Complies

CHECKLISTS · EXPLAINERS · REAL COSTS

Compliance checklists, guides, and honest cost breakdowns

Working material for the person who got handed compliance: SOC 2, ISO 27001, and GDPR checklists, real audit cost ranges, controls explained in plain language, and timelines without the optimism.

GRC COMPARISONS

Continuous Control Monitoring Software and CCM Tools

Vanta publishes hourly, Drata and Sprinto every 24 hours, and most vendors no interval at all. What CCM means and the four questions that settle an evaluation.

AUGUST 2026 · 8 MIN READ

POLICY COMPARISONS

Policy Management Software vs SharePoint: Which to Buy

SharePoint stores policies well but cannot prove who acknowledged which version. The four specific gaps, three ways to close them, and how to tell if you need to buy anything.

AUGUST 2026 · 7 MIN READ

GDPR COMPARISONS

Best GDPR Compliance Software: 8 Tools Compared

Eight GDPR tools compared on what they actually do and what each publishes on price, plus how to tell which of the three product categories you are really shopping for.

AUGUST 2026 · 7 MIN READ

VENDORS GUIDES

Vendor Risk Assessment: Risk Rating and Template

How to run a vendor risk assessment: a risk rating model that scales, the questionnaire to send, what to collect at each tier, and the template columns that matter.

AUGUST 2026 · 9 MIN READ

ISO 27001 GUIDES

Statement of Applicability: ISO 27001 SoA Example

Statement of Applicability explained: what the ISO 27001 SoA must contain, an example with real justifications, how to justify exclusions, and when to update it.

AUGUST 2026 · 9 MIN READ

ACCESS GUIDES

User Access Review: Process, Checklist, Frequency

How to run a user access review that survives an audit: the process, what each line needs, how often SOC 2, ISO 27001 and PCI DSS expect it, and the four ways reviews fail.

AUGUST 2026 · 9 MIN READ

CROSSWALK GUIDES

Control Mapping: SOC 2, ISO 27001, HIPAA, PCI DSS

A control mapping crosswalk across SOC 2, ISO 27001, HIPAA, PCI DSS, and GDPR: which controls overlap, how to build a map that survives an audit, and what never maps.

AUGUST 2026 · 10 MIN READ

PCI DSS GUIDES

PCI DSS Compliance Checklist: The 12 Requirements

A PCI DSS compliance checklist that starts where it should: scope and the right SAQ, then the 12 requirements, what changed in v4.0.1, and the annual cycle.

AUGUST 2026 · 9 MIN READ

HIPAA GUIDES

HIPAA Security Risk Assessment: How to Do One

How to run the HIPAA security risk assessment 45 CFR 164.308 requires: the nine elements HHS lists, scope, likelihood, impact, and the risk management step.

AUGUST 2026 · 10 MIN READ

SOC 2 GUIDES

How to Read a SOC 2 Report and Review a Vendor

How to read a SOC 2 report the way an auditor does: the opinion, the scope, the exceptions in Section 4, the user entity controls you inherit, and report age.

AUGUST 2026 · 9 MIN READ

SOC 2 GUIDES

SOC 2 Audit Process and SOC 2 Audit Preparation

The SOC 2 audit process phase by phase: planning, fieldwork, and reporting, what the auditor samples, what lands in the report, and how to prepare for it.

AUGUST 2026 · 9 MIN READ

TPRM DECISIONS

Third-Party Risk Management Software: Do You Need TPRM?

Third-party risk management software compared against the vendor risk module already in your compliance platform, and when a standalone TPRM tool pays off.

AUGUST 2026 · 7 MIN READ

ISO27001 GUIDES

ISO 27001 Certification Cost: Full 2026 Breakdown

ISO 27001 certification cost explained: how certification bodies price audit days, what US companies under 50 people pay, and the hidden internal time.

JULY 2026 · 8 MIN READ

ISO27001 GUIDES

Best ISO 27001 Software: Audit and Compliance Tools Compared

ISO 27001 software compared for teams of 5 to 200: which tools publish real prices, which are quote-only, what open source covers, and how to choose in an afternoon.

AUGUST 2026 · 11 MIN READ

ADVISORY GUIDES

Do You Need a Compliance Consultant, or Just Software?

Compliance consultant vs software: what a consultant actually does for a SOC 2 or ISO 27001, when the advisory is worth it, and when self-serve software gets a small team there for less.

JULY 2026 · 9 MIN READ

POLICY GUIDES

What Policies Should a Company Have? SOC 2 and ISO 27001

The security policies SOC 2 and ISO 27001 really require, how many a company of 5 to 200 people needs, which ones auditors sample first, and what makes one fail.

AUGUST 2026 · 8 MIN READ

POLICY GUIDES

AI Policy Management Software: What It Does and Does Not Do

AI policy management software explained: how AI drafts and maintains security policies, what still needs a human, and what to look for when a small team needs policies without a policy writer.

JULY 2026 · 8 MIN READ

AUTOMATE GUIDES

Compliance Automation vs Manual: When to Switch

Compliance automation vs a manual, spreadsheet-run program: what each really costs in hours and risk, the point where automation pays off, and how to tell which your team needs right now.

JULY 2026 · 9 MIN READ

FRAMEWORKS GUIDES

SOC 2 or ISO 27001 First? How to Sequence Them

SOC 2 or ISO 27001 first? A practical way to sequence the two, based on where your buyers are, what each one costs, and how much of the first pre-fills the second.

JULY 2026 · 8 MIN READ

GRC GUIDES

GRC Platform vs Compliance Software: Which to Choose

GRC platform vs compliance software, compared honestly: what each one is, who each fits, what they cost, and how to tell which your team actually needs. A practical 2026 guide.

JULY 2026 · 9 MIN READ

EVIDENCE GUIDES

Bundled SOC 2 Audit vs Bring Your Own Auditor

Bundled SOC 2 audit or bring your own auditor? What bundling the CPA audit with your compliance platform actually changes for cost, independence, and speed, and when each model wins.

JULY 2026 · 8 MIN READ

BUYERS GUIDES

How to Choose Compliance Software: A Buyer Guide

How to choose compliance software: the criteria that actually matter (frameworks, pricing transparency, contracts, setup time), plus the questions to ask before you buy. 2026 buyer guide.

JULY 2026 · 9 MIN READ

BUYERS GUIDES

Best Compliance Software for Startups in 2026: 6 Tools Compared

Best compliance software for startups, prices included: Vanta, Drata, Sprinto and Secureframe are quote-only ($15k to $25k a year); Complies publishes $79/mo. Frameworks and who each one fits.

JULY 2026 · 9 MIN READ

GRC EXPLAINERS

GRC Framework Examples: 9 Frameworks Compared for 2026

GRC framework examples with what each one governs: SOC 2, ISO 27001, NIST CSF, NIST 800-53, PCI DSS, HIPAA, GDPR, COSO, and COBIT. When to use which, and how they overlap.

JULY 2026 · 10 MIN READ

EVIDENCE GUIDES

Security Questionnaire Automation: What It Does and Does Not Do

Security questionnaire automation explained honestly: what the tools actually automate, what still needs a human, and how a ready control library cuts the answering time either way.

JULY 2026 · 8 MIN READ

PRICING GUIDES

How Much Does Compliance Software Cost in 2026?

How much does compliance software cost? From $79/mo for small-team tools to $20,000 to $60,000/yr for automation platforms, plus the separate audit bill. Honest 2026 ranges.

JULY 2026 · 8 MIN READ

TRACK GUIDES

How to Track Compliance in Excel (Template + Columns)

How to track compliance in Excel: the exact seven-column template, how to build a compliance calendar, the limits of a spreadsheet, and when to move to software.

JULY 2026 · 8 MIN READ

GRC EXPLAINERS

What Is GRC? Governance, Risk, and Compliance Explained

What is GRC? Governance, risk, and compliance: the three linked disciplines that set your rules, track what could go wrong, and prove you follow them. GRC vs compliance, frameworks, and who owns it.

JULY 2026 · 9 MIN READ

TRACK GUIDES

Compliance Calendar: How to Build and Run One (With Template)

Compliance calendar: what belongs on it, how to set cadence, who owns each item, and a worked annual table of recurring obligations with owners and evidence.

JULY 2026 · 9 MIN READ

SOC 2 EXPLAINERS

SOC 2 Type 1 vs Type 2: Differences, Costs, and Which to Do First

SOC 2 Type 1 vs Type 2: Type 1 tests control design at a point in time, Type 2 tests operation over 3-12 months. Costs, timelines, and which to run first.

APRIL 2026 · 9 MIN READ

ISO 27001 CHECKLISTS

ISO 27001 Checklist: 13 Steps From Scope to Certification

ISO 27001 checklist: 13 steps from ISMS scope and risk assessment through the Statement of Applicability, internal audit, and stage 1 and stage 2 cert audits.

MARCH 2026 · 11 MIN READ

GDPR CHECKLISTS

GDPR Compliance Checklist: 12 Steps for Small and Mid-Size Companies

GDPR compliance checklist: lawful basis, Article 30 records, DPAs, privacy notices, a DSAR process, a 72-hour breach plan, and the DPO question, step by step.

MAY 2026 · 10 MIN READ

SOC 2 CHECKLISTS

SOC 2 Compliance Checklist: 12 Steps From Scoping to Audit

SOC 2 compliance checklist: 12 steps covering Trust Services Criteria scoping, policies, controls, evidence collection, and how to choose an auditor.

JUNE 2026 · 10 MIN READ

SOC 2 COSTS

SOC 2 Audit Cost: Real Price Breakdown for 2026

SOC 2 audit cost: auditor fees typically run $5k-20k for Type 1 and $12k-40k+ for Type 2, before tooling and pen testing. Full line-item cost table inside.

APRIL 2026 · 9 MIN READ

SOC 2 EXPLAINERS

SOC 2 Controls List: All 33 CC1 to CC9 Common Criteria

SOC 2 controls list: all 33 common criteria across nine AICPA series (CC1 to CC9) in one table with what each covers and example controls.

JULY 2026 · 12 MIN READ

CROSS-FRAMEWORK EXPLAINERS

SOC 2 vs ISO 27001: Which One Do You Need? (Or Both)

SOC 2 vs ISO 27001 compared: geography, structure, audit model, cost, and timeline in one table, plus how roughly 60% of the work overlaps if you do both.

JUNE 2026 · 11 MIN READ

SOC 2 GUIDES

How Long Does SOC 2 Take? Honest Timelines by Phase

How long does SOC 2 take? Type 1 commonly lands in 2-4 months; Type 2 commonly takes 4-9 months end to end because of the observation window. Phase table inside.

MAY 2026 · 8 MIN READ

CROSS-FRAMEWORK GUIDES

Audit Evidence Examples: What Auditors Actually Ask For

Audit evidence examples by control area: access reviews, change logs, onboarding checklists, backup test results, and vendor reviews, plus freshness rules.

APRIL 2026 · 10 MIN READ

CROSS-FRAMEWORK EXPLAINERS

Compliance Risk Assessment: Definition, Matrix, and Workflow

A compliance risk assessment identifies, scores, and prioritizes the risks of failing your obligations. Likelihood x impact matrix, register workflow, cadence.

JUNE 2026 · 9 MIN READ

SOC 1/SOC 2 EXPLAINERS

SOC 1 vs SOC 2: Differences and SOC 1 Type 2

SOC 1 vs SOC 2: SOC 1 covers controls over financial reporting, SOC 2 covers security. Comparison tables, what is inside each report, SOC 1 Type 2, and cost.

AUGUST 2026 · 13 MIN READ

VENDOR RISK GUIDES

Vendor Risk Management Process: 6 Steps to a Program

Vendor risk management process explained in 6 steps: inventory, tiering, assessment, remediation, contract controls, and continuous monitoring, with a vendor tiering table.

JULY 2026 · 11 MIN READ

CMMC EXPLAINERS

CMMC Levels Explained: Level 1, Level 2, and Level 3

CMMC levels explained: Level 1 is 15 FAR requirements self-assessed, Level 2 is 110 NIST 800-171 controls, Level 3 adds 800-172. Plus the July 2026 Phase 2 pause.

JULY 2026 · 9 MIN READ

CMMC GUIDES

CMMC Level 2 Requirements: All 110 NIST 800-171 Controls

CMMC Level 2 requirements: all 110 NIST SP 800-171 controls by family, SPRS scoring, POA&M rules, the C3PAO process, and what the July 2026 suspension changed.

JULY 2026 · 11 MIN READ

HEALTHCARE COMPARISONS

Healthcare Compliance Software: Best Tools for Providers

Six healthcare compliance platforms compared on what US provider groups buy: training, exclusion screening, policy attestation and published pricing.

AUGUST 2026 · 8 MIN READ

REGULATORY COMPARISONS

Regulatory Change Management Software: Best Tools Compared

Nine regulatory change management tools compared on the spec that decides the bill: whether the regulatory content is inside the price or sold beside it.

AUGUST 2026 · 7 MIN READ

SOX COMPARISONS

SOX Compliance Software: Best Tools for Pre-IPO Companies

Six SOX tools compared on the split that decides the bill: whether you need the financial-process half of SOX 404 or the IT general controls half.

AUGUST 2026 · 7 MIN READ

SRA COMPARISONS

Best HIPAA Risk Assessment Tools for Practices and Healthtech

Seven HIPAA risk assessment tools compared, including the free HHS SRA Tool most roundups leave out, and the signals that you have outgrown it.

SEPTEMBER 2026 · 7 MIN READ

FI COMPARISONS

Compliance Software for Banks and Credit Unions Compared

Seven compliance platforms for financial institutions compared on the question that decides it: is an examiner driving the purchase, or a customer security review?

SEPTEMBER 2026 · 8 MIN READ

UAR COMPARISONS

Best User Access Review Software for SOC 2 and ISO 27001

Seven user access review tools compared on the one question that decides it: do you need access revoked automatically, or do you need to prove the review happened?

SEPTEMBER 2026 · 8 MIN READ

Stop reading, start tracking

Every checklist on this blog becomes rows with owners inside Complies. See how on the compliance automation page.