Complies
OB-01 OBLIGATIONS

Obligation tracking software: compliance obligation tracking with owners and due dates

Every requirement from every framework in one tracker, with a named owner, a status, and a due date. The calendar chases people so you do not have to.

See pricing

Obligation tracking software keeps every regulatory and framework obligation in one system, each with a named owner, a current status, and a due date, so nothing lives in a spreadsheet tab that nobody reopens until the audit. Complies builds that tracker automatically when you connect your stack and pick your frameworks: every SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS requirement becomes a tracked obligation, and the compliance calendar shows what is due this week, this month, and this quarter. Reminders go to the owner in Slack or email before a deadline slips, not after, and recurring obligations like quarterly access reviews reschedule themselves. Because obligations are cross-mapped, closing one item can update your standing in several frameworks at once. Pricing is published on the site: the tracker and calendar are included from the Starter plan at $79 per month billed yearly, with monthly billing available and no sales call required, while a compliance consultant runs $15,000 to $40,000 per audit. One honest limitation: Complies tracks, schedules, and chases the work, but your team still has to do it. What changes is that everyone can finally see what the work is, who owns it, and when it is due.

It is one capability inside our compliance tracking software. It works alongside compliance evidence collection and audit readiness, and plugs straight into soc 2 compliance software, iso 27001 compliance software on every plan from Growth up.

OB-01 OBLIGATIONS

What changes when it is in place

One tracker for every framework

SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS obligations live in a single list with owners and statuses, instead of five spreadsheets maintained by whoever remembered last.

A compliance calendar that chases

Quarterly access reviews, annual policy refreshes, pentest windows, and evidence renewals sit on one calendar. Owners get reminded in Slack before a deadline slips, not in a postmortem after.

Owners, not vague responsibility

Every obligation has exactly one named owner. When something is overdue, the tracker shows who, since when, and what closing it unblocks, so follow-up is a message, not a meeting.

Recurring work handles itself

Obligations on a cadence reschedule automatically after each completion, with the prior evidence attached for reference. The second and third audit cycles get cheaper instead of starting from scratch.

QUESTIONS

Common questions

It is a system that lists every obligation your frameworks impose, assigns each one an owner and a due date, and tracks status over time. Complies goes one step further by cross-mapping obligations across SOC 2, ISO 27001, GDPR, HIPAA, and PCI DSS, so completing one item can advance several frameworks at once instead of being logged five separate times.

A spreadsheet does not send reminders, reschedule recurring reviews, or update itself when a connected system changes. Complies does all three, and the tracker feeds a live readiness score, so status is always current instead of current as of the last time someone edited the sheet. Teams typically stop maintaining the spreadsheet within the first month.

Yes. Reminders go out through Slack and email, obligations can be pushed to Jira as tickets, and the calendar view covers weekly, monthly, and quarterly cadences. Complies connects to AWS, GitHub, Google Workspace, Slack, Jira, Azure, and Okta, so due dates live where your team already works.

Put obligation tracking on autopilot

All plans include it. Prices are public. Start today.