Readiness / framework router

Compliance Readiness Checklist

Work out whether ISO 27001, SOC 2, PCI DSS, or ISO 42001 should come first, then turn the answer into policies, evidence, software shortlists, and audit-ready next steps.

Compliance evidence room showing policy, owner, evidence and review mapped across ISO 27001, SOC 2, PCI DSS and ISO 42001.
Readiness evidence / 10 KB WebP
Framework router

Start with the reason a customer or assessor cares.

Compare frameworks
SOC 2

US SaaS buyers ask for a security report.

Define system boundaries, Trust Services Criteria, and evidence owners.

Open templates
ISO 27001

Enterprise, government, or international customers ask for certification.

Define ISMS scope, risk method, Statement of Applicability, and policy set.

Open templates
PCI DSS

You process, store, or transmit payment card data.

Map cardholder data flows, reduce scope, and document the CDE boundary.

Open templates
ISO 42001

You build, provide, buy, or govern AI systems.

Create an AI system inventory, impact assessment, and approved-use policy.

Open templates
30-minute workshop

Turn the first meeting into a concrete compliance path.

Control-to-policy map ->
Audit preparation

The practical readiness list

Use the checkboxes in a working session. They do not submit anywhere. The links open the relevant policies, controls, software guides, or template pack.

Scope and accountability

Risk and control map

Policies and procedures

Evidence operations

Audit readiness

1

Pick one proof path

Choose the framework your buyer, payment obligation, or AI risk profile actually requires first.

2

Build the minimum evidence set

Use the 45 templates to create scope, risk, policies, supplier records, access evidence, and incident records.

3

Automate when manual chasing breaks

Use compliance software when integrations, evidence owners, and recurring tests become the bottleneck.

Markdown pack

Take the full template set with you.

Open one plain Markdown file with all policy, scope, risk, PCI and evidence templates. It is crawler-friendly, copy-friendly and fast.

Software shortlist

Need evidence automation?

Compare Vanta, Drata, Secureframe, Sprinto, and Thoropass by framework support, integrations, audit workflow, and fit.

Compare software

Common questions

Should a startup do SOC 2 or ISO 27001 first?

Follow buyer demand. US SaaS customers usually ask for SOC 2 first. International, enterprise, government, and Australian buyers often recognise ISO 27001 more readily. If you sell globally, many teams eventually map both.

Does PCI DSS replace SOC 2 or ISO 27001?

No. PCI DSS applies when you process, store, or transmit payment card data. SOC 2 and ISO 27001 are broader security assurance frameworks. A card-data business may need PCI DSS plus SOC 2 or ISO 27001.

What documents should I create first?

Start with scope, risk register, Statement of Applicability if ISO 27001 applies, access control policy, incident response policy, supplier security policy, data handling policy, backup policy, encryption policy, and AI use policy if AI tools are in scope.