Free compliance resources

Practical, no-cost resources to help small teams, MSPs and regulated professionals get audit-ready faster — without paying consultant rates to learn the basics. Start with a step-by-step checklist, get oriented with a framework guide, look up any term in the glossary, then browse the editable policy templates that turn all of it into documentation.

Step-by-step checklists

Free, actionable checklists you can work through in order. No email required to read them.

The ISO 27001:2022 Starter Checklist

Get ISO 27001 audit-ready in 9 steps — defining scope, running the risk assessment, building the Statement of Applicability, the internal audit, and the Stage 1 and Stage 2 certification audits. Read it on the page, or download the one-page PDF to share with your team.

Read the checklist Download the PDF

The WISP Starter Checklist for Tax Preparers

Build a Written Information Security Plan in 8 steps — the plan every US tax and accounting firm must maintain under the FTC Safeguards Rule (16 CFR Part 314), and PTIN renewal asks you to confirm. Covers the Qualified Individual, risk assessment, required safeguards, testing, training, vendor oversight and incident response.

Read the checklist

The GDPR Compliance Checklist for Small Business

Work through the EU GDPR in 8 steps — mapping your data (Article 30 RoPA), choosing a lawful basis (Article 6), privacy notices, data-subject rights (DSARs), consent, DPIAs, the 72-hour breach rule, and processor and international-transfer controls. Written for small businesses handling EU or UK data.

Read the checklist

The ISO 42001 Starter Checklist (AI Management System)

Build an AI Management System to ISO/IEC 42001:2023 in 9 steps — scope, AI policy, the AI risk assessment and the AI system impact assessment, the Annex A Statement of Applicability, AI-lifecycle controls, internal audit and the certification audit. Also the operational backbone for EU AI Act readiness.

Read the checklist

Free full policy templates (Word)

Complete, editable policy templates — the full text is on the page and the .docx download is free, no email required. Drafted to the same standard as the paid toolkits.

Free HIPAA Sanction Policy Template (Word)

HIPAA Security & Privacy Rules — the written document 45 CFR §164.308(a)(1)(ii)(C) and §164.530(e)(1) calls for. Read the full template on the page, then download the editable Word version.

Read & download free

Or download the Word file directly (.docx)

Free ISO 27001 ISMS Scope Statement Template (Word)

ISO/IEC 27001:2022 — the written document Clause 4.3 (Determining the scope of the ISMS) calls for. Read the full template on the page, then download the editable Word version.

Read & download free

Or download the Word file directly (.docx)

Free Change Management Policy Template for SOC 2 (Word)

SOC 2 (AICPA Trust Services Criteria) — the written document TSC CC8.1 (Change Management) calls for. Read the full template on the page, then download the editable Word version.

Read & download free

Or download the Word file directly (.docx)

Free Backup and Recovery Policy Template (Word)

ISO/IEC 27001:2022 — the written document ISO/IEC 27001:2022 Annex A 8.13 (Information backup) calls for. Read the full template on the page, then download the editable Word version.

Read & download free

Or download the Word file directly (.docx)

Free Vulnerability and Patch Management Policy Template (Word)

ISO/IEC 27001:2022 — the written document ISO/IEC 27001:2022 Annex A 8.8 (Management of technical vulnerabilities) calls for. Read the full template on the page, then download the editable Word version.

Read & download free

Or download the Word file directly (.docx)

Free Security Awareness Training Policy Template for ISO 27001 (Word)

ISO/IEC 27001:2022 — the written document ISO/IEC 27001:2022 Annex A control A.6.3 (Information security awareness, education and training), supported by A.5.4 (Management responsibilities) and A.6.4 (Disciplinary process); Clauses 7.2 (Competence), 7.3 (Awareness), and 7.5 (Documented information) calls for. Read the full template on the page, then download the editable Word version.

Read & download free

Or download the Word file directly (.docx)

Free Asset Management and Information Classification Policy Template (Word)

ISO/IEC 27001:2022 — the written document ISO/IEC 27001:2022 Annex A 5.9, 5.10, 5.11, 5.12, 5.13, 7.10, 7.14, 8.10 calls for. Read the full template on the page, then download the editable Word version.

Read & download free

Or download the Word file directly (.docx)

GDPR Articles Reference — all 99 articles (Excel)

Every article of Regulation (EU) 2016/679 by chapter, with a status drop-down, owner and evidence columns so it works as a tracker. Free, no email required.

Read & download free

Or download the Excel file directly (.xlsx)

Get new templates and guides by email

An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.

Guides, comparisons & references

Deeper background when you need to choose a framework, understand what an audit involves, or settle the exact meaning of a term.

Compliance Documentation Calculator

Interactive and free — pick your framework (ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF 2.0, ISO 42001, AI governance, WISP) and organization type to see exactly which documents you need, with real counts, editing-time estimates and prices.

Open the calculator

Framework guides

Plain-English overviews of ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF 2.0, ISO 42001 and AI governance — what each one is, who needs it, realistic costs and timelines, and the fastest route to audit-ready documentation.

Browse the guides

Articles & how-tos

In-depth, plain-English articles — how to respond to a customer security questionnaire, what SOC 2 and ISO 27001 actually cost, what auditors look for, WISP rules for tax preparers, and the EU AI Act for small companies.

Read the articles

Framework comparisons

Side-by-side breakdowns — ISO 27001 vs SOC 2, NIST CSF vs ISO 27001, HIPAA vs GDPR, ISO 42001 vs the EU AI Act — to help you choose the right framework, or the right combination, for your situation.

Compare frameworks

Compliance glossary

Plain-English definitions of the audit and information-security terms that matter — ISMS, Statement of Applicability, SOC 2 Type I vs II, BAA, DPIA, RoPA and dozens more — written so you and your auditor mean the same thing.

Open the glossary

Policy template library (A–Z)

Browse every editable policy and procedure template in our toolkits — over a hundred documents across access control, incident response, data protection, risk management and more, each mapped to the frameworks it supports.

Browse policy templates

Original research & data

Original benchmarks you can cite — what compliance documentation costs, how many documents each framework requires, and how long it takes to tailor a toolkit — plus straight answers to the questions buyers ask most.

2026 Compliance Template Pricing Index

What compliance policy templates actually cost — $49–$149 one-time across eight frameworks, next to consultant ($1,250–$2,750+) and enterprise-platform ($897–$2,397) ranges, with the document count behind every price.

See the pricing index

Documents per compliance framework

How many policies and procedures each framework really needs — ISO 27001 (~24), SOC 2 (~22), HIPAA (~18), GDPR (~14), plus NIST CSF 2.0, ISO 42001, AI governance and the WISP — in one comparative table.

Compare document counts

How long compliance documentation takes

Realistic editing-time benchmarks — 15–60 minutes per document, so a full ISO 27001 set is one to three focused days of work, not the weeks a consultant or from-scratch drafting takes.

See the time benchmarks

Compliance questions, answered

Straight, honest answers to 25 of the most common compliance questions — across ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF, WISP and AI governance — each linking to the toolkit or guide that goes deeper.

Read the answers

GDPR fines in numbers

GDPR enforcement through July 2026, every figure sourced: €6.31 billion in fines across 3,195 actions, the record €1.2B Meta fine, the most-fined articles (Art. 6, 5 and 32), and the Article 83 maximums.

See the GDPR numbers

HIPAA breach & enforcement statistics

772 large breaches reported in 2025 — the worst year on record — plus OCR’s Right of Access and Risk Analysis enforcement initiatives that reach solo and small practices, and the 2026 civil penalty tiers.

See the HIPAA numbers

ISO 27001 certification statistics

The latest ISO Survey data: 96,709 valid certificates across 179,877 sites worldwide, the top countries, five-year growth, and why every valid certificate is now against the 2022 revision.

See the ISO numbers

Data breach cost statistics

What a breach actually costs, every figure edition-labelled: $4.44M global / $10.22M US average (IBM 2025), ransomware medians (DBIR 2026), FBI-reported losses, and the verified small-business impact numbers.

See the breach-cost numbers

EU AI Act deadlines, verified

The EU AI Act timeline as verified against official EU sources in July 2026 — what already applies, the August 2, 2026 transparency duties, and the Digital Omnibus deferral of high-risk obligations to Dec 2027 / Aug 2028.

See the verified timeline

How to use these resources

If you are starting from scratch, read the framework guide for the standard you need, then work through the matching checklist to understand the milestones. Use the glossary whenever a term is unfamiliar, and when you are ready to document your program, the policy templates give you professionally structured Microsoft Word and Excel files you adapt to your organization — a fraction of the cost and time of writing them yourself or hiring a consultant. None of these resources are legal advice; review your final documents with qualified counsel, your compliance professional, or your auditor.

Professional editable templates — general information only, not legal, audit, tax, or certification advice, and no professional or advisory relationship is created. No purchase makes an organization compliant or certified. Review each document with qualified counsel, your compliance professional, or your auditor before relying on it. ISO, IEC, SOC 2, AICPA, HIPAA, NIST, GDPR, the EU AI Act, IRS and FTC are referenced descriptively only; ComplianceDocs (ExpertEngine LLC) is independent and is not affiliated with, endorsed by, or certified by any standards body, regulator, or audit firm.