Learn

Practical articles on getting audit-ready — real costs and timelines, what auditors actually look for, and the regulations that apply to small teams. Need a definition? See the glossary; for framework overviews, read the guides.

Getting started

How to Respond to a Customer Security Questionnaire

A vendor security questionnaire is a buyer's way of vetting your security before they trust you with their data. You answer it fastest, and most credibly, by assembling the policies and evidence you already have and answering every question honestly.

Read the article

Do You Need an AI Use Policy for ChatGPT & Copilot at Work?

Yes — if your team uses ChatGPT, Copilot, or Gemini, you need an acceptable-use AI policy, because the alternative is "shadow AI" running with no rules at all. Here is what that policy should cover, and why writing it is only half the job.

Read the article

SOC 2 Type I vs Type II: Which Do You Need?

A SOC 2 Type I report attests that your controls are suitably designed on a single date; a Type II adds proof they actually operated over a period of months. Here is how the two differ, how to choose, and why most buyers eventually want Type II.

Read the article

NIST CSF 2.0 Explained: The Six Functions and Where to Start

The NIST Cybersecurity Framework 2.0 is a voluntary way to organize and self-assess your security program — no certificate involved. Here are its six Functions (with Govern new in 2.0), how Tiers and Profiles work, and a realistic place for a small organization to begin.

Read the article

SOC 2 Trust Services Criteria Explained (the Five Categories)

Every SOC 2 report is measured against the AICPA Trust Services Criteria — five categories, of which only Security is mandatory. Here is what each category covers, why Security maps to the Common Criteria, and how your scoping choices drive audit effort and cost for both Type I and Type II.

Read the article

What Is an ISMS? The ISO 27001 Information Security Management System

An ISMS — an information security management system — is the set of policies, processes, roles, and decisions an organization runs to manage information risk deliberately and improve it over time. ISO/IEC 27001:2022 specifies what a conforming ISMS must contain, and certification is what proves yours actually works.

Read the article

Buyer's guides

Where to Buy ISO 27001 Policy Templates (2026): Free, Paid & Consultant Options

There are four common routes to ISO/IEC 27001:2022 policy templates: free libraries (SANS publishes 30+ free, editable security policy templates; GRC vendors like Vanta, Secureframe and Drata offer free policy packs as lead-gen, though offerings change), paid editable template sets, enterprise toolkit platforms, and compliance consultants. A complete 2022 documentation set runs to about 24 policies and procedures (around 16 for a lean core), plus a risk register and the 93-control Statement of Applicability.

This guide compares the routes honestly so you can pick one — but note up front that no template, free or paid, makes an organization certified or compliant. ISO 27001 certification is issued only by an accredited body after a Stage 1 and Stage 2 audit of a working ISMS.

Read the article

WISP Template for Tax Preparers (2026): The Free IRS Option and Paid Toolkits

Every tax and accounting firm that handles client financial data must maintain a Written Information Security Plan (WISP) under the FTC Safeguards Rule (16 CFR Part 314), which implements the Gramm-Leach-Bliley Act — and at PTIN renewal the IRS asks preparers to confirm they are aware of this data-security obligation. You have three routes to a WISP document: the free sample template in IRS Publication 5708, free vendor templates, and paid editable toolkits built for tax firms. This guide compares them honestly. Up front: a written plan is required, but the document by itself does not make a firm compliant — you have to operate the safeguards it describes.

Read the article

HIPAA Policy Templates for Dental & Medical Practices (2026): What to Look For

HIPAA has no official certification — compliance is self-attested and enforced by the HHS Office for Civil Rights (OCR). A working set for a small practice is about 18 policies covering the Security and Privacy Rules, a Business Associate Agreement (BAA) template, and a Security Risk Assessment (SRA) workbook. This guide covers what to look for in HIPAA policy templates for dental, medical and mental-health practices, names the genuinely free options (including the free HHS SRA Tool), and is plain about the limit: a toolkit gives you the documents, but the risk assessment is the real work and no template makes a practice HIPAA compliant on its own.

Read the article

SOC 2 Policy Templates for Startups (2026): Buyer Guide

SOC 2 is not a certification — it is an examination against the AICPA Trust Services Criteria, and a licensed CPA firm issues the report. A working startup set is about 22 policies mapped to the criteria (around 15 for a lean core). For startups trying to clear enterprise security questionnaires and close deals, the choice is usually between free GRC-vendor templates, a paid editable set, a consultant, or a continuous-monitoring platform. This guide compares them honestly. The constant: no template, free or paid, makes a company "SOC 2" — the report comes only from a CPA firm examining controls you actually operate.

Read the article

ISO 27001 + SOC 2 Without a Consultant (2026): The Cheapest Honest Path

You can do most of the ISO 27001 and SOC 2 documentation yourself without a consultant — and because the two frameworks share many controls, one security program mapped to both is cheaper than documenting each separately. For the documentation layer, an editable dual toolkit is a one-time $149, versus illustrative consultant fees of $1,250+ or monitoring platforms at $7,000+/yr. This guide lays out the honest cheapest path. The one thing you cannot DIY: the SOC 2 report comes only from a licensed CPA firm, and ISO 27001 certification only from an accredited body after a Stage 1 and Stage 2 audit. No purchase skips those.

Read the article

How Much Do SOC 2 Policy Templates Cost in 2026?

A complete, editable SOC 2 policy template set costs $59–$149 as a one-time purchase in 2026. Free options exist — several GRC vendors publish free SOC 2 policy templates as lead-generation, and open-source repositories on GitHub carry usable individual policies — while enterprise toolkit platforms run an illustrative $897–$2,397 and a compliance consultant $1,250–$2,750+ for the same documentation layer. This page prices the routes honestly. Note the template cost is separate from the audit itself: a SOC 2 report is a licensed CPA firm’s attestation, priced and performed independently of whichever templates you use.

Read the article

HIPAA Policy Templates vs Hiring a Consultant: Which Does Your Practice Need?

For the HIPAA documentation layer — the ~18 written policies plus a Security Risk Assessment worksheet a small practice needs — an editable template set is a one-time $79, while a compliance consultant engagement runs an illustrative $1,250–$2,750+ (estimates, not quotes). The honest answer to "which do I need" is: templates fit a practice that can spend a few focused hours tailoring documents to how it actually operates; a consultant earns the premium when you need hands-on program work, remediation of a known problem, or someone to run the risk analysis with you.

Neither route, by itself, makes a practice compliant — HIPAA compliance comes from operating the safeguards, training the workforce and keeping the risk analysis current.

Read the article

Free vs Paid ISO 27001 Toolkits: An Honest Comparison (2026)

You can assemble a real ISO 27001 starting point for $0: SANS publishes 30+ free editable security policy templates, several GRC vendors (Vanta, Secureframe, Drata among them — offerings change) give away policy packs as lead-generation, and open-source GitHub repositories carry usable policy sets. What free routes rarely include is the connective tissue — a coherent, cross-referenced ISMS set, a populated risk register and the 93-control Statement of Applicability. Paid toolkits at $59–$149 one-time sell exactly that assembly. This page maps what free genuinely covers and what paid actually adds, so you can choose on facts. Either way, certification comes only from an accredited body auditing a working ISMS — no toolkit changes that.

Read the article

Common questions

Compliance Questions, Answered

Straight, honest answers to the questions buyers actually ask about compliance documentation — what each framework requires, what it costs, how long it takes, and the one rule that never changes: a template gives you the documents an auditor expects, but it does not make your organization certified or compliant.

Read the article

Original research & data

Compliance Documentation Benchmarks: What a Policy Library Actually Contains

How long is a security policy, how much of it do you have to fill in, and what is a compliance documentation set actually made of? These benchmarks are measured from the 261 Word documents ComplianceDocs ships across 16 toolkit editions, and from its catalog of 125 unique document templates, as of 2026-09-02. They describe the ComplianceDocs library only — no other vendor, and no estimate of the market.

Read the article

How Long Breach Notification Actually Takes, Measured from California’s Register

The median incident in California’s official data-breach register took 135 days to travel from the breach itself to a report on the Attorney General’s public list — measured across 4,758 incidents from the register’s 5,266 rows as of 2026-08-20. 91.2% of incidents took longer than 30 days and 64% took longer than 90. The interval has also grown: among filings reported in 2013 the median was 62 days, and among those reported in 2025 it was 186 days — more than double, on a robust trend of about 10.2 days a year.

The interval includes the time it took to discover the breach, so it measures the full distance between an incident and its disclosure — not compliance with any statutory deadline.

Read the article

HIPAA Breach Reports, Measured from the Full OCR Register

The HHS Office for Civil Rights has published 7,868 reports of health-data breaches affecting 500 or more individuals since the portal opened in 2009, covering a cumulative 1,068,214,394 individuals — figures computed from both public views of the portal (the open-investigation list and the resolved archive) as of 2026-08-20. The structural story is the takeover by hacking: 4% of reports in 2010 named a hacking or IT incident; in 2025 it was 80.9%, and in 2026 so far it is 87.4%.

The register records when each report reached OCR, not when the breach happened or was discovered, so these are statistics about reports received — not a measure of anyone's compliance with a notification deadline.

Read the article

How Long Organizations Take to Report a Breach After They Discover It

Most breach statistics measure the distance from the breach to the notice, which bundles together two very different problems: not knowing, and not telling. Washington State's official breach register records both endpoints. Across 1,615 filings, the median interval from the day an organization recorded becoming aware of a breach to the day it notified the Attorney General is 67 days, and 85 days across 2021–2025.

Two things about the register itself turn out to matter more than the headline: one incident can produce a hundred separate filings, and slightly over half of Washington's filings are incidents that also appear in California's register. These are descriptive intervals computed from dates the filers reported, and they measure no organization's compliance with anything.

Read the article

What the UK ICO Actually Does: Enforcement Actions in Numbers

The UK Information Commissioner’s Office publishes every enforcement action it takes, one page per action, with no aggregate view of any kind. Counted across all 222 actions in that register as it stands on 2026-09-02: 98 are reprimands, 64 are monetary penalties, 55 are enforcement notices and 6 are prosecutions. This is a composition of the register, not a history of everything the ICO has ever done, and deliberately not a series over time — the reason is in the method note.

Read the article

Governance Docs Alternatives: ISO 27001 and ISO 42001 Toolkits Compared (2026)

Governance Docs lists its ISO 42001 Toolkit at $199.00 one-time and its ISO 27001, SOC 2, GDPR and NIST SP 800-53 toolkits at $99.00 one-time each (governancedocs.com, checked 5 September 2026). The verified alternative for the same document classes is ComplianceDocs: the ISO 42001 AI Management System Toolkit at $99 one-time, ISO 27001 toolkits at $59 to $99, and SOC 2 toolkits at $59 to $99, all editable Word and Excel files with instant download under a single-organization license.

Governance Docs' pages state far larger document counts; every product page we read displays a 30-day money-back guarantee, and the ISO 42001 and ISO 27001 pages additionally state 12 months of free updates, neither of which ComplianceDocs offers. No template, at any price, makes an organization certified or compliant on its own.

Read the article

ISO Docs Alternatives: ISO 42001 and ISO 27001 Toolkits Compared (2026)

ISO Docs, the iso-docs.com store (site header "ISO Templates and Documents Download", part of the Techno-PM group), lists its ISO 42001 Toolkit & AI Governance Framework at $799.00 USD one-time and its ISO 27001 Toolkit Documentation Toolkit at $299.00 (iso-docs.com/products/iso-42001-ai-governance-framework and iso-docs.com/products/iso27001-bundle, checked 5 September 2026). ComplianceDocs sells the same product class, editable one-time Word and Excel document sets licensed to one organization, at $99 (ISO 42001, ISO 27001 Complete, SOC 2 Complete) and $79 (NIST CSF 2.0), with fewer templates at every price point. No template, at any price, makes an organization certified or compliant on its own.

Read the article

2026 Compliance Template Pricing Index

Editable compliance policy toolkits cost $49–$599 one-time in the ComplianceDocs catalog. Across five named competitors whose public pricing pages were fetched on August 19, 2026, a complete ISO 27001 documentation toolkit runs from £97 to $897 one-time — and the per-document unit price spreads from about $3.65 to $19.93, a five-fold gap that is the real story of this market. No template, at any price, makes an organization certified or compliant on its own.

Read the article

How Many Documents Each Compliance Framework Actually Requires

A complete ISO/IEC 27001:2022 documentation set runs to about 24 policies and procedures plus the 93-control Statement of Applicability; a SOC 2 set is around 22 policies mapped to the Trust Services Criteria; a small-practice HIPAA set is about 18 policies plus a Security Risk Assessment; and NIST CSF 2.0 spans 6 Functions, 22 Categories and 106 Subcategories. The exact list depends on scope, but these are the document counts auditors typically expect.

Read the article

How Long Compliance Documentation Actually Takes

Tailoring a professionally structured policy template takes most teams 15–60 minutes per document using Find & Replace on the bracketed placeholders — so a full ISO 27001 set (≈24 documents) is realistically one to three focused days of editing, versus the weeks a consultant engagement or from-scratch drafting typically takes. The documentation is the slowest part of getting audit-ready, which is exactly the part a template removes; you still have to operate the controls and produce evidence.

Read the article

ISO 27001 Documentation Toolkits Compared: 2026 Prices and What You Get

ISO 27001 documentation-toolkit prices published in July 2026 run from $59 to $1,582: ComplianceDocs' editable Word/Excel sets are $59–$99 one-time, High Table lists $97–$597 across three tiers (store sale prices), GRC Solutions charges £395 ex. VAT for year one of its UK subscription and $1,265 (on sale from $1,582) for its US Complete Suite, CertiKit lists £595 excl. VAT, and Advisera lists $897 — every figure taken from the vendor's own public pricing page.

The higher prices verifiably buy more than documents — video tutorials, live expert consultations, multi-user and consultant licenses — but no template, at any price, makes an organization certified or compliant on its own. Pricing update, re-fetched August 19, 2026: High Table's pricing page now lists £97 / £297 / £590 (its product pages served $97 / $297 / $590 to a US visitor), and GRC Solutions' transactable UK store price is £495 ex. VAT one-time — the freshest dated snapshot lives on the 2026 Compliance Template Pricing Index.

Read the article

Vanta, Drata & Alternatives: Platform vs. Template Costs in 2026

As of July 2026, none of the leading compliance automation platforms — Vanta, Drata, Secureframe, Sprinto — publishes a price on its public pricing page (all sell quote-based subscriptions, with third-party contract data reporting median annual contracts of $15,000–$24,869), while editable policy template toolkits cost $49–$599 one-time and cover only the documentation layer.

They are different product categories, and for most startups they are consecutive stages rather than substitutes: platforms continuously monitor controls and collect evidence — and also bundle policy templates — so a team that only needs the document set today can start with templates and adopt a platform when a customer demands continuous monitoring. No template — and no platform — at any price makes an organization certified or compliant on its own.

Read the article

HIPAA Policy Templates for Small Practices: 2026 Options Compared

A small practice can buy a complete, editable HIPAA policy template set for $79 to $1,497 one-time, based on prices published on six vendors' public pages retrieved July 2026 — from ComplianceDocs' 18-policy toolkits at $79 to HIPAA Essentials Library's 110-document Program in a Box at $1,497 — while full-service compliance platforms such as Accountable publish subscription plans at $199–$799 per month. Whatever the price, the documentation set must cover the same five components: Privacy Rule and Security Rule policies, breach-notification procedures, a documented security risk analysis, and business associate agreements — and no template, at any price, makes a practice certified or compliant on its own.

Read the article

Advisera Alternatives: ISO 27001 Toolkit Options at Every Price (2026)

Verified Advisera alternatives as of July 2026: ComplianceDocs at $59–$99 one-time, High Table at $97–$597 across three license tiers (store sale prices, Aug 2026), CertiKit at £595.00 excl. VAT one-time, and GRC Solutions (the rebranded IT Governance) at £395.00 ex. VAT for year one of its UK subscription or $1,265.00 on sale for its US Complete Suite — every figure as published on the vendor's own pricing page.

What you give up is Advisera's bundled help: its $897 toolkit verifiably includes video tutorials, an expert review of a document, and live one-on-one consultations — the strongest bundled-help offer published in this market — while every alternative is documents-only or a different delivery model. No template, at any price, makes an organization certified or compliant on its own.

Read the article

High Table Alternatives: ISO 27001 Toolkits Compared (2026)

As of July 2026, High Table lists its ISO 27001 toolkit at $97 (Document Pack, reduced from $395), $400 (Business Edition) and $597 (Consultant Edition, reduced from $997), and the verified alternatives — every figure taken from the vendor's own public pricing page — are ComplianceDocs at $59–$99 one-time, CertiKit at £595 excl. VAT, Advisera at $897, and GRC Solutions' UK subscription at £395 ex. VAT for year one.

Which alternative fits depends on the tier: the $97 Document Pack competes with $59–$99 document sets, the $400 Business Edition with CertiKit and Advisera, and the $597 Consultant Edition — an explicit unlimited-client, white-label license — has no direct equivalent among these vendors, ComplianceDocs included. No template, at any price, makes an organization certified or compliant on its own.

Pricing update, re-fetched August 19, 2026: High Table's pricing page now lists £97 (Document Pack), £297 (Business Edition) and £590 (Consultant Edition), with its product pages serving $97 / $297 / $590 to a US visitor — the freshest dated snapshot lives on the 2026 Compliance Template Pricing Index.

Read the article

CertiKit Alternatives: ISO 27001 Toolkit Options Compared (2026)

As of July 2026, the verified alternatives to CertiKit's £595.00 (excl. VAT) ISO 27001 Toolkit are ComplianceDocs at $59–$99 one-time, High Table at $97–$597 across three license tiers (store sale prices, Aug 2026), Advisera at $897 one-time, and GRC Solutions at £395 ex. VAT for year one of its UK subscription or $1,265 (on sale from $1,582) for its US Complete Suite — every price as published on the vendor's own public page.

CertiKit's verifiable strengths are the largest document count we verified (60+ ISMS documents plus 130+ Annex A control documents) and the friendliest license terms at its tier (perpetual, unlimited internal users, no subscription), so the honest question is not which toolkit is "best" but whether you need that volume — and no template, at any price, makes an organization certified or compliant on its own.

Read the article

ComplianceForge Alternatives: ISO 27001 Documentation Compared (2026)

ComplianceForge's ISO 27001 / 27002 policies-and-standards product is listed at $1,980.00 USD one-time, with procedures sold separately at $4,700.00 and the combined bundle at $5,344.00 (complianceforge.com, checked 1 August 2026). The verified alternatives for the documentation itself are ComplianceDocs at $59–$99 one-time, CertiKit at £595.00 excl. VAT, Advisera at $897 one-time, and ISMS Copilot from $20/month. One caveat stated up front: if you are looking at ComplianceForge for CMMC or NIST 800-171, none of the alternatives below — including ours — is a substitute.

Read the article

Compliance statistics

GDPR Fines in Numbers: Enforcement and Penalty Statistics

European data protection authorities have issued roughly €6.31 billion in GDPR fines across 3,206 enforcement actions since May 2018, per the CMS GDPR Enforcement Tracker as of August 19, 2026. The largest fine remains Meta’s €1.2 billion (Irish DPC, 2023), 2025 added about €1.2 billion more, and the most common grounds are insufficient legal basis (Art. 6), violations of the core processing principles (Art. 5) and insufficient security measures (Art. 32) — failures of exactly the program-and-documentation layer small businesses most often skip.

Read the article

HIPAA Breach and Enforcement Statistics Through Mid-2026

2025 was the worst year on record for large healthcare data breaches — 772 breaches of 500+ records reported to HHS, affecting roughly 139.7 million people. The HHS Office for Civil Rights closed 21 enforcement actions in 2025 for about $8.3 million, and its Risk Analysis Initiative is aimed squarely at the failure small practices most often have: never completing a compliant security risk analysis. There is no small-practice exemption; Right of Access penalties have started as low as $3,500 for a solo dental office.

Read the article

ISO 27001 Certification in Numbers: The Latest ISO Survey Data

There were 96,709 valid ISO/IEC 27001 certificates covering 179,877 sites worldwide in the ISO Survey 2024 — the latest edition available as of July 2026 — up from 36,362 certificates in the 2019 survey, roughly a 2.7x increase in five years. China leads by a wide margin, information technology is the most-certified sector, and since October 31, 2025 every valid certificate is to the 2022 revision with its 93 Annex A controls.

Read the article

What a Data Breach Costs: The Verified 2026 Numbers

The average data breach costs $4.99 million globally — a 12% rise to a record high — and a record $11.5 million in the United States, per IBM’s Cost of a Data Breach Report 2026, published July 29, 2026. ComplianceDocs compiled and edition-labeled every figure on this page from the primary reports: Verizon’s DBIR 2026 puts ransomware in 48% of breaches with a median ransom payment of $139,875, the FBI logged $20.9 billion in reported cybercrime losses for 2025, and for small businesses the sharpest verified finding is that in extreme cases a breach costs more than 7% of annual revenue.

Read the article

Costs & timelines

How Much Does SOC 2 Cost (and How Long Does It Take)?

A SOC 2 report is a CPA attestation, and its real cost is several pieces stacked together: the examination fee, readiness work, optional tooling, and staff time. Here is how each one typically breaks down, with realistic ranges and ways to spend less.

Read the article

How Much Does ISO 27001 Certification Cost?

ISO 27001 certification costs are driven mainly by the accredited audit and the work to build a working ISMS — not by buying documents. Here are realistic, illustrative ranges and a kickoff-to-certificate timeline for a small or mid-sized organization.

Read the article

Getting audit-ready

What Auditors Actually Look For in Your First Audit

A first ISO 27001 or SOC 2 audit rarely fails on the framework itself — it stumbles on missing evidence, reconstructed records, and policies that do not match reality. Here is what an auditor actually examines, and how to be ready.

Read the article

How to Write an Information Security Policy

The Information Security Policy is the cornerstone document of an ISO 27001 ISMS or a SOC 2 program — and usually the first thing an auditor reads. Here is what it should contain, who owns it, and why short and honest beats long and aspirational.

Read the article

How to Do an ISO 27001 Risk Assessment (Step by Step)

An ISO 27001 risk assessment is required by clause 6.1.2, and its quality depends on reflecting your real environment, not the template you start from. Here is how to define a repeatable method, identify and rank risks, and turn the results into a treatment plan and Statement of Applicability.

Read the article

Vendor Risk Management for Small Teams

Every vendor that touches your data or systems inherits a piece of your risk. Here is a lightweight, repeatable way for a small team to inventory, tier, vet, and monitor third parties — without building a procurement department.

Read the article

How to Write Your ISO 27001 Statement of Applicability (SoA)

The Statement of Applicability is the central ISMS document an ISO 27001 auditor reaches for first. It records every one of the 93 Annex A:2022 controls, whether each applies, why, and where it stands — and it follows directly from your risk assessment and treatment plan under clause 6.1.3.

Read the article

How to Do a HIPAA Security Risk Assessment (Step by Step)

The HIPAA Security Rule requires every covered entity and business associate to assess the risks to the ePHI it holds. Here is what the risk analysis requirement actually says, the step-by-step methodology OCR expects, and why no template can complete it for you.

Read the article

How to Write a Security Incident Response Plan

A security incident response plan turns a chaotic event into a rehearsed procedure. This guide shows how to build one. It covers the NIST SP 800-61 lifecycle, roles, severity tiers, notification, evidence handling, and testing.

Read the article

How to Do a GDPR DPIA (Data Protection Impact Assessment)

A DPIA is the documented risk assessment GDPR Article 35 requires before you start high-risk processing. Here is what it is, when it is mandatory, the step-by-step process, and when you must consult your regulator first.

Read the article

How to Respond to a GDPR Data Subject Access Request (DSAR)

A Data Subject Access Request gives an individual the right to a copy of their personal data and supplementary information under GDPR Article 15. Here is the deadline, what you must provide, when a fee or refusal is allowed, and a step-by-step workflow.

Read the article

How to Write a WISP (FTC Safeguards Rule), Step by Step

A WISP is the written information security plan the FTC Safeguards Rule requires of tax and accounting firms. Here is what it must contain, how to draft one section by section, and why writing it is only half the job.

Read the article

How to Run an ISO 27001 Internal Audit (Clause 9.2)

Clause 9.2 of ISO/IEC 27001:2022 requires you to audit your own information security management system at planned intervals — before a certification body ever does. Here is what the clause actually requires, how to run the audit, and where the work is yours alone.

Read the article

Do You Need a Penetration Test for SOC 2 or ISO 27001?

Neither SOC 2 nor ISO 27001 spells out a mandatory annual penetration test in its text — yet auditors and enterprise buyers routinely expect evidence of technical security testing. Here is what the standards actually require, how a pentest differs from a vulnerability scan, and what to hand your auditor.

Read the article

How to Get SOC 2 Ready: A Step-by-Step Roadmap

Getting SOC 2 ready follows a predictable sequence: scope the right Trust Services Categories, close gaps, document and operate controls, and collect evidence. ComplianceDocs' six-step roadmap below lays that sequence out end to end, with the limit stated up front: the report itself comes only from a licensed CPA firm.

Read the article

HIPAA Security Awareness Training: What's Required

HIPAA requires every covered entity and business associate to run a security awareness and training program for all workforce members, including management. Here is what the Security Rule and Privacy Rule actually require, why "addressable" does not mean optional, and why you have to deliver and evidence the training, not just write the policy.

Read the article

How to Write an Access Control Policy (for ISO 27001 & SOC 2)

The Access Control Policy is one of the most heavily tested documents in any ISO 27001 or SOC 2 engagement. Here is what it must cover, how it maps to the controls auditors check, and how to make it true rather than aspirational.

Read the article

Business Continuity vs Disaster Recovery (BCP vs DRP): What's the Difference?

Business continuity keeps your critical operations running through a disruption; disaster recovery is the IT-focused arm that restores systems and data. Here is how they fit together, what RTO and RPO actually mean, and how ISO 27001 and SOC 2 expect you to handle both.

Read the article

Data Retention and Disposal: How Long to Keep Data (and How to Destroy It)

Keeping data forever is a liability, not an asset. This is how to decide how long to keep each kind of data, how a retention schedule differs from a legal hold, and how to destroy data securely when its time is up.

Read the article

What Is a SOC 2 Bridge Letter (Gap Letter)?

A SOC 2 bridge letter — also called a gap letter — is a short statement your own organization writes to cover the gap between the end of your last SOC 2 report period and a customer's reliance date. It is your management's assertion that nothing material changed, not a new audit opinion, and never a substitute for a fresh report.

Read the article

ISO 27001:2022 vs 2013: What Changed

ISO/IEC 27001 was revised in October 2022, reshaping Annex A from 114 controls in 14 domains into 93 controls across four themes, adding 11 new controls and control attributes. The transition from the 2013 edition ended on 31 October 2025, so all certification is now against the 2022 version.

Read the article

Encryption Requirements for ISO 27001, SOC 2, HIPAA & GDPR

None of these frameworks names a specific algorithm or key length — each expects encryption appropriate to the risk. Here is how ISO 27001, SOC 2, HIPAA, and GDPR actually treat encryption, where the safe harbors live, and why key management, not the cipher, is where programs fail.

Read the article

How to Write a Change Management Policy (for ISO 27001 & SOC 2)

A change management policy keeps changes to your systems controlled so they do not quietly break security or availability. Here is what it must cover, how it maps to ISO 27001 and SOC 2, and how auditors expect you to evidence it.

Read the article

Regulations

Do Tax Preparers Need a WISP? The FTC Safeguards Rule & IRS Form W-12, Explained

Yes—if you prepare tax returns, federal law treats you as a "financial institution," and the FTC Safeguards Rule requires you to develop, implement, and maintain a Written Information Security Plan (WISP). Here is where that obligation comes from and what your plan has to cover.

Read the article

The EU AI Act for Small Companies: What You Actually Need to Do

The EU AI Act can reach small and non-EU companies whose AI outputs touch the EU. Here is a plain-English map of who it covers, the four risk tiers, and how a governance program helps you get ready.

Read the article

GDPR for US Companies: Does It Apply to You?

A US company with no European office can still fall under the GDPR. The trigger is Article 3: if you offer goods or services to people in the EU, or monitor their behavior, the regulation reaches you across the Atlantic.

Read the article

HIPAA for Small Practices: What You Actually Have to Do

HIPAA applies to small medical, dental, and therapy practices the same way it applies to large ones — but there is no "HIPAA certification" to buy. Here is what the rules actually require, and where a documented program ends and your daily operation of it begins.

Read the article

What Is a Business Associate Agreement (BAA)? HIPAA, Explained

A Business Associate Agreement is the written contract HIPAA requires before you let a vendor create, receive, maintain, or transmit protected health information on your behalf. Here is who needs one, when the law requires it, what it must contain, and where a signed agreement ends and your daily oversight begins.

Read the article

Do You Need ISO 42001? AI Management Systems vs the EU AI Act

ISO/IEC 42001 is a voluntary, certifiable standard for managing AI; the EU AI Act is binding law with risk tiers and deadlines. They are not the same thing — here is how each works, who needs which, and where they meet.

Read the article

GDPR Records of Processing Activities (RoPA): Article 30 Explained

A Record of Processing Activities is the written inventory at the heart of GDPR accountability. Article 30 says what it must contain, who keeps it, and why the "fewer than 250 employees" exemption almost never lets a working business off the hook.

Read the article

HIPAA Breach Notification: What to Do After a Breach

When unsecured protected health information is exposed, HIPAA presumes a breach and starts a clock the moment you discover it. Here is what the Breach Notification Rule (45 CFR 164.400-414) actually requires — the four-factor analysis, the notification matrix, and where a written procedure helps.

Read the article

The NIST AI Risk Management Framework (AI RMF 1.0), Explained

The NIST AI Risk Management Framework is a voluntary way to organize and improve how you manage AI risk — no certificate involved. Here are its four functions, the seven characteristics of trustworthy AI, how it relates to the EU AI Act and ISO 42001, and a realistic place for a small organization to begin.

Read the article

HIPAA Privacy Rule vs Security Rule: What's the Difference?

The HIPAA Privacy Rule governs all protected health information in any form. The Security Rule governs electronic PHI specifically and prescribes the safeguards that protect it. Here is how the two rules differ, where they overlap, and why a real program needs both.

Read the article

The GDPR 72-Hour Breach Notification Rule (Articles 33 & 34)

A personal data breach starts a clock: notify your supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware. Here is what Articles 33 and 34 require, when you must also tell affected individuals, and how to run a response.

Read the article

Cookie Consent Under GDPR and the ePrivacy Directive

Cookie consent sits on two laws at once: the ePrivacy Directive requires consent before non-essential cookies are set, and the GDPR defines what valid consent must look like. Here is how the two fit together and what a compliant banner actually has to do.

Read the article

HIPAA Compliance for Telehealth and Online Therapy

HIPAA applies in full to telehealth and online therapy delivered by covered entities and their business associates. The OCR COVID-19 enforcement discretion that briefly allowed consumer tools has ended, so practices now need a HIPAA-eligible platform under a signed Business Associate Agreement, plus the Security Rule safeguards that protect ePHI in transit.

Read the article

EU AI Act Deadlines: The Verified Timeline

Verified against the Official Journal on August 19, 2026: the EU AI Act’s prohibitions and AI-literacy duties have applied since February 2, 2025, general-purpose AI obligations since August 2, 2025, and the Article 50 transparency duties (chatbot disclosure, deepfake labeling, synthetic-content marking) have been in force since August 2, 2026. The "Digital Omnibus" amendment is now law — Regulation (EU) 2026/1744, adopted July 8, 2026 and published in the Official Journal on July 24, 2026 — deferring stand-alone Annex III high-risk duties to December 2, 2027 and product-embedded Annex I duties to August 2, 2028. The next deadline on the calendar is December 2, 2026: machine-readable marking for generative systems already on the market.

Read the article

Professional editable templates — general information only, not legal, audit, tax, or certification advice, and no professional or advisory relationship is created. No purchase makes an organization compliant or certified. Review each document with qualified counsel, your compliance professional, or your auditor before relying on it. ISO, IEC, SOC 2, AICPA, HIPAA, NIST, GDPR, the EU AI Act, IRS and FTC are referenced descriptively only; ComplianceDocs (ExpertEngine LLC) is independent and is not affiliated with, endorsed by, or certified by any standards body, regulator, or audit firm.