Complies

CHECKLISTS · EXPLAINERS · REAL COSTS

Compliance checklists, guides, and honest cost breakdowns

Working material for the person who got handed compliance: SOC 2, ISO 27001, and GDPR checklists, real audit cost ranges, controls explained in plain language, and timelines without the optimism.

PRICING GUIDES

How Much Does Compliance Software Cost in 2026?

How much does compliance software cost? From $79/mo for small-team tools to $20,000 to $60,000/yr for automation platforms, plus the separate audit bill. Honest 2026 ranges.

JULY 2026 · 8 MIN READ

TRACK GUIDES

How to Track Compliance in Excel (Template + Columns)

How to track compliance in Excel: the exact seven-column template, how to build a compliance calendar, the limits of a spreadsheet, and when to move to software.

JULY 2026 · 8 MIN READ

GRC EXPLAINERS

What Is GRC? Governance, Risk, and Compliance Explained

What is GRC? Governance, risk, and compliance: the three linked disciplines that set your rules, track what could go wrong, and prove you follow them. GRC vs compliance, frameworks, and who owns it.

JULY 2026 · 9 MIN READ

TRACK GUIDES

Compliance Calendar: How to Build and Run One (With Template)

Compliance calendar: what belongs on it, how to set cadence, who owns each item, and a worked annual table of recurring obligations with owners and evidence.

JULY 2026 · 9 MIN READ

SOC 2 EXPLAINERS

SOC 2 Type 1 vs Type 2: Differences, Costs, and Which to Do First

SOC 2 Type 1 vs Type 2: Type 1 tests control design at a point in time, Type 2 tests operation over 3-12 months. Costs, timelines, and which to run first.

APRIL 2026 · 9 MIN READ

ISO 27001 CHECKLISTS

ISO 27001 Checklist: 13 Steps From Scope to Certification

ISO 27001 checklist: 13 steps from ISMS scope and risk assessment through the Statement of Applicability, internal audit, and stage 1 and stage 2 cert audits.

MARCH 2026 · 11 MIN READ

GDPR CHECKLISTS

GDPR Compliance Checklist: 12 Steps for Small and Mid-Size Companies

GDPR compliance checklist: lawful basis, Article 30 records, DPAs, privacy notices, a DSAR process, a 72-hour breach plan, and the DPO question, step by step.

MAY 2026 · 10 MIN READ

SOC 2 CHECKLISTS

SOC 2 Compliance Checklist: 12 Steps From Scoping to Audit

SOC 2 compliance checklist: 12 steps covering Trust Services Criteria scoping, policies, controls, evidence collection, and how to choose an auditor.

JUNE 2026 · 10 MIN READ

SOC 2 COSTS

SOC 2 Audit Cost: Real Price Breakdown for 2026

SOC 2 audit cost: auditor fees typically run $5k-20k for Type 1 and $12k-40k+ for Type 2, before tooling and pen testing. Full line-item cost table inside.

APRIL 2026 · 9 MIN READ

SOC 2 EXPLAINERS

SOC 2 Controls List: AICPA CC1 to CC9 Common Criteria

SOC 2 controls list: all nine AICPA common criteria series (CC1 to CC9) in one table with what each covers and example controls, plus the four optional categories.

JULY 2026 · 12 MIN READ

CROSS-FRAMEWORK EXPLAINERS

SOC 2 vs ISO 27001: Which One Do You Need? (Or Both)

SOC 2 vs ISO 27001 compared: geography, structure, audit model, cost, and timeline in one table, plus how roughly 60% of the work overlaps if you do both.

JUNE 2026 · 11 MIN READ

SOC 2 GUIDES

How Long Does SOC 2 Take? Honest Timelines by Phase

How long does SOC 2 take? Type 1 commonly lands in 2-4 months; Type 2 commonly takes 4-9 months end to end because of the observation window. Phase table inside.

MAY 2026 · 8 MIN READ

CROSS-FRAMEWORK GUIDES

Audit Evidence Examples: What Auditors Actually Ask For

Audit evidence examples by control area: access reviews, change logs, onboarding checklists, backup test results, and vendor reviews, plus freshness rules.

APRIL 2026 · 10 MIN READ

CROSS-FRAMEWORK EXPLAINERS

Compliance Risk Assessment: Definition, Matrix, and Workflow

A compliance risk assessment identifies, scores, and prioritizes the risks of failing your obligations. Likelihood x impact matrix, register workflow, cadence.

JUNE 2026 · 9 MIN READ

SOC 1/SOC 2 EXPLAINERS

SOC 1 vs SOC 2: Key Differences and Which You Need

SOC 1 vs SOC 2: SOC 1 covers controls over financial reporting; SOC 2 covers security and the Trust Services Criteria. Full comparison table and which report you need.

JULY 2026 · 9 MIN READ

VENDOR RISK GUIDES

Vendor Risk Management Process: 6 Steps to a Program

Vendor risk management process explained in 6 steps: inventory, tiering, assessment, remediation, contract controls, and continuous monitoring, with a vendor tiering table.

JULY 2026 · 11 MIN READ

CMMC EXPLAINERS

CMMC Levels Explained: Level 1, Level 2, and Level 3

CMMC levels explained: Level 1 is 15 FAR requirements self-assessed, Level 2 is 110 NIST 800-171 controls, Level 3 adds 800-172. Plus the July 2026 Phase 2 pause.

JULY 2026 · 9 MIN READ

CMMC GUIDES

CMMC Level 2 Requirements: All 110 NIST 800-171 Controls

CMMC Level 2 requirements: all 110 NIST SP 800-171 controls by family, SPRS scoring, POA&M rules, the C3PAO process, and what the July 2026 suspension changed.

JULY 2026 · 11 MIN READ

Stop reading, start tracking

Every checklist on this blog becomes rows with owners inside Complies. See how on the compliance automation page.