You track compliance in Excel by building one row per obligation, with columns for the requirement, the framework it satisfies, a named owner, a frequency, a due date, a status, and a link to the evidence, then setting calendar reminders separately because a spreadsheet will not chase anyone. It works well up to roughly 30 obligations and a single framework. Past that, the tabs drift, the evidence links rot, and nobody notices a lapsed access review until an auditor asks for it. This guide gives you the exact template, then the honest signs it is time to stop.
How do you track compliance in Excel?
You track compliance in Excel by turning every requirement into a dated task with an owner and a status, then keeping a link to the proof that each task actually happened. The spreadsheet is a register: one row per obligation, one column per fact you need to know about it. The discipline that makes it work is not the formula. It is that every row has a real name in the owner column and a real date in the due column, and that someone looks at the sheet on a schedule.
Start with a single tab called Obligations. Add a second tab called Calendar that pulls the recurring items into a month-by-month view, and a third called Evidence that lists where each artifact lives. Keep it to three tabs for as long as you can. The moment you have one tab per framework, you have signed up to maintain the same access-review row in five places, and that is the failure this whole exercise is supposed to prevent.
What columns should a compliance tracking spreadsheet have?
A working compliance tracker needs seven columns per row. Fewer and you cannot answer an auditor; more and nobody keeps it current. Here is the template, with what each column is for.
| Column | What goes in it | Example |
|---|---|---|
| Obligation | The plain-language task | Quarterly user access review |
| Framework requirement | The control or clause it satisfies | SOC 2 CC6.2, ISO 27001 A.5.18 |
| Owner | A named person, not a team | Priya (Head of Eng) |
| Frequency | How often it repeats | Quarterly |
| Due date | The next date it is due | 2026-09-30 |
| Status | Done, in progress, overdue | Overdue |
| Evidence link | Where the proof lives | Drive: /evidence/access-2026-Q2 |
Two refinements earn their keep. Add conditional formatting so anything past its due date turns red, because an overdue item that looks identical to a done item is invisible. And add a column for the last completed date, separate from the next due date, so you can prove the previous cycle actually closed rather than just that a future one is scheduled. Auditors ask for the last cycle, not the next one.
How do you build a compliance calendar in Excel?
You build a compliance calendar by taking every recurring row from your obligations tab and laying it out against the twelve months, so you can see at a glance what lands in each one. Quarterly access reviews, annual policy reviews, vendor re-assessments, risk register updates, control tests, and your audit window all belong on it. The calendar exists because compliance programs rarely fail from bad intentions. They fail from missed dates.
The practical build is a grid: obligations down the left, months across the top, an X in each cell where that item is due. Filter it by owner so each person can see their own three tasks without reading the whole program. The catch is that Excel will not remind anyone the X is coming, so you have to mirror every date into a real calendar with alerts, and keep the two in sync by hand. That manual sync is the first thing that quietly breaks. Our walkthrough of how to build and run a compliance calendar covers the cadence for each item type in more detail.
What are the limits of tracking compliance in Excel?
The limits are ownership, staleness, and evidence, and they all show up at the same size: somewhere north of 30 obligations or the day you add a second framework. A spreadsheet is a genuinely fine tracker below that line, and anyone who tells you a 15 person company needs a platform is selling one. Above the line, four problems compound.
- Nobody owns a row. A name typed in a cell is not an assignment. There is no reminder, no escalation, and no record that the owner ever saw it. When that person goes on vacation or leaves, their rows go silent and nobody notices until fieldwork.
- The data goes stale and stays stale. Evidence links point at files that got moved or overwritten. A status says Done from a cycle two quarters ago. The sheet looks healthy because a spreadsheet cannot tell you its own contents are out of date. This is the same freshness problem that pushes analytics teams to add automated monitoring that flags stale and broken data rather than trusting a dashboard at face value, and compliance evidence rots the same way.
- Evidence collection is manual and enormous. Every access list, change log, and configuration screenshot is gathered by a human, on a deadline, the week before the audit. Gathering the evidence, not deciding anything about it, is where most of the hours go.
- Multi-framework means duplicate maintenance. The same access review is SOC 2 CC6.2, ISO 27001 A.5.18, GDPR Art. 32, HIPAA 164.308(a)(4), and PCI DSS Req. 7. In a spreadsheet you either copy the row into five tabs and maintain it five times, or you lose the cross-mapping and re-prove the same control per framework.
When should you move from Excel to compliance software?
Move when the tracker starts costing you deals or sleep, which in practice is one of four triggers: you cross about 30 live obligations, you add a second framework, evidence collection eats more than a day or two per audit cycle, or a missed review nearly slips into a customer's security questionnaire. Before any of those, stay in the spreadsheet and save the money.
The reason software helps is not that it stores the rows better. It is that it does the two things Excel structurally cannot: it assigns each obligation to a named person with a reminder that actually fires, and it pulls the evidence in on its own. Dedicated obligation tracking keeps every recurring task owned and dated, and automated evidence collection reads configuration from the systems you already run so the artifacts refresh on a schedule instead of on adrenaline. That is the whole difference: the work stops depending on one person remembering.
Excel vs compliance software: a quick comparison
| Dimension | Excel spreadsheet | Compliance software |
|---|---|---|
| Setup cost | An afternoon and a template | Connect your stack, score the same day |
| Best for | One framework, fewer than ~30 obligations | 1 to 5 frameworks, part-time owners |
| Ownership | A name in a cell nobody enforces | A named user, a due date, a reminder that fires |
| Evidence | Gathered by hand before the audit | Auto-collected from AWS, GitHub, Okta on a schedule |
| Multi-framework | Copy the tab, maintain it twice | Map a control once, it counts everywhere |
| Cost | Free, until a missed review costs a deal | Published from $79/mo on Complies |
If you are past the line and want a system rather than a spreadsheet, that is exactly what compliance tracking software is for: every obligation gets a row, a named owner, and a date, the calendar chases the dates, and evidence collects itself. Complies publishes its prices, starts at $79 a month, and cross-maps SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS from the Growth tier, so a second framework does not mean a second spreadsheet.
One honest caveat before you migrate: importing a messy spreadsheet into any tool imports the mess. Clean the owner and due-date columns first, decide which obligations are actually live, and drop the ones that were aspirational. The tool will chase whatever you give it.
This article is educational and is not legal advice. Which obligations apply to you depends on your contracts, your jurisdiction, and the data you handle; confirm those with qualified counsel or your auditor.
RUN IT, NOT JUST READ IT
Turn this into tracked rows with owners
Everything in this guide becomes obligations, controls, and evidence with owners and due dates inside Complies, with a live readiness score on top. Plans from $79 a month, prices published.