CHECKLISTS · EXPLAINERS · REAL COSTS
Compliance checklists, guides, and honest cost breakdowns
Working material for the person who got handed compliance: SOC 2, ISO 27001, and GDPR checklists, real audit cost ranges, controls explained in plain language, and timelines without the optimism.
How Much Does Compliance Software Cost in 2026?
How much does compliance software cost? From $79/mo for small-team tools to $20,000 to $60,000/yr for automation platforms, plus the separate audit bill. Honest 2026 ranges.
JULY 2026 · 8 MIN READ
How to Track Compliance in Excel (Template + Columns)
How to track compliance in Excel: the exact seven-column template, how to build a compliance calendar, the limits of a spreadsheet, and when to move to software.
JULY 2026 · 8 MIN READ
What Is GRC? Governance, Risk, and Compliance Explained
What is GRC? Governance, risk, and compliance: the three linked disciplines that set your rules, track what could go wrong, and prove you follow them. GRC vs compliance, frameworks, and who owns it.
JULY 2026 · 9 MIN READ
Compliance Calendar: How to Build and Run One (With Template)
Compliance calendar: what belongs on it, how to set cadence, who owns each item, and a worked annual table of recurring obligations with owners and evidence.
JULY 2026 · 9 MIN READ
SOC 2 Type 1 vs Type 2: Differences, Costs, and Which to Do First
SOC 2 Type 1 vs Type 2: Type 1 tests control design at a point in time, Type 2 tests operation over 3-12 months. Costs, timelines, and which to run first.
APRIL 2026 · 9 MIN READ
ISO 27001 Checklist: 13 Steps From Scope to Certification
ISO 27001 checklist: 13 steps from ISMS scope and risk assessment through the Statement of Applicability, internal audit, and stage 1 and stage 2 cert audits.
MARCH 2026 · 11 MIN READ
GDPR Compliance Checklist: 12 Steps for Small and Mid-Size Companies
GDPR compliance checklist: lawful basis, Article 30 records, DPAs, privacy notices, a DSAR process, a 72-hour breach plan, and the DPO question, step by step.
MAY 2026 · 10 MIN READ
SOC 2 Compliance Checklist: 12 Steps From Scoping to Audit
SOC 2 compliance checklist: 12 steps covering Trust Services Criteria scoping, policies, controls, evidence collection, and how to choose an auditor.
JUNE 2026 · 10 MIN READ
SOC 2 Audit Cost: Real Price Breakdown for 2026
SOC 2 audit cost: auditor fees typically run $5k-20k for Type 1 and $12k-40k+ for Type 2, before tooling and pen testing. Full line-item cost table inside.
APRIL 2026 · 9 MIN READ
SOC 2 Controls List: AICPA CC1 to CC9 Common Criteria
SOC 2 controls list: all nine AICPA common criteria series (CC1 to CC9) in one table with what each covers and example controls, plus the four optional categories.
JULY 2026 · 12 MIN READ
SOC 2 vs ISO 27001: Which One Do You Need? (Or Both)
SOC 2 vs ISO 27001 compared: geography, structure, audit model, cost, and timeline in one table, plus how roughly 60% of the work overlaps if you do both.
JUNE 2026 · 11 MIN READ
How Long Does SOC 2 Take? Honest Timelines by Phase
How long does SOC 2 take? Type 1 commonly lands in 2-4 months; Type 2 commonly takes 4-9 months end to end because of the observation window. Phase table inside.
MAY 2026 · 8 MIN READ
Audit Evidence Examples: What Auditors Actually Ask For
Audit evidence examples by control area: access reviews, change logs, onboarding checklists, backup test results, and vendor reviews, plus freshness rules.
APRIL 2026 · 10 MIN READ
Compliance Risk Assessment: Definition, Matrix, and Workflow
A compliance risk assessment identifies, scores, and prioritizes the risks of failing your obligations. Likelihood x impact matrix, register workflow, cadence.
JUNE 2026 · 9 MIN READ
SOC 1 vs SOC 2: Key Differences and Which You Need
SOC 1 vs SOC 2: SOC 1 covers controls over financial reporting; SOC 2 covers security and the Trust Services Criteria. Full comparison table and which report you need.
JULY 2026 · 9 MIN READ
Vendor Risk Management Process: 6 Steps to a Program
Vendor risk management process explained in 6 steps: inventory, tiering, assessment, remediation, contract controls, and continuous monitoring, with a vendor tiering table.
JULY 2026 · 11 MIN READ
CMMC Levels Explained: Level 1, Level 2, and Level 3
CMMC levels explained: Level 1 is 15 FAR requirements self-assessed, Level 2 is 110 NIST 800-171 controls, Level 3 adds 800-172. Plus the July 2026 Phase 2 pause.
JULY 2026 · 9 MIN READ
CMMC Level 2 Requirements: All 110 NIST 800-171 Controls
CMMC Level 2 requirements: all 110 NIST SP 800-171 controls by family, SPRS scoring, POA&M rules, the C3PAO process, and what the July 2026 suspension changed.
JULY 2026 · 11 MIN READ
Stop reading, start tracking
Every checklist on this blog becomes rows with owners inside Complies. See how on the compliance automation page.