#f9f4f4\" stroke=\"#e6cfcf\" stroke-width=\"1.5\"\/>\n <text x=\"442\" y=\"94\" fill=\"#9a4a54\" font-size=\"14.5\" font-weight=\"800\">Legally required<\/text>\n <text x=\"442\" y=\"114\" fill=\"#5b6178\" font-size=\"11\">Triggered by your data and your customers.<\/text>\n <line x1=\"442\" y1=\"128\" x2=\"754\" y2=\"128\" stroke=\"#ecd9d9\" stroke-width=\"1\"\/>\n <text x=\"442\" y=\"154\" fill=\"#7a2e38\" font-size=\"12.5\" font-weight=\"700\">State privacy laws<\/text><text x=\"600\" y=\"154\" fill=\"#7a5560\" font-size=\"12\">20 states<\/text>\n <text x=\"442\" y=\"182\" fill=\"#7a2e38\" font-size=\"12.5\" font-weight=\"700\">HIPAA \/ PCI \/ GLBA<\/text><text x=\"612\" y=\"182\" fill=\"#7a5560\" font-size=\"12\">by data<\/text>\n <text x=\"442\" y=\"222\" fill=\"#9a4a54\" font-size=\"11.5\">You must follow these by law, based<\/text>\n <text x=\"442\" y=\"242\" fill=\"#9a4a54\" font-size=\"11.5\">on what data you hold and who you sell to.<\/text>\n<\/g><\/svg>\n  \n<\/div>\n\n  <p>The first bucket is buyer-driven. These are not laws, they are what enterprise procurement teams demand before they sign, and without them your deal stalls in the security review. The second bucket is legally required, and it is triggered not by your ambition but by the data you hold and the customers you serve. A startup that understands which bucket a given requirement sits in stops treating compliance as one overwhelming pile and starts sequencing it sensibly.<\/p>\n\n  <h2 class=\"sec c-sage\" id=\"buyer\">What buyers require: SOC 2 and ISO 27001<\/h2>\n  <p>For most B2B SaaS startups selling in the US, the SaaS compliance requirements begin with a single credential: SOC 2. It is an independent audit report, based on the AICPA Trust Services Criteria, that proves you protect customer data with real, working controls. Enterprise procurement teams routinely disqualify vendors who cannot produce a current SOC 2 report, so it functions as a gate on revenue.<\/p>\n<p>Most startups begin with SOC 2 Type I, a point-in-time report, then move to Type II, which proves the controls operated over months. Our guide to <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-for-startups\/\">SOC 2 for startups<\/a> walks through the stages and timeline.<\/p>\n  <p>ISO 27001 is the second buyer-driven credential. Unlike SOC 2, it is a formal certification of an information security management system, and it carries the most weight with international and European buyers. A US-focused startup often starts with SOC 2 and adds ISO 27001 as it expands abroad. Both exist to answer the same buyer question, can we trust you with our data, which is exactly the question a <a href=\"https:\/\/www.osto.one\/resources\/blog\/security-questionnaire-killed-enterprise-deal\/\">security questionnaire<\/a> is designed to probe.<\/p>\n\n  <div class=\"bbox teal\"><div class=\"bt\">Buyer-driven does not mean optional<\/div>SOC 2 and ISO 27001 are not laws, but in enterprise sales they are effectively mandatory. The practical rule: if security-conscious buyers are on your roadmap, start SOC 2 early, because Type II needs months of operating history you cannot manufacture once a buyer asks.<\/div>\n\n  <h2 class=\"sec c-apri\" id=\"legal\">What the law requires: privacy laws and sectoral rules<\/h2>\n  <p>The second half of the SaaS compliance requirements is not a choice. These obligations are law, and they attach based on the data you process, regardless of what your buyers ask for.<\/p>\n  <p>The biggest piece is US state privacy law. There is no single federal privacy law, so the country runs on a patchwork: as of 2026, twenty states have comprehensive consumer privacy laws in effect, with Indiana, Kentucky, and Rhode Island the newest. California, through the CCPA and CPRA, is the strictest and the only state with a private right of action for data breaches.<\/p>\n<p>If you sell to consumers or hold personal data across states, you are very likely in scope somewhere, and California compliance gets you most of the way to a national baseline.<\/p>\n  <p>On top of state privacy law sit federal sectoral rules that trigger by data type. HIPAA applies the moment your software touches health data on behalf of a healthcare customer, and it makes you a business associate directly liable, our guide to <a href=\"https:\/\/www.osto.one\/resources\/blog\/hipaa-compliance-for-saas-startups\/\">HIPAA compliance for SaaS startups<\/a> covers what that means.<\/p>\n<p>PCI DSS applies if you store, process, or transmit payment card data. GLBA covers financial data, COPPA covers data from children under 13, and FERPA covers student education records. Each is mandatory only when its data type is in play, so most startups trigger only one or two of them.<\/p>\n\n  <div class=\"bbox indigo\"><div class=\"bt\">There is still no US federal privacy law<\/div>Proposed federal bills have not passed, so consumer privacy rights exist only at the state level. That means your privacy obligations are defined by where your users are, not by a single national rulebook. For a SaaS startup selling nationally, the practical short list is California, Texas, Colorado, and Connecticut, plus wherever most of your customers sit.<\/div>\n\n  <h2 class=\"sec c-plum\" id=\"frameworks\">The frameworks that may apply, at a glance<\/h2>\n  <p>Put both buckets together and the full set of SaaS compliance requirements a US-selling startup might encounter looks like this. Very few startups need all of them, the point is to recognise which ones your situation actually triggers.<\/p>\n\n  <div style=\"background:#f6f8ff;border:1px solid #e3e6f5;border-radius:20px;padding:30px 32px;margin:30px 0;box-shadow:0 12px 40px rgba(28,38,122,.08)\">\n  <div style=\"font-size:11px;font-weight:800;letter-spacing:.14em;text-transform:uppercase;color:#1C267A;margin-bottom:6px;text-align:left\">The frameworks<\/div>\n  <div style=\"font-size:20px;font-weight:800;color:#0e1330;margin-bottom:8px;text-align:left\">What may apply to your startup<\/div>\n  <div style=\"font-size:14px;line-height:1.7;color:#5b6178;margin-bottom:24px;text-align:left\">Depending on who you sell to and what data you hold, a handful of frameworks make up the SaaS compliance requirements you will actually face. Few startups need all of them at once.<\/div>\n  <svg viewBox=\"0 0 800 356\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:100%;height:auto;display:block\" role=\"img\" aria-label=\"The frameworks a US SaaS startup may need\"><text x=\"400\" y=\"34\" text-anchor=\"middle\" fill=\"#0e1330\" font-size=\"16\" font-weight=\"800\" font-family=\"Inter,Arial,sans-serif\">The frameworks a US SaaS startup may need<\/text><rect x=\"16\" y=\"58\" width=\"240\" height=\"132\" rx=\"16\" fill=\"#eef1fb\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><circle cx=\"136\" cy=\"92\" r=\"20\" fill=\"#fff\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><g transform=\"translate(126.16,82.16) scale(0.82)\" fill=\"none\" stroke=\"#1C267A\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><circle cx=\"12\" cy=\"9\" r=\"6\"\/><path d=\"M9 13.5L8 21l4-2 4 2-1-7.5\"\/><path d=\"M9.5 9l1.8 1.8L15 7.5\"\/><\/g><text x=\"136\" y=\"136\" text-anchor=\"middle\" fill=\"#1C267A\" font-size=\"13\" font-weight=\"800\" font-family=\"Inter,Arial,sans-serif\">SOC 2<\/text><text x=\"136\" y=\"158\" text-anchor=\"middle\" fill=\"#5b6178\" font-size=\"11\" font-family=\"Inter,Arial,sans-serif\">The enterprise buyer standard<\/text><rect x=\"274\" y=\"58\" width=\"240\" height=\"132\" rx=\"16\" fill=\"#eef1fb\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><circle cx=\"394\" cy=\"92\" r=\"20\" fill=\"#fff\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><g transform=\"translate(384.16,82.16) scale(0.82)\" fill=\"none\" stroke=\"#1C267A\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><circle cx=\"12\" cy=\"12\" r=\"8\"\/><path d=\"M4 12h16M12 4c2.5 2.2 2.5 13.8 0 16M12 4c-2.5 2.2-2.5 13.8 0 16\"\/><\/g><text x=\"394\" y=\"136\" text-anchor=\"middle\" fill=\"#1C267A\" font-size=\"13\" font-weight=\"800\" font-family=\"Inter,Arial,sans-serif\">ISO 27001<\/text><text x=\"394\" y=\"158\" text-anchor=\"middle\" fill=\"#5b6178\" font-size=\"11\" font-family=\"Inter,Arial,sans-serif\">For international and EU buyers<\/text><rect x=\"532\" y=\"58\" width=\"240\" height=\"132\" rx=\"16\" fill=\"#eef1fb\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><circle cx=\"652\" cy=\"92\" r=\"20\" fill=\"#fff\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><g transform=\"translate(642.16,82.16) scale(0.82)\" fill=\"none\" stroke=\"#1C267A\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M14 4l6 6-3 3-6-6z\"\/><path d=\"M11 7l-6 6M4 20h9M6.5 15.5l3 3\"\/><\/g><text x=\"652\" y=\"136\" text-anchor=\"middle\" fill=\"#1C267A\" font-size=\"13\" font-weight=\"800\" font-family=\"Inter,Arial,sans-serif\">State privacy laws<\/text><text x=\"652\" y=\"158\" text-anchor=\"middle\" fill=\"#5b6178\" font-size=\"11\" font-family=\"Inter,Arial,sans-serif\">20 states, led by California<\/text><rect x=\"16\" y=\"208\" width=\"240\" height=\"132\" rx=\"16\" fill=\"#eef1fb\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><circle cx=\"136\" cy=\"242\" r=\"20\" fill=\"#fff\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><g transform=\"translate(126.16,232.16) scale(0.82)\" fill=\"none\" stroke=\"#1C267A\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M12 21s-7-4.5-9-9a5 5 0 0 1 9-3 5 5 0 0 1 9 3c-2 4.5-9 9-9 9z\"\/><path d=\"M8 12h2l1 2 2-4 1 2h2\" transform=\"scale(0)\"\/><\/g><text x=\"136\" y=\"286\" text-anchor=\"middle\" fill=\"#1C267A\" font-size=\"13\" font-weight=\"800\" font-family=\"Inter,Arial,sans-serif\">HIPAA<\/text><text x=\"136\" y=\"308\" text-anchor=\"middle\" fill=\"#5b6178\" font-size=\"11\" font-family=\"Inter,Arial,sans-serif\">If you touch health data<\/text><rect x=\"274\" y=\"208\" width=\"240\" height=\"132\" rx=\"16\" fill=\"#eef1fb\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><circle cx=\"394\" cy=\"242\" r=\"20\" fill=\"#fff\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><g transform=\"translate(384.16,232.16) scale(0.82)\" fill=\"none\" stroke=\"#1C267A\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><rect x=\"3\" y=\"6\" width=\"18\" height=\"12\" rx=\"2\"\/><path d=\"M3 10h18\"\/><\/g><text x=\"394\" y=\"286\" text-anchor=\"middle\" fill=\"#1C267A\" font-size=\"13\" font-weight=\"800\" font-family=\"Inter,Arial,sans-serif\">PCI DSS<\/text><text x=\"394\" y=\"308\" text-anchor=\"middle\" fill=\"#5b6178\" font-size=\"11\" font-family=\"Inter,Arial,sans-serif\">If you handle card payments<\/text><rect x=\"532\" y=\"208\" width=\"240\" height=\"132\" rx=\"16\" fill=\"#eef1fb\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><circle cx=\"652\" cy=\"242\" r=\"20\" fill=\"#fff\" stroke=\"#1C267A\" stroke-width=\"1.5\"\/><g transform=\"translate(642.16,232.16) scale(0.82)\" fill=\"none\" stroke=\"#1C267A\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M6 21V4\"\/><path d=\"M6 5h11l-2 3 2 3H6\"\/><\/g><text x=\"652\" y=\"286\" text-anchor=\"middle\" fill=\"#1C267A\" font-size=\"13\" font-weight=\"800\" font-family=\"Inter,Arial,sans-serif\">FedRAMP \/ CMMC<\/text><text x=\"652\" y=\"308\" text-anchor=\"middle\" fill=\"#5b6178\" font-size=\"11\" font-family=\"Inter,Arial,sans-serif\">If you sell to the US government<\/text><\/svg>\n  \n<\/div>\n\n  <p>SOC 2 and ISO 27001 answer the buyer. State privacy laws apply if you hold personal data. HIPAA, PCI DSS, GLBA, COPPA, and FERPA each switch on with a specific data type. FedRAMP and CMMC apply only if you sell to the US federal government or the defense supply chain. Reading the list this way turns an intimidating alphabet soup into a short, situation-specific checklist.<\/p>\n\n  <h2 class=\"sec c-sky\" id=\"scope\">How to scope your SaaS compliance requirements<\/h2>\n  <p>The way to turn the SaaS compliance requirements into a plan is to answer two questions honestly, and let the answers route you.<\/p>\n\n  <div style=\"background:#f6f8ff;border:1px solid #e3e6f5;border-radius:20px;padding:30px 32px;margin:30px 0;box-shadow:0 12px 40px rgba(28,38,122,.08)\">\n  <div style=\"font-size:11px;font-weight:800;letter-spacing:.14em;text-transform:uppercase;color:#1C267A;margin-bottom:6px;text-align:left\">How to scope it<\/div>\n  <div style=\"font-size:20px;font-weight:800;color:#0e1330;margin-bottom:8px;text-align:left\">Two questions decide what you need<\/div>\n  <div style=\"font-size:14px;line-height:1.7;color:#5b6178;margin-bottom:24px;text-align:left\">You do not chase every framework. The SaaS compliance requirements that apply to you come down to two questions: who you sell to, and what data you hold.<\/div>\n  <svg viewBox=\"0 0 800 246\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" style=\"width:100%;height:auto;display:block\" role=\"img\" aria-label=\"How US SaaS compliance requirements depend on customer and data type\">\n<g font-family=\"Inter,Arial,sans-serif\">\n <text x=\"400\" y=\"34\" text-anchor=\"middle\" fill=\"#0e1330\" font-size=\"16\" font-weight=\"800\">What you need depends on two questions<\/text>\n <rect x=\"30\" y=\"66\" width=\"350\" height=\"160\" rx=\"16\" fill=\"#eef1fb\" stroke=\"#1C267A\" stroke-width=\"1.6\"\/>\n <circle cx=\"66\" cy=\"104\" r=\"18\" fill=\"#fff\" stroke=\"#1C267A\" stroke-width=\"1.4\"\/><g transform=\"translate(57.00,95.00) scale(0.75)\" fill=\"none\" stroke=\"#1C267A\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><circle cx=\"12\" cy=\"8\" r=\"4\"\/><path d=\"M4 21a8 8 0 0 1 16 0\"\/><\/g>\n <text x=\"96\" y=\"102\" fill=\"#1C267A\" font-size=\"13.5\" font-weight=\"800\">Who do you sell to?<\/text>\n <line x1=\"54\" y1=\"122\" x2=\"356\" y2=\"122\" stroke=\"#d3d9f2\" stroke-width=\"1\"\/>\n <text x=\"54\" y=\"146\" fill=\"#4a5170\" font-size=\"12\">Enterprises, SOC 2. EU buyers,<\/text>\n <text x=\"54\" y=\"164\" fill=\"#4a5170\" font-size=\"12\">ISO 27001. Government, FedRAMP<\/text>\n <text x=\"54\" y=\"182\" fill=\"#4a5170\" font-size=\"12\">or CMMC. Healthcare orgs, HIPAA.<\/text>\n <text x=\"54\" y=\"210\" fill=\"#2b3596\" font-size=\"11.5\" font-weight=\"700\">The customer sets the bar.<\/text>\n <rect x=\"420\" y=\"66\" width=\"350\" height=\"160\" rx=\"16\" fill=\"#eef7f4\" stroke=\"#0a7d6c\" stroke-width=\"1.6\"\/>\n <circle cx=\"456\" cy=\"104\" r=\"18\" fill=\"#fff\" stroke=\"#0a7d6c\" stroke-width=\"1.4\"\/><g transform=\"translate(447.00,95.00) scale(0.75)\" fill=\"none\" stroke=\"#0a7d6c\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><rect x=\"4.5\" y=\"10.5\" width=\"15\" height=\"9.5\" rx=\"2\"\/><path d=\"M8 10.5V7a4 4 0 0 1 8 0v3.5\"\/><\/g>\n <text x=\"486\" y=\"102\" fill=\"#0a6558\" font-size=\"13.5\" font-weight=\"800\">What data do you hold?<\/text>\n <line x1=\"444\" y1=\"122\" x2=\"746\" y2=\"122\" stroke=\"#c7e3dc\" stroke-width=\"1\"\/>\n <text x=\"444\" y=\"146\" fill=\"#4a5170\" font-size=\"12\">Personal data, state privacy laws.<\/text>\n <text x=\"444\" y=\"164\" fill=\"#4a5170\" font-size=\"12\">Health data, HIPAA. Card data,<\/text>\n <text x=\"444\" y=\"182\" fill=\"#4a5170\" font-size=\"12\">PCI DSS. Children, COPPA.<\/text>\n <text x=\"444\" y=\"210\" fill=\"#0a6558\" font-size=\"11.5\" font-weight=\"700\">The data triggers the law.<\/text>\n<\/g><\/svg>\n  \n<\/div>\n\n  <p>First, who do you sell to? Enterprise buyers mean SOC 2, European buyers mean ISO 27001, government means FedRAMP or CMMC, and healthcare organisations mean HIPAA. Second, what data do you hold? Personal data brings state privacy laws into play, health data triggers HIPAA, card data triggers PCI DSS, and data from children triggers COPPA.<\/p>\n<p>Work through both questions and you have your actual list, usually far shorter than the full set. Then sequence it: build the real security first, and let the SOC 2 report and the legal obligations follow as evidence of it, not the other way round. That grounding in the <a href=\"https:\/\/www.osto.one\/resources\/blog\/types-of-vapt\/\">types of security testing<\/a> is often where readiness begins.<\/p>\n\n  <h2 class=\"sec c-sage\" id=\"osto\">How Osto helps you get US-ready<\/h2>\n  <p>The hard part of the SaaS compliance requirements is not knowing the list, it is doing the work: standing up real controls, running the testing, gathering evidence, and keeping it audit-ready, all without a dedicated security team while the product roadmap keeps moving. Piecing that together from separate tools and consultants is slow and fragile, which is the gap Osto is built to close.<\/p>\n  <p>Osto is a one-stop cybersecurity and compliance platform. It automates SOC 2 and ISO 27001 controls and evidence, runs VAPT across your apps, APIs, and infrastructure, supports data-protection controls that map to state privacy laws and DPDP, and pre-fills security questionnaires, all mapped across 200+ frameworks in one place. It gets a SaaS startup genuinely ready for the SaaS compliance requirements of selling in the US, and keeps the evidence in order, so the audit and the security review become a verification rather than a scramble. Osto is the readiness and automation layer, the formal SOC 2 opinion is still issued by an independent CPA firm.<\/p>\n\n  <div class=\"callout\">\n    <h3>Get US-ready without a big security team.<\/h3>\n    <p>Osto is the one-stop cybersecurity and compliance platform built for fast-moving teams. Automate SOC 2 and ISO 27001, run VAPT, cover your data-protection controls, and answer security questionnaires, on one platform. No security team required.<\/p>\n    <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:#1c267a;color:#ffffff;font-weight:700;font-size:15px;padding:14px 26px;border-radius:12px;text-decoration:none;margin-top:6px\" target=\"_blank\" rel=\"noopener\">Book a Demo &rarr;<\/a>\n  <\/div>\n\n  <h2 class=\"sec\" id=\"faq\">Frequently asked questions<\/h2>\n  <details><summary>What compliances does a SaaS startup need to sell in the US?<\/summary><p>Two kinds. Buyer-driven credentials, SOC 2 and, for international buyers, ISO 27001, which enterprise procurement demands. And legally required rules triggered by your data and customers: US state privacy laws, HIPAA for health data, PCI DSS for card data, and FedRAMP or CMMC for government sales.<\/p><\/details>\n  <details><summary>Is SOC 2 legally required to sell SaaS in the US?<\/summary><p>No. SOC 2 is not a law, it is an AICPA attestation. But enterprise buyers almost always require a current SOC 2 report before signing, so in practice it is mandatory for selling to enterprises, even though no statute compels it.<\/p><\/details>\n  <details><summary>Is there a federal US privacy law for SaaS companies?<\/summary><p>No. The US has no single comprehensive federal privacy law. As of 2026, twenty states have their own comprehensive privacy laws in effect, led by California&#8217;s CCPA and CPRA, so compliance is defined state by state based on where your users are.<\/p><\/details>\n  <details><summary>When does a SaaS startup need HIPAA or PCI DSS?<\/summary><p>HIPAA applies the moment your software stores, processes, or transmits health information on behalf of a healthcare customer, making you a business associate. PCI DSS applies if you store, process, or transmit payment card data. Each is mandatory only when that data type is in play.<\/p><\/details>\n  <details><summary>Do I need ISO 27001 as well as SOC 2?<\/summary><p>Not always. SOC 2 is the primary US enterprise credential. ISO 27001 is a certification that carries more weight with international and European buyers, so many US-focused startups start with SOC 2 and add ISO 27001 as they expand abroad.<\/p><\/details>\n  <details><summary>Which compliance should a SaaS startup do first?<\/summary><p>Start with the requirement your buyers actually ask for, usually SOC 2, and the legal obligations your data already triggers, such as state privacy laws. Build real security first and let the report and legal compliance follow as evidence of it.<\/p><\/details>\n<\/div>\n<\/body>\n<\/html>\n","protected":false},"excerpt":{"rendered":"<p>SaaS Compliance Requirements: 6 US Frameworks | Osto SaaS compliance requirements are the first thing a US enterprise buyer checks,\u2026<\/p>\n","protected":false},"author":8,"featured_media":1342,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[721,722],"class_list":["post-1341","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-saas-compliance-requirements","tag-saas-compliance-us"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=1341"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1341\/revisions"}],"predecessor-version":[{"id":1343,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/1341\/revisions\/1343"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/1342"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=1341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=1341"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=1341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}