Compliance buying guides
Start with the decision you need to make
Practical guides for software teams choosing tools, hiring specialists, and responding to customers. Each guide ends with a concrete next step and links to relevant directory pages.
Plan certificationHow to plan an ISO 27001 certification engagementDefine ISO 27001 certification scope, assign ISMS responsibilities, evaluate certification bodies, compare audit-cycle costs, and plan ongoing reviews.Act on testing resultsHow to review and use a penetration-test reportCheck penetration-test coverage, prioritize findings, assign remediation, verify fixes, record risk decisions, and prepare an accurate customer handoff.Share security informationHow to build a useful security trust centerPlan a security trust center around approved documents, product scope, access rules, review dates, customer requests, and a tested sharing workflow.Hire security leadershipHow to choose a virtual CISOScope a virtual CISO engagement around accountable leadership, named staff, decision rights, capacity, deliverables, escalation, and handover.Organize recurring workHow to plan compliance evidence collectionTurn compliance evidence requests into recurring work with scoped sources, owners, review steps, exception handling, controlled sharing, and a usable handoff.Review a supplierHow to assess a vendor's securityBuild a vendor security review around service scope, data access, evidence, rating findings, accountable decisions, and follow-up work.Choose privacy softwareHow to evaluate privacy management softwareCompare privacy software through data inventory, assessment, rights-request, approval, integration, and export workflows using a scoped pilot.Hire an auditorHow to choose a SOC 2 auditorCompare SOC 2 audit firms by issuing CPA firm, scope, independence, evidence workflow, milestones, and proposal exclusions.Choose softwareHow to evaluate compliance softwareRun a practical compliance software demo: integration permissions, evidence quality, control mapping, auditor access, exports, and total scope.Respond to a customerBuild a security questionnaire workflowOrganize customer security questionnaires with evidence owners, approved answers, review dates, controlled sharing, and a repeatable tool evaluation.Hire a testing providerHow to scope a penetration testWrite a penetration testing brief covering assets, access, authorization, testing limits, deliverables, remediation, and retesting.Review assuranceSOC 2 report review checklistReview a supplier’s SOC 2 report against the service you use: scope, period, auditor opinion, exceptions, customer responsibilities, and follow-up decisions.Verify certificationISO 27001 certificate verification checklistCheck an ISO 27001 certificate’s issuing entity, scope, edition, dates, and current status against the service you intend to use.Onboard a supplierVendor security onboarding checklistConnect supplier security review to onboarding: service scope, access, evidence, accountable decisions, contract handoff, and continuing review.
Editable buying templates
Set the scope first
Start with the customer's request and the service or system it covers. Then choose software and providers for that work. These resources help you connect the steps: