ACCESS REVIEWS · CC6.2 · A.5.18 · 7.2.4
User access review software: a user access review tool for SOC 2, ISO 27001, PCI DSS and SOX access reviews
The access review is rarely skipped. It is done in a spreadsheet, half the reviewers never reply, nobody checks the revocations closed, and the file gets overwritten before the auditor asks for it.
From $79/mo · Prices published · No sales call · Monthly billing
Audit readiness
0 %
Built for teams of 5 to 200
What user access review software does, and the frequency rule almost everyone gets wrong
User access review software runs the periodic check that everyone who still has access to a system is supposed to have it, and produces the dated record an auditor accepts as proof. The work has four parts: pull the current list of users and their entitlements out of each system, route each line to a person who actually knows whether that access is still justified, capture an explicit keep or revoke decision with a reviewer name and a timestamp, then confirm the revocations happened and file the whole thing as evidence. Access reviews are among the most common evidence gaps in a SOC 2 audit, and the reason is almost never that the review did not happen. It is that it happened in a Slack thread and a spreadsheet, so nothing dated names who approved what.
One fact reshapes most shortlists: only one major framework names a review interval. PCI DSS 4.0.1 requirement 7.2.4 requires that all user accounts and related access privileges, including third party and vendor accounts, are reviewed at least once every six months to confirm access remains appropriate to job function. That requirement stopped being best practice and became mandatory on March 31, 2025, along with the other 50 future dated requirements the PCI Security Standards Council brought into force in v4.x. SOC 2, ISO 27001 and HIPAA all decline to name a number. The SOC 2 Trust Services Criteria ask under CC6.2 that the appropriateness of access credentials is reviewed on a periodic basis. ISO 27001:2022 Annex A 5.18 asks that access rights be reviewed at regular intervals, with the interval set by your own risk assessment. The HIPAA information access management standard at 164.308(a)(4) requires the process and prescribes no cadence at all. Quarterly for standard accounts and monthly for privileged ones is the convention auditors have settled on, but it is a convention, and a documented risk based interval you actually meet defends better than a quarterly promise you miss twice a year.
The category then splits into two groups that solve genuinely different problems, and buying the wrong one is expensive. Identity governance tools such as Microsoft Entra ID Governance, Okta Identity Governance, Lumos, C1 and AccessOwl connect to your identity provider and your applications, and they can execute the change: revoke the entitlement, deprovision the account, run the joiner mover leaver workflow. Compliance platforms hold the review as an obligation and the result as evidence, cross mapped to every framework that asks for it, without touching your identity plane. Complies sits firmly in the second group. It holds the access review as a recurring obligation with a named owner and a due date, stores the exported user list and the decisions as evidence, maps that single artifact to SOC 2 CC6.2 and CC6.3, ISO 27001 A.5.18, PCI DSS 7.2.4 and HIPAA 164.308(a)(4) at the same time, and flags the review before it is late rather than after. It does not connect to your applications to revoke access, it does not provision accounts, and it does not run joiner mover leaver automation. If what you need is automated revocation, buy an identity governance tool, and do not let anyone tell you a compliance platform substitutes for one. If what you need is for the review to happen on schedule, to be decided by the right person, and to leave something an auditor accepts, that is the half Complies covers, at $79 to $499 a month with the price printed on the page.
Complies assists with compliance workflows. It is not legal advice, and it does not certify you or guarantee audit outcomes. Your auditor decides; Complies gets you ready.
Last updated September 2026
The three phases of an access review, and where each one breaks
Pull a complete list, not a convenient one
The review is only as good as its scope. A list exported from the identity provider covers everyone who signs in through single sign on and misses the accounts that never did: local database users, service accounts with standing credentials, contractors added directly to a repository, the shared vendor login nobody owns. Those are the accounts that turn up in findings, because they are exactly the ones that outlive the person who created them. Decide the system list first, write down why anything is out of scope, and keep that reasoning with the evidence so next quarter starts from a decision rather than a guess.
compliance evidence collectionGet a real decision from someone who can make it
Sending the whole user list to IT produces rubber stamping, because IT knows what access exists and not whether it is still warranted. The person who can answer is the manager or system owner who knows what the individual does now, and the useful unit of review is one reviewer looking at their own people rather than one person looking at everybody. Each line needs an explicit keep or revoke, the name of who decided, and the date. A blank line is not an approval, and an auditor reads it as one thing: the review was not finished.
obligation tracking softwareClose the loop, then keep the record
The step that fails most often is the last one. Revocations get raised as tickets and the review is filed before anyone checks the tickets closed, so the evidence proves a decision was made and not that anything changed. Tie each revoke decision to its confirmation, keep the original export alongside the decisions and the closure proof, and hold the next cycle as a dated obligation rather than a calendar reminder someone will snooze. That bundle, export plus decisions plus closure plus date, is what satisfies the requirement in every framework at once.
audit readiness softwareHow often each framework actually requires an access review
Vendor marketing in this category tends to say that "frameworks require quarterly access reviews". One of them names an interval. The rest hand the decision back to you and then test whether you kept the promise you made in your own policy, which is a very different obligation and a more forgiving one if you set it honestly.
| Framework and requirement | What the text actually requires | Named interval? | What auditors expect in practice |
|---|---|---|---|
| PCI DSS 4.0.1, requirement 7.2.4 | All user accounts and related access privileges, including third party and vendor accounts, reviewed to confirm access remains appropriate to job function, with any inappropriate access addressed and management confirming the access level is appropriate. | Yes. At least once every six months for user accounts. Mandatory since March 31, 2025, when the future dated v4.x requirements took effect. | A six month cycle with the date evidenced. Application and system account frequency can instead be set by a targeted risk analysis under 7.2.5.1, which is the flexibility most teams miss. |
| SOC 2, CC6.2 and CC6.3 | Users are registered and authorized before credentials are issued, access is removed when no longer appropriate, and the appropriateness of access credentials is reviewed on a periodic basis. CC6.3 covers modification and removal specifically. | No. The Trust Services Criteria say periodic and leave the interval to you. | Quarterly for most systems, but tested against whatever your own policy states. A policy promising quarterly and delivering twice a year is worse than a policy that honestly says twice a year. |
| ISO 27001:2022, Annex A 5.18 | Access rights to information and associated assets are provisioned, reviewed, modified and removed in line with the organization's access control policy, including on role change and on exit. | No. The control asks for regular intervals and leaves the interval to your risk assessment. | A risk based split, with privileged and administrative access reviewed more often than standard access and the reasoning written down. The auditor checks that you meet the interval you set yourself. |
| HIPAA Security Rule, 164.308(a)(3) and (a)(4) | Workforce security and information access management: procedures for authorizing access to electronic PHI, for establishing, documenting, reviewing and modifying a user's right of access, and for terminating access when employment ends. | No. The Security Rule prescribes the process and names no cadence. | An interval set in your own policy that you can show you met, commonly annual at minimum with quarterly for systems holding ePHI, plus a termination record for every leaver. |
| SOX IT general controls | Access to financially relevant systems is appropriate and restricted, tested as an IT general control supporting the internal control over financial reporting assertion. | No. Set by your control description and the external auditor's testing approach. | Quarterly is close to universal for in scope financial systems, because the auditor samples periods across the year and a missed quarter reads as a control deficiency rather than a late task. |
The practical consequence is worth stating plainly, because it is where teams create their own findings. Outside PCI DSS, the interval that binds you is the one written in your own access control policy. A policy that promises quarterly reviews and delivers three in a year produces a deficiency; a policy that says semi annual for standard access and quarterly for privileged access, backed by your risk assessment and actually met, does not. Before buying anything, read what your policy currently commits you to. Changing that sentence is free and sometimes fixes the whole problem. Compare the multi-framework platforms in this space in detail on Vanta alternatives, Drata alternatives and Sprinto alternatives.
Access review tools compared, and what each one actually costs
This category is unusually quiet about money. We checked every vendor's own pricing page in September 2026 rather than repeating third party summaries, and only two print a per user number. Everything below is read off the vendor's own page on the date shown, and anything a vendor does not publish is recorded as not published rather than estimated.
| Tool | What it actually does | Who it fits | Published pricing (September 2026) |
|---|---|---|---|
| Microsoft Entra ID Governance | Access reviews, entitlement management and lifecycle workflows inside Microsoft Entra, able to revoke access directly for the applications Entra governs. | Organizations already standardized on Microsoft 365 and Entra, where most access already flows through a single identity provider. | Published: $7.00 per user per month paid yearly. It is an add on that requires Entra ID P1 at $7.00 or P2 at $10.00, so the practical floor is around $14.00 per user per month. |
| AccessOwl | SaaS access management covering access requests, approvals, joiner mover leaver workflows, shadow IT detection and access reviews. | Growing companies whose sprawl is across many SaaS apps rather than one directory, and who want provisioning and review from the same tool. | Published: Basic $4.50 and Growth $6.00 per user per month, both with a $250 monthly minimum and 15 percent off annually. Access reviews sit in Growth, not Basic. Provisioning is a $2.50 per user add on. Enterprise is quote only. |
| Okta Identity Governance | Access certification campaigns, lifecycle management and workflows layered on Okta as the identity provider. | Companies already running Okta that want governance without introducing a second vendor into the identity plane. | Not published. Okta's own pricing page lists Identity Governance as an add on and says to inquire for pricing. |
| Lumos | Identity governance covering app discovery, license management, access requests and access reviews. | IT teams whose main problem is SaaS sprawl and over provisioned accounts rather than a specific audit deadline. | Not published. The pricing page offers an ROI calculator and a demo form and prints no figures. |
| C1, formerly reached at conductorone.com | Access reviews, just in time access and access requests for workforce identity, now also marketed around governing AI agents. As of September 2026 conductorone.com issues a 301 redirect to c1.ai. | Mid market and growth stage companies meeting SOC 2 or ISO 27001 access requirements for the first time. | Not published. The pricing page describes SKU based tiers named Pro, Advanced and Enterprise scaled by managed identities from 100 to 20,000 and above, plus a usage based Flex option, but prints no dollar figures. |
| Vanta, Drata, Secureframe and Sprinto | Compliance automation platforms that run access review campaigns alongside evidence collection and continuous control monitoring, so review results land directly in the SOC 2 or ISO 27001 evidence set. | Funded startups running a full framework program that want the access review inside the same tool as everything else. | Not published. All four are quote only and annual first. Vendr reported a median Vanta contract of about $20,000 a year in February 2026. |
| Complies | Holds the access review as a recurring obligation with an owner and a due date, stores the export and the keep or revoke decisions as evidence, and cross maps that one artifact to SOC 2 CC6.2 and CC6.3, ISO 27001 A.5.18, PCI DSS 7.2.4 and HIPAA 164.308(a)(4). It does not revoke access. | Teams of 5 to 200 whose access review problem is that it slips and leaves no record, rather than that revocation is manual. | Published: $79, $199 and $499 a month at the yearly rate, charged flat rather than per user. |
Two honest notes about reading that table. First, the price shapes are not comparable until you have decided what you are buying. For a 50 person company, Entra ID Governance plus the required P1 licence is roughly $700 a month and AccessOwl Growth is roughly $300, against $199 flat for Complies, but the first two can revoke access and Complies cannot. Per user pricing also means your compliance cost grows with headcount even though the review workload barely does. Second, the silence is itself the finding: five of the seven entries above publish nothing at all, which means most access review budgets in the United States are set after a discovery call rather than before one. If you are building a business case, that is the friction to plan around.
What Complies covers when the access review has to survive an audit
The review shows up before it is late
Access reviews do not fail dramatically. They slip a month, then a quarter, and the gap only surfaces when an auditor samples the period nobody covered. Complies holds each cycle as an obligation with a named owner and a due date, and flags it in advance rather than recording afterwards that it was missed.
One artifact, every framework that asks for it
A completed access review satisfies SOC 2 CC6.2 and CC6.3, ISO 27001 A.5.18, PCI DSS 7.2.4 and HIPAA 164.308(a)(4) at the same time. Cross mapping means you attach the export and the decisions once and they count everywhere, instead of the same spreadsheet being re-collected for each audit in a different folder.
Evidence with the decision attached, not just the list
A user export on its own proves nothing. What an auditor tests is whether somebody competent looked at each line and decided. Each evidence item carries the reviewer, the date and the outcome, so the record answers the question being asked rather than the easier one.
A dated history instead of a current state
Frameworks test periods, not moments. Last quarter's review has to still be retrievable with its original date when the auditor samples it eight months later, which is exactly what a shared drive full of access-review-final-v3.xlsx cannot give you. Every cycle stays filed against the control it supports.
Honest about where it stops
Complies reads configuration and access from Okta, Google Workspace, GitHub and AWS to help assemble the list. It does not push changes back, revoke entitlements, deprovision accounts or run joiner mover leaver automation. That boundary is stated here rather than discovered during your trial.
A price you can budget before a sales call
Most of this category is quote only, which means the number arrives after a demo and a discovery call. Complies publishes $79, $199 and $499 a month, billed monthly, with self serve signup, so the access review line in your budget can be filled in this afternoon.
Running an access review an auditor accepts, without buying an IGA platform
Decide the system list, and write down the exclusions
Start with anything holding customer data, production infrastructure, source code, money movement or administrative rights over the rest. Then name what you are leaving out and why. The exclusion note is doing real work: it is the difference between a scoped review and an incomplete one, and it is the first thing an auditor pushes on.
Export current access per system, including the accounts that skip single sign on
Identity provider exports cover federated access and stop there. Add local accounts, service accounts, standing API credentials and anyone added directly to a repository or a database. Connect Okta or Google Workspace, GitHub and AWS so the recurring part of that assembly stops being manual.
Route each user to the person who can actually judge the access
Split the list by manager or system owner rather than sending one file to everyone. Ask for a keep or revoke on each line, with a reason on anything unusual. Set a deadline shorter than the review period, because the last reviewer always finishes on the final day.
Close the revocations, then file the whole bundle as evidence
Raise a ticket per revoke, confirm each one closed, and attach the export, the decisions, the reviewer names and the closure proof to the control. Then schedule the next cycle immediately, while you still remember what was annoying about this one.
Who this is for, and who it is not
A GOOD FIT WHEN
- Your access review already happens, but it lives in a spreadsheet and an auditor asked for the dated record.
- You owe SOC 2 or ISO 27001 and the access review is the control most likely to be found operating ineffectively.
- You take card payments and PCI DSS 7.2.4 now means a hard six month cycle you have to prove.
- You want the review cross mapped once across every framework instead of repeated per audit.
- You want the cost on the page rather than after a discovery call, and you are under 200 people.
LOOK ELSEWHERE WHEN
- You need access revoked or accounts deprovisioned automatically; that is identity governance and Complies does not do it.
- You want joiner mover leaver provisioning workflows driven from your HR system.
- You need just in time or time bound privileged access elevation.
- You have thousands of identities and a dedicated identity team, where an enterprise IGA platform is the honest answer.
- You want a tool that discovers shadow IT and reclaims unused SaaS licenses; that is a different category.
User access review questions buyers actually ask
A user access review is a periodic check that every account with access to a system still needs it, and that the level of access matches what the person does now. You export the current users and their entitlements, have someone who knows the role decide keep or revoke on each line, act on the revocations, and keep the dated record. It is also called a user access certification or an entitlement review.
Quarterly for standard accounts and monthly for privileged or administrative accounts is the convention most auditors expect, but only PCI DSS names an actual number: at least once every six months under requirement 7.2.4. SOC 2, ISO 27001 and HIPAA leave the interval to your own risk assessment and then test whether you meet the interval you set. Choose one you can sustain and document why.
Detective. The review finds inappropriate access that already exists, after the fact, which is why frameworks pair it with preventive controls rather than accepting it alone. The preventive counterparts are the approval step at provisioning and the termination procedure that removes access on exit. An auditor expects both, because a detective control catching the same problem every quarter signals the preventive one is broken.
The manager or system owner who knows what the person does now, not the IT team that granted the access. IT knows what access exists; only the business owner knows whether it is still warranted. In practice the security or compliance team runs the process, sets the deadline and collects the evidence, while the actual keep or revoke decisions come from the people accountable for each system or team.
The system in scope, the complete list of accounts and their entitlements, a keep or revoke decision on every line, the name of the reviewer, the date the decision was made, and confirmation that each revocation actually happened. Blank lines are the most common defect, because an auditor reads an undecided line as an unfinished review rather than an implicit approval.
Decide which systems are in scope and record why anything is excluded. Export current users and entitlements from each one, including local and service accounts that bypass single sign on. Split the list by manager or system owner and ask for an explicit keep or revoke on each line with a deadline. Raise tickets for the revocations, confirm they closed, then file the export, the decisions and the closure proof together.
At least once every six months. Requirement 7.2.4 of PCI DSS 4.0.1 covers all user accounts and related access privileges, including third party and vendor accounts, and requires that inappropriate access is addressed and that management confirms the access level is appropriate. It was a future dated requirement and became mandatory on March 31, 2025. Application and system accounts can follow a frequency set by a targeted risk analysis under 7.2.5.1 instead.
Both, and the same review satisfies each. SOC 2 tests it under CC6.2 and CC6.3, which cover authorization, periodic review of access appropriateness, and removal. ISO 27001:2022 covers it under Annex A 5.18, access rights. Because the evidence an auditor wants is nearly identical, running one review and cross mapping it to both is the normal approach rather than running two.
The original export showing who had access at the time, a decision recorded against each account, the identity of the reviewer, the date, and proof that revoked access was actually removed. A screenshot of a current user list does not work, because it shows today rather than the review period. The point of the artifact is to be dated and unchanged since.
In IT general controls, usually in a SOX context, the user access review is the periodic control proving that access to financially relevant systems is appropriate and restricted. It sits alongside access provisioning, access removal and privileged access controls. External auditors typically sample across the year, so quarterly is close to universal for in scope financial systems and a single missed quarter is treated as a deficiency.
A spreadsheet genuinely works up to a point: a handful of systems, one reviewer, and someone disciplined enough to date and archive each cycle. It stops working when reviewers stop replying, when nobody can prove the revocations closed, or when the file is overwritten and last quarter's version is gone. Those three failures, not the size of the list, are what push teams onto a tool.
Identity governance connects to your applications and can execute the change, revoking entitlements and deprovisioning accounts. Compliance oriented access review tooling holds the review as an obligation, captures the decisions and keeps the evidence, without touching your identity plane. They overlap in the middle and solve different problems at the edges, so the deciding question is whether your bottleneck is doing the revocation or proving the review.
Very few vendors say. As of September 2026, Microsoft publishes Entra ID Governance at $7.00 per user per month paid yearly on top of a required Entra ID P1 or P2 licence at $7.00 or $10.00, and AccessOwl publishes $4.50 and $6.00 per user per month with a $250 monthly minimum. Okta, Lumos, C1, Vanta, Drata, Secureframe and Sprinto all publish no figure. Complies publishes $79, $199 and $499 a month, flat rather than per user.
No, and it is worth being blunt about it. Complies reads access and configuration from Okta, Google Workspace, GitHub and AWS to help assemble the list, then holds the review, the decisions and the evidence. It does not push changes back, revoke entitlements, deprovision accounts or run joiner mover leaver workflows. If automated revocation is the requirement, an identity governance platform is the right purchase.
Frameworks and guides
SOC 2 compliance software
ISO 27001ISO 27001 compliance software
PCI DSSPCI DSS compliance software
ACCESSUser Access Review: Process, Checklist, Frequency
CROSS-FRAMEWORKAudit Evidence Examples: What Auditors Actually Ask For
CROSSWALKControl Mapping: SOC 2, ISO 27001, HIPAA, PCI DSS
AUTOMATECompliance Automation vs Manual: When to Switch
Make the access review a dated record instead of a spreadsheet nobody kept
Prices published, $79 to $499 a month. Monthly billing. Start today, no sales call.