Complies

OBLIGATIONS · CALENDAR · EVIDENCE

Compliance tracking software: track compliance obligations on a compliance calendar

Every obligation gets a row, a named human, and a date. The compliance calendar chases the dates, evidence collects itself on a schedule, and a readiness score tells you where you actually stand instead of where you hoped you were.

See pricing

From $79/mo · Prices published · No sales call · Monthly billing

SOC 2 · TRUST SERVICES CRITERIA

Audit readiness

0 %

Your auditor makes the final call

Built for teams of 5 to 200

AWS GitHub Google Workspace Slack Jira Azure Okta
TRACK

What compliance tracking software actually is

Compliance tracking software is a system that lists every compliance obligation you carry, gives each one an owner and a due date, and shows in one place what is done, what is late, and what lands next month. It usually pairs an obligation register with a compliance calendar, a control library mapped to the frameworks in scope, and evidence attached to the control it proves. Complies is compliance tracking software for companies of 5 to 200 people, where compliance is a founder's or an engineer's second job rather than a department. The tracking layer is an obligation list with named humans on it: access reviews, policy reviews, vendor reviews, risk treatments, and control tests. The calendar layer turns recurring work into dated tasks that get chased before they go stale, which matters because most compliance failures are missed dates, not missing intent. The control layer maps each control once across SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS, so a quarterly access review satisfies five frameworks at once instead of five separate rows. Evidence collects itself on a schedule from AWS, GitHub, Google Workspace, and Okta, reading configuration rather than customer data. A live readiness score sits on top, with a ranked gap list naming what is missing. Pricing is published: Starter $79 a month, Growth $199, Scale $499, with all five frameworks cross-mapped from Growth. If you run a regulatory obligation library across multiple entities and legal jurisdictions, or you need a horizon-scanning feed of new rules, an enterprise GRC suite is the honest recommendation and Complies is not it.

Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.

Last updated July 2026

THE THREE LAYERS

The three layers of a tracker that actually holds

1

The obligation register

A tracker is only real when every row has a name on it. Each obligation carries an owner, a frequency, a due date, and the control or framework requirement it serves, so nothing survives as a vague intention in someone's inbox. Recurring work (quarterly access reviews, annual policy reviews, vendor re-checks) regenerates itself instead of quietly lapsing after the first cycle.

obligation tracking software
2

The compliance calendar

Dates are where compliance programs actually fail. The calendar shows what is due this week, what is late, and what is coming, filtered by owner so nobody has to read the whole program to find their three tasks. Reminders fire before the date, not after, and a missed item stays visible instead of scrolling out of a chat channel.

audit readiness tracking
3

Evidence attached to the thing it proves

Tracking a task is half the job. The other half is the artifact: the screenshot, the export, the log, the signed acknowledgment. Evidence attaches to the control it proves and refreshes on a schedule from AWS, GitHub, Google Workspace, and Okta, so when the auditor asks for Q2 access reviews you open a folder rather than start an excavation.

automated evidence collection
COMPARE

Three ways teams track compliance, and who each one is for

Most teams track compliance one of three ways, and the right answer depends entirely on how much program you have. Here is the honest comparison, including the cases where Complies is the wrong tool.

Dimension Spreadsheet and reminders Enterprise GRC suite Complies
Best for One framework, one person, fewer than about 30 obligations Multi-entity regulatory obligation libraries and a GRC team Companies of 5 to 200 tracking 1 to 5 frameworks part-time
Setup cost An afternoon and a template An implementation project, often with a partner Connect your stack, first readiness score the same day
Who owns a row A name typed in a cell that nobody enforces Assigned through workflow with escalation paths A named user, a due date, and a reminder that fires
Recurring tasks A calendar invite you delete when it is inconvenient Scheduled workflow with sign-off chains Recurring obligations regenerate with owners attached
Evidence A shared drive folder, organized by hope Full audit-management workflow and retention rules Auto-collected from AWS, GitHub, Google Workspace, Okta
Multi-framework Copy the tab and maintain it twice Deep coverage, scoped and priced per module SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS cross-mapped from Growth
Regulatory change feed You read the news Horizon scanning and regulatory content libraries Not offered. We track your obligations, not the statute book
Price Free, until a missed review costs you a deal Quote-only annual contracts Published: $79, $199, $499 per month, monthly billing available

Read that table honestly. If you have three obligations and one framework, a spreadsheet is genuinely fine and we will tell you so. If you run a multi-entity obligation library with a dedicated GRC team, an enterprise suite earns its price and Complies will feel thin. The middle of that range is what we built for. If you are also weighing the audit-readiness platforms, compare them in detail on Vanta alternatives, Drata alternatives and Sprinto alternatives.

CAPABILITIES

What you get on every plan from Growth

Nothing depends on one person remembering

The single biggest failure mode in a small program is that the tracker lives in the head of whoever set it up. Obligations here have owners, dates, and reminders, so when that person is on vacation or leaves, the quarterly access review still happens.

One task, five frameworks

A quarterly access review is SOC 2 CC6.2, ISO 27001 A.5.18, GDPR Art. 32, HIPAA 164.308(a)(4), and PCI DSS Req. 7 wearing different labels. Track it once and it counts everywhere. Finishing SOC 2 pre-fills roughly 60 percent of ISO 27001.

Late is visible, not buried

Overdue items surface on the calendar and in the readiness score instead of scrolling out of a Slack channel. You find out in week two that the vendor review slipped, not in the audit fieldwork call.

Evidence shows up on its own

Configuration reads from AWS, GitHub, Google Workspace, and Okta land on a schedule, attached to the control they prove. The gathering is the part that burns engineering time, and it is the part worth automating first.

A score that refuses to flatter you

Readiness is one number plus a ranked list of what is missing and who owns it. It never reads 100, because no software can promise an audit outcome, and a tracker that always shows green is just a decoration.

A price you can read before you talk to anyone

Starter $79 a month, Growth $199, Scale $499, published. Sign up and start this afternoon. Monthly billing means the tracker has to earn its seat every cycle rather than ride out a renewal clause.

SETUP

From signup to a readiness score

01

Load the obligations you already have

Import or pick the frameworks in scope and the control set generates the obligation list: reviews, tests, policy refreshes, vendor checks. Anything specific to you gets added as a custom obligation with the same fields.

02

Put a human on every row

An obligation without an owner is a wish. Assign each one to a named person with a frequency and a due date. Recurring items regenerate automatically, so the calendar stays populated after the first quarter.

03

Connect the systems the evidence lives in

Point Complies at AWS, GitHub, Google Workspace, and Okta. It reads configuration, not your customer data, and starts refreshing the artifacts behind your controls on a schedule.

04

Work the calendar and watch the score

Each week the calendar shows what is due and what slipped. Close the ranked gaps. When readiness says you are there, export the organized evidence pack and bring in your auditor.

FIT

Who this is for, and who it is not

A GOOD FIT WHEN

  • You are 5 to 200 people and your compliance tracker is currently a spreadsheet nobody has opened since March.
  • You keep missing recurring work: access reviews, policy reviews, vendor re-checks.
  • One or two people own compliance alongside their real jobs and need the dates chased for them.
  • You track more than one framework and refuse to maintain the same control in two places.
  • You want a published price and a signup form instead of a demo and a quote.

LOOK ELSEWHERE WHEN

  • You need regulatory horizon scanning: a feed of new and changing statutes across jurisdictions. Complies tracks your obligations, not the statute book.
  • You are tracking CMMC, consent, cookie banners, DSARs, or data mapping. Complies does not do any of those.
  • You run a multi-entity program with a dedicated GRC team, where an enterprise suite earns its price.
  • You have three obligations and one framework. A spreadsheet is honestly fine, and we will tell you so.
QUESTIONS

Common questions about compliance tracking

Compliance tracking software is a system that records every compliance obligation your company has, assigns each one an owner and a due date, and shows what is complete, what is overdue, and what is coming next. Most tools pair that register with a compliance calendar, a control library, and the evidence proving each control works.

You track compliance by turning every requirement into a dated task with a named owner, then keeping the evidence that proves each task happened. That means a list of obligations, a recurring calendar for the ones that repeat, and an artifact attached to each control. The hard part is not the list. It is making sure someone owns each row and that overdue work stays visible instead of quietly disappearing.

A compliance calendar is a dated schedule of every recurring compliance task: quarterly access reviews, annual policy reviews, vendor re-assessments, risk register updates, control tests, and audit windows. It exists because compliance programs rarely fail from bad intentions. They fail from missed dates. A good calendar shows the owner, the frequency, the due date, and whether the last cycle actually closed.

You build one row per obligation with columns for the requirement, framework, owner, frequency, due date, status, and a link to the evidence, then set calendar reminders separately because Excel will not chase anyone. It works up to roughly 30 obligations and one framework. Past that, the tabs drift, evidence links rot, and nobody notices a lapsed review until an auditor asks.

Compliance tracking is the visibility layer: what is due, who owns it, and whether it got done. Compliance management is broader and adds the work itself, including policies, risk treatment, vendor reviews, and audit preparation. In practice small teams need both, and buying a tracker that cannot hold the evidence usually means buying a second tool six months later.

Complies publishes its prices: Starter is $79 a month, Growth $199, and Scale $499, at the yearly-billed rate, with monthly available at $95, $239, and $599. Most vendors in this category are quote-led and annual-first, so a public number is unusual. Budget your auditor separately, since a SOC 2 Type 1 typically runs $5,000 to $20,000 in CPA firm fees.

A working tracker needs seven fields per row: the obligation, the framework requirement it satisfies, a named owner, a frequency, a due date, a status, and a link to the evidence. Add a calendar view filtered by owner and a plain overdue list. Anything past that is depth an enterprise program needs and a 25 person company will never open.

GO DEEPER

Frameworks and guides

Every obligation, one calendar, named owners

Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.