Free compliance resources
Practical, no-cost resources to help small teams, MSPs and regulated professionals get audit-ready faster — without paying consultant rates to learn the basics. Start with a step-by-step checklist, get oriented with a framework guide, look up any term in the glossary, then browse the editable policy templates that turn all of it into documentation.
Step-by-step checklists
Free, actionable checklists you can work through in order. No email required to read them.
The ISO 27001:2022 Starter Checklist
Get ISO 27001 audit-ready in 9 steps — defining scope, running the risk assessment, building the Statement of Applicability, the internal audit, and the Stage 1 and Stage 2 certification audits. Read it on the page, or download the one-page PDF to share with your team.
The WISP Starter Checklist for Tax Preparers
Build a Written Information Security Plan in 8 steps — the plan every US tax and accounting firm must maintain under the FTC Safeguards Rule (16 CFR Part 314), and PTIN renewal asks you to confirm. Covers the Qualified Individual, risk assessment, required safeguards, testing, training, vendor oversight and incident response.
The GDPR Compliance Checklist for Small Business
Work through the EU GDPR in 8 steps — mapping your data (Article 30 RoPA), choosing a lawful basis (Article 6), privacy notices, data-subject rights (DSARs), consent, DPIAs, the 72-hour breach rule, and processor and international-transfer controls. Written for small businesses handling EU or UK data.
The ISO 42001 Starter Checklist (AI Management System)
Build an AI Management System to ISO/IEC 42001:2023 in 9 steps — scope, AI policy, the AI risk assessment and the AI system impact assessment, the Annex A Statement of Applicability, AI-lifecycle controls, internal audit and the certification audit. Also the operational backbone for EU AI Act readiness.
Free full policy templates (Word)
Complete, editable policy templates — the full text is on the page and the .docx download is free, no email required. Drafted to the same standard as the paid toolkits.
Free HIPAA Sanction Policy Template (Word)
HIPAA Security & Privacy Rules — the written document 45 CFR §164.308(a)(1)(ii)(C) and §164.530(e)(1) calls for. Read the full template on the page, then download the editable Word version.
Free ISO 27001 ISMS Scope Statement Template (Word)
ISO/IEC 27001:2022 — the written document Clause 4.3 (Determining the scope of the ISMS) calls for. Read the full template on the page, then download the editable Word version.
Free Change Management Policy Template for SOC 2 (Word)
SOC 2 (AICPA Trust Services Criteria) — the written document TSC CC8.1 (Change Management) calls for. Read the full template on the page, then download the editable Word version.
Free Backup and Recovery Policy Template (Word)
ISO/IEC 27001:2022 — the written document ISO/IEC 27001:2022 Annex A 8.13 (Information backup) calls for. Read the full template on the page, then download the editable Word version.
Free Vulnerability and Patch Management Policy Template (Word)
ISO/IEC 27001:2022 — the written document ISO/IEC 27001:2022 Annex A 8.8 (Management of technical vulnerabilities) calls for. Read the full template on the page, then download the editable Word version.
Free Security Awareness Training Policy Template for ISO 27001 (Word)
ISO/IEC 27001:2022 — the written document ISO/IEC 27001:2022 Annex A control A.6.3 (Information security awareness, education and training), supported by A.5.4 (Management responsibilities) and A.6.4 (Disciplinary process); Clauses 7.2 (Competence), 7.3 (Awareness), and 7.5 (Documented information) calls for. Read the full template on the page, then download the editable Word version.
Free Asset Management and Information Classification Policy Template (Word)
ISO/IEC 27001:2022 — the written document ISO/IEC 27001:2022 Annex A 5.9, 5.10, 5.11, 5.12, 5.13, 7.10, 7.14, 8.10 calls for. Read the full template on the page, then download the editable Word version.
GDPR Articles Reference — all 99 articles (Excel)
Every article of Regulation (EU) 2016/679 by chapter, with a status drop-down, owner and evidence columns so it works as a tracker. Free, no email required.
Get new templates and guides by email
An occasional email when we publish a new free template, guide, or dataset. Unsubscribe any time.
Guides, comparisons & references
Deeper background when you need to choose a framework, understand what an audit involves, or settle the exact meaning of a term.
Compliance Documentation Calculator
Interactive and free — pick your framework (ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF 2.0, ISO 42001, AI governance, WISP) and organization type to see exactly which documents you need, with real counts, editing-time estimates and prices.
Framework guides
Plain-English overviews of ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF 2.0, ISO 42001 and AI governance — what each one is, who needs it, realistic costs and timelines, and the fastest route to audit-ready documentation.
Articles & how-tos
In-depth, plain-English articles — how to respond to a customer security questionnaire, what SOC 2 and ISO 27001 actually cost, what auditors look for, WISP rules for tax preparers, and the EU AI Act for small companies.
Framework comparisons
Side-by-side breakdowns — ISO 27001 vs SOC 2, NIST CSF vs ISO 27001, HIPAA vs GDPR, ISO 42001 vs the EU AI Act — to help you choose the right framework, or the right combination, for your situation.
Compliance glossary
Plain-English definitions of the audit and information-security terms that matter — ISMS, Statement of Applicability, SOC 2 Type I vs II, BAA, DPIA, RoPA and dozens more — written so you and your auditor mean the same thing.
Policy template library (A–Z)
Browse every editable policy and procedure template in our toolkits — over a hundred documents across access control, incident response, data protection, risk management and more, each mapped to the frameworks it supports.
Original research & data
Original benchmarks you can cite — what compliance documentation costs, how many documents each framework requires, and how long it takes to tailor a toolkit — plus straight answers to the questions buyers ask most.
2026 Compliance Template Pricing Index
What compliance policy templates actually cost — $49–$149 one-time across eight frameworks, next to consultant ($1,250–$2,750+) and enterprise-platform ($897–$2,397) ranges, with the document count behind every price.
Documents per compliance framework
How many policies and procedures each framework really needs — ISO 27001 (~24), SOC 2 (~22), HIPAA (~18), GDPR (~14), plus NIST CSF 2.0, ISO 42001, AI governance and the WISP — in one comparative table.
How long compliance documentation takes
Realistic editing-time benchmarks — 15–60 minutes per document, so a full ISO 27001 set is one to three focused days of work, not the weeks a consultant or from-scratch drafting takes.
Compliance questions, answered
Straight, honest answers to 25 of the most common compliance questions — across ISO 27001, SOC 2, HIPAA, GDPR, NIST CSF, WISP and AI governance — each linking to the toolkit or guide that goes deeper.
GDPR fines in numbers
GDPR enforcement through July 2026, every figure sourced: €6.31 billion in fines across 3,195 actions, the record €1.2B Meta fine, the most-fined articles (Art. 6, 5 and 32), and the Article 83 maximums.
HIPAA breach & enforcement statistics
772 large breaches reported in 2025 — the worst year on record — plus OCR’s Right of Access and Risk Analysis enforcement initiatives that reach solo and small practices, and the 2026 civil penalty tiers.
ISO 27001 certification statistics
The latest ISO Survey data: 96,709 valid certificates across 179,877 sites worldwide, the top countries, five-year growth, and why every valid certificate is now against the 2022 revision.
Data breach cost statistics
What a breach actually costs, every figure edition-labelled: $4.44M global / $10.22M US average (IBM 2025), ransomware medians (DBIR 2026), FBI-reported losses, and the verified small-business impact numbers.
EU AI Act deadlines, verified
The EU AI Act timeline as verified against official EU sources in July 2026 — what already applies, the August 2, 2026 transparency duties, and the Digital Omnibus deferral of high-risk obligations to Dec 2027 / Aug 2028.
How to use these resources
If you are starting from scratch, read the framework guide for the standard you need, then work through the matching checklist to understand the milestones. Use the glossary whenever a term is unfamiliar, and when you are ready to document your program, the policy templates give you professionally structured Microsoft Word and Excel files you adapt to your organization — a fraction of the cost and time of writing them yourself or hiring a consultant. None of these resources are legal advice; review your final documents with qualified counsel, your compliance professional, or your auditor.
