CHECKLISTS · EXPLAINERS · REAL COSTS
Compliance checklists, guides, and honest cost breakdowns
Working material for the person who got handed compliance: SOC 2, ISO 27001, and GDPR checklists, real audit cost ranges, controls explained in plain language, and timelines without the optimism.
Continuous Control Monitoring Software and CCM Tools
Vanta publishes hourly, Drata and Sprinto every 24 hours, and most vendors no interval at all. What CCM means and the four questions that settle an evaluation.
AUGUST 2026 · 8 MIN READ
Policy Management Software vs SharePoint: Which to Buy
SharePoint stores policies well but cannot prove who acknowledged which version. The four specific gaps, three ways to close them, and how to tell if you need to buy anything.
AUGUST 2026 · 7 MIN READ
Best GDPR Compliance Software: 8 Tools Compared
Eight GDPR tools compared on what they actually do and what each publishes on price, plus how to tell which of the three product categories you are really shopping for.
AUGUST 2026 · 7 MIN READ
Vendor Risk Assessment: Risk Rating and Template
How to run a vendor risk assessment: a risk rating model that scales, the questionnaire to send, what to collect at each tier, and the template columns that matter.
AUGUST 2026 · 9 MIN READ
Statement of Applicability: ISO 27001 SoA Example
Statement of Applicability explained: what the ISO 27001 SoA must contain, an example with real justifications, how to justify exclusions, and when to update it.
AUGUST 2026 · 9 MIN READ
User Access Review: Process, Checklist, Frequency
How to run a user access review that survives an audit: the process, what each line needs, how often SOC 2, ISO 27001 and PCI DSS expect it, and the four ways reviews fail.
AUGUST 2026 · 9 MIN READ
Control Mapping: SOC 2, ISO 27001, HIPAA, PCI DSS
A control mapping crosswalk across SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR: which controls overlap, how to build a map that survives an audit, and what never maps.
AUGUST 2026 · 10 MIN READ
PCI DSS Compliance Checklist: The 12 Requirements
A PCI DSS compliance checklist that starts where it should: scope and the right SAQ, then the 12 requirements, what changed in v4.0.1, and the annual cycle.
AUGUST 2026 · 9 MIN READ
HIPAA Security Risk Assessment: How to Do One
How to run the HIPAA security risk assessment 45 CFR 164.308 requires: the nine elements HHS lists, scope, likelihood, impact, and the risk management step.
AUGUST 2026 · 10 MIN READ
How to Read a SOC 2 Report and Review a Vendor
How to read a SOC 2 report the way an auditor does: the opinion, the scope, the exceptions in Section 4, the user entity controls you inherit, and report age.
AUGUST 2026 · 9 MIN READ
SOC 2 Audit Process and SOC 2 Audit Preparation
The SOC 2 audit process phase by phase: planning, fieldwork, and reporting, what the auditor samples, what lands in the report, and how to prepare for it.
AUGUST 2026 · 9 MIN READ
Third-Party Risk Management Software: Do You Need TPRM?
Third-party risk management software compared against the vendor risk module already in your compliance platform, and when a standalone TPRM tool pays off.
AUGUST 2026 · 7 MIN READ
ISO 27001 Certification Cost: Full 2026 Breakdown
ISO 27001 certification cost explained: how certification bodies price audit days, what US companies under 50 people pay, and the hidden internal time.
JULY 2026 · 8 MIN READ
Best ISO 27001 Software: Audit and Compliance Tools Compared
ISO 27001 software compared for teams of 5 to 200: which tools publish real prices, which are quote-only, what open source covers, and how to choose in an afternoon.
AUGUST 2026 · 11 MIN READ
Do You Need a Compliance Consultant, or Just Software?
Compliance consultant vs software: what a consultant actually does for a SOC 2 or ISO 27001, when the advisory is worth it, and when self-serve software gets a small team there for less.
JULY 2026 · 9 MIN READ
What Policies Should a Company Have? SOC 2 and ISO 27001
The security policies SOC 2 and ISO 27001 really require, how many a company of 5 to 200 people needs, which ones auditors sample first, and what makes one fail.
AUGUST 2026 · 8 MIN READ
AI Policy Management Software: What It Does and Does Not Do
AI policy management software explained: how AI drafts and maintains security policies, what still needs a human, and what to look for when a small team needs policies without a policy writer.
JULY 2026 · 8 MIN READ
Compliance Automation vs Manual: When to Switch
Compliance automation vs a manual, spreadsheet-run program: what each really costs in hours and risk, the point where automation pays off, and how to tell which your team needs right now.
JULY 2026 · 9 MIN READ
SOC 2 or ISO 27001 First? How to Sequence Them
SOC 2 or ISO 27001 first? A practical way to sequence the two, based on where your buyers are, what each one costs, and how much of the first pre-fills the second.
JULY 2026 · 8 MIN READ
GRC Platform vs Compliance Software: Which to Choose
GRC platform vs compliance software, compared honestly: what each one is, who each fits, what they cost, and how to tell which your team actually needs. A practical 2026 guide.
JULY 2026 · 9 MIN READ
Bundled SOC 2 Audit vs Bring Your Own Auditor
Bundled SOC 2 audit or bring your own auditor? What bundling the CPA audit with your compliance platform actually changes for cost, independence, and speed, and when each model wins.
JULY 2026 · 8 MIN READ
How to Choose Compliance Software: A Buyer Guide
How to choose compliance software: the criteria that actually matter (frameworks, pricing transparency, contracts, setup time), plus the questions to ask before you buy. 2026 buyer guide.
JULY 2026 · 9 MIN READ
Best Compliance Software for Startups in 2026: 6 Tools Compared
Best compliance software for startups, prices included: Vanta, Drata, Sprinto and Secureframe are quote-only ($15k to $25k a year); Complies publishes $79/mo. Frameworks and who each one fits.
JULY 2026 · 9 MIN READ
GRC Framework Examples: 9 Frameworks Compared for 2026
GRC framework examples with what each one governs: SOC 2, ISO 27001, NIST CSF, NIST 800-53, PCI DSS, HIPAA, GDPR, COSO, and COBIT. When to use which, and how they overlap.
JULY 2026 · 10 MIN READ
Security Questionnaire Automation: What It Does and Does Not Do
Security questionnaire automation explained honestly: what the tools actually automate, what still needs a human, and how a ready control library cuts the answering time either way.
JULY 2026 · 8 MIN READ
How Much Does Compliance Software Cost in 2026?
How much does compliance software cost? From $79/mo for small-team tools to $20,000 to $60,000/yr for automation platforms, plus the separate audit bill. Honest 2026 ranges.
JULY 2026 · 8 MIN READ
How to Track Compliance in Excel (Template + Columns)
How to track compliance in Excel: the exact seven-column template, how to build a compliance calendar, the limits of a spreadsheet, and when to move to software.
JULY 2026 · 8 MIN READ
What Is GRC? Governance, Risk, and Compliance Explained
What is GRC? Governance, risk, and compliance: the three linked disciplines that set your rules, track what could go wrong, and prove you follow them. GRC vs compliance, frameworks, and who owns it.
JULY 2026 · 9 MIN READ
Compliance Calendar: How to Build and Run One (With Template)
Compliance calendar: what belongs on it, how to set cadence, who owns each item, and a worked annual table of recurring obligations with owners and evidence.
JULY 2026 · 9 MIN READ
SOC 2 Type 1 vs Type 2: Differences, Costs, and Which to Do First
SOC 2 Type 1 vs Type 2: Type 1 tests control design at a point in time, Type 2 tests operation over 3-12 months. Costs, timelines, and which to run first.
APRIL 2026 · 9 MIN READ
ISO 27001 Checklist: 13 Steps From Scope to Certification
ISO 27001 checklist: 13 steps from ISMS scope and risk assessment through the Statement of Applicability, internal audit, and stage 1 and stage 2 cert audits.
MARCH 2026 · 11 MIN READ
GDPR Compliance Checklist: 12 Steps for Small and Mid-Size Companies
GDPR compliance checklist: lawful basis, Article 30 records, DPAs, privacy notices, a DSAR process, a 72-hour breach plan, and the DPO question, step by step.
MAY 2026 · 10 MIN READ
SOC 2 Compliance Checklist: 12 Steps From Scoping to Audit
SOC 2 compliance checklist: 12 steps covering Trust Services Criteria scoping, policies, controls, evidence collection, and how to choose an auditor.
JUNE 2026 · 10 MIN READ
SOC 2 Audit Cost: Real Price Breakdown for 2026
SOC 2 audit cost: auditor fees typically run $5k-20k for Type 1 and $12k-40k+ for Type 2, before tooling and pen testing. Full line-item cost table inside.
APRIL 2026 · 9 MIN READ
SOC 2 Controls List: All 33 CC1 to CC9 Common Criteria
SOC 2 controls list: all 33 common criteria across nine AICPA series (CC1 to CC9) in one table with what each covers and example controls.
JULY 2026 · 12 MIN READ
SOC 2 vs ISO 27001: Which One Do You Need? (Or Both)
SOC 2 vs ISO 27001 compared: geography, structure, audit model, cost, and timeline in one table, plus how roughly 60% of the work overlaps if you do both.
JUNE 2026 · 11 MIN READ
How Long Does SOC 2 Take? Honest Timelines by Phase
How long does SOC 2 take? Type 1 commonly lands in 2-4 months; Type 2 commonly takes 4-9 months end to end because of the observation window. Phase table inside.
MAY 2026 · 8 MIN READ
Audit Evidence Examples: What Auditors Actually Ask For
Audit evidence examples by control area: access reviews, change logs, onboarding checklists, backup test results, and vendor reviews, plus freshness rules.
APRIL 2026 · 10 MIN READ
Compliance Risk Assessment: Definition, Matrix, and Workflow
A compliance risk assessment identifies, scores, and prioritizes the risks of failing your obligations. Likelihood x impact matrix, register workflow, cadence.
JUNE 2026 · 9 MIN READ
SOC 1 vs SOC 2: Differences and SOC 1 Type 2
SOC 1 vs SOC 2: SOC 1 covers controls over financial reporting, SOC 2 covers security. Comparison tables, what is inside each report, SOC 1 Type 2, and cost.
AUGUST 2026 · 13 MIN READ
Vendor Risk Management Process: 6 Steps to a Program
Vendor risk management process explained in 6 steps: inventory, tiering, assessment, remediation, contract controls, and continuous monitoring, with a vendor tiering table.
JULY 2026 · 11 MIN READ
CMMC Levels Explained: Level 1, Level 2, and Level 3
CMMC levels explained: Level 1 is 15 FAR requirements self-assessed, Level 2 is 110 NIST 800-171 controls, Level 3 adds 800-172. Plus the July 2026 Phase 2 pause.
JULY 2026 · 9 MIN READ
CMMC Level 2 Requirements: All 110 NIST 800-171 Controls
CMMC Level 2 requirements: all 110 NIST SP 800-171 controls by family, SPRS scoring, POA&M rules, the C3PAO process, and what the July 2026 suspension changed.
JULY 2026 · 11 MIN READ
Healthcare Compliance Software: Best Tools for Providers
Six healthcare compliance platforms compared on what US provider groups buy: training, exclusion screening, policy attestation and published pricing.
AUGUST 2026 · 8 MIN READ
Regulatory Change Management Software: Best Tools Compared
Nine regulatory change management tools compared on the spec that decides the bill: whether the regulatory content is inside the price or sold beside it.
AUGUST 2026 · 7 MIN READ
SOX Compliance Software: Best Tools for Pre-IPO Companies
Six SOX tools compared on the split that decides the bill: whether you need the financial-process half of SOX 404 or the IT general controls half.
AUGUST 2026 · 7 MIN READ
Best HIPAA Risk Assessment Tools for Practices and Healthtech
Seven HIPAA risk assessment tools compared, including the free HHS SRA Tool most roundups leave out, and the signals that you have outgrown it.
SEPTEMBER 2026 · 7 MIN READ
Compliance Software for Banks and Credit Unions Compared
Seven compliance platforms for financial institutions compared on the question that decides it: is an examiner driving the purchase, or a customer security review?
SEPTEMBER 2026 · 8 MIN READ
Best User Access Review Software for SOC 2 and ISO 27001
Seven user access review tools compared on the one question that decides it: do you need access revoked automatically, or do you need to prove the review happened?
SEPTEMBER 2026 · 8 MIN READ
Stop reading, start tracking
Every checklist on this blog becomes rows with owners inside Complies. See how on the compliance automation page.