Skip to content

Structured Audit & Compliance Checklists for Modern Teams

Free operational checklists and field notes for ISO standards, cybersecurity frameworks, and privacy regulations.

Index

Filter by framework family or search by standard, audience, or topic.

02

Trust Services · Cybersecurity & Cloud

SOC 2 Type II Audit Readiness Checklist

An operational checklist for scoping Trust Services Criteria, designing controls, collecting evidence over the observation window, and preparing for a Type II examination.

SaaS, Cloud, and B2B Technology Companies

Field note →

Open
03

Privacy Regulation · Data Privacy & Law

GDPR Compliance Checklist for Web Applications

A practical checklist for mapping personal data in web applications, establishing lawful bases, honoring data-subject rights, and preparing internal GDPR readiness reviews.

Product, Engineering, and Legal Teams Building Web Apps

Field note →

Open
04

Healthcare Privacy · Data Privacy & Law

HIPAA Security Rule Checklist for HealthTech

A Security Rule–oriented checklist to help HealthTech teams safeguard ePHI, complete a risk analysis, implement required and addressable safeguards, and prepare for internal or customer audits.

HealthTech, Digital Health, and Covered-Entity Vendors

Field note →

Open

Field notes

Separate articles for search and context. Each one points to its interactive checklist — they are not the same page.

All guides →
  1. 01

    Information Security

    ISO 27001:2022 audit readiness: what Stage 1 and Stage 2 actually test

    How to prepare an ISMS for ISO 27001:2022 certification in 2026 — scope, SoA, internal audit, and what registrars sample in Stage 2.

  2. 02

    Trust Services

    SOC 2 Type II in 2026: observation windows, evidence, and exceptions

    A practical guide to SOC 2 Type II — Trust Services Criteria, Type I vs Type II, and how to collect evidence over the observation period.

  3. 03

    Privacy Regulation

    GDPR for web applications: lawful basis, cookies, and processor chains

    How web and SaaS teams operationalize GDPR — ROPA, consent UX, subprocessors, and transfers — without treating the privacy policy as the program.

  4. 04

    Payments

    PCI DSS v4.0.1 in 2026: ROC scope, SAQ choice, and customized approach

    How payment teams prepare for PCI DSS v4.0.1 — cardholder data environment, SAQ vs ROC, and what QSAs sample after the 2025 future-dated requirements.

  5. 05

    NIST CSF

    NIST CSF 2.0: Govern, profiles, and how to use the framework without a certificate

    A 2026 guide to NIST Cybersecurity Framework 2.0 — the new Govern function, current vs target profiles, and how CSF sits next to ISO 27001 and SOC 2.

  6. 06

    EU AI Act

    EU AI Act in 2026: prohibited, GPAI, high-risk — and who is provider vs deployer

    A practical guide to EU AI Act readiness — role classification, high-risk obligations, GPAI documentation, and how it sits next to ISO 42001.

How these checklists are curated

Each guide is structured from publicly available framework clauses and control families so internal teams can run a self-assessment before a formal audit. They are operational references for audit readiness — not a substitute for accredited certification or legal counsel.

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs.