Compliance Readiness Checklist
Work out whether ISO 27001, SOC 2, PCI DSS, or ISO 42001 should come first, then turn the answer into policies, evidence, software shortlists, and audit-ready next steps.

Start with the reason a customer or assessor cares.
US SaaS buyers ask for a security report.
Define system boundaries, Trust Services Criteria, and evidence owners.
Open templatesEnterprise, government, or international customers ask for certification.
Define ISMS scope, risk method, Statement of Applicability, and policy set.
Open templatesYou process, store, or transmit payment card data.
Map cardholder data flows, reduce scope, and document the CDE boundary.
Open templatesYou build, provide, buy, or govern AI systems.
Create an AI system inventory, impact assessment, and approved-use policy.
Open templatesTurn the first meeting into a concrete compliance path.
The practical readiness list
Use the checkboxes in a working session. They do not submit anywhere. The links open the relevant policies, controls, software guides, or template pack.
Scope and accountability
Risk and control map
Policies and procedures
Evidence operations
Audit readiness
Pick one proof path
Choose the framework your buyer, payment obligation, or AI risk profile actually requires first.
Build the minimum evidence set
Use the 45 templates to create scope, risk, policies, supplier records, access evidence, and incident records.
Automate when manual chasing breaks
Use compliance software when integrations, evidence owners, and recurring tests become the bottleneck.
Take the full template set with you.
Open one plain Markdown file with all policy, scope, risk, PCI and evidence templates. It is crawler-friendly, copy-friendly and fast.
Need evidence automation?
Compare Vanta, Drata, Secureframe, Sprinto, and Thoropass by framework support, integrations, audit workflow, and fit.
Common questions
Should a startup do SOC 2 or ISO 27001 first?
Follow buyer demand. US SaaS customers usually ask for SOC 2 first. International, enterprise, government, and Australian buyers often recognise ISO 27001 more readily. If you sell globally, many teams eventually map both.
Does PCI DSS replace SOC 2 or ISO 27001?
No. PCI DSS applies when you process, store, or transmit payment card data. SOC 2 and ISO 27001 are broader security assurance frameworks. A card-data business may need PCI DSS plus SOC 2 or ISO 27001.
What documents should I create first?
Start with scope, risk register, Statement of Applicability if ISO 27001 applies, access control policy, incident response policy, supplier security policy, data handling policy, backup policy, encryption policy, and AI use policy if AI tools are in scope.