Straight answers to common GRC questions
The questions teams actually ask when they start a compliance program, answered directly and then in depth, so you can act instead of guess.
SOC 2
How do I prepare for SOC 2?
Prepare for SOC 2 by choosing your report type and Trust Services Criteria, scoping your system, implementing the core controls (a…
What evidence is required for SOC 2?
SOC 2 evidence is the proof that your controls operate: security policies, access-control and access-review records, change-manage…
What is the difference between SOC 2 Type I and Type II?
A SOC 2 Type I report evaluates whether your controls are suitably designed at a single point in time. A Type II goes further and …
Do I need SOC 2 or ISO 27001?
Both demonstrate strong information security, but they differ in form and audience. SOC 2 is a US attestation report (from a CPA f…
What is the difference between SOC 1 and SOC 2?
SOC 1 and SOC 2 are both AICPA attestation reports, but they cover different things. SOC 1 covers controls at a service organizati…
What is a SOC 2 bridge letter?
A bridge letter (or gap letter) is a short letter from a service organization that covers the gap between the end of its SOC 2 rep…
What is a SOC 2 readiness assessment?
A SOC 2 readiness assessment is a gap analysis you do before the formal audit: you compare your current controls and evidence agai…
How do I read a SOC 2 report?
A SOC 2 report has a few key parts: the independent auditor’s opinion, management’s assertion, the system description, and the tes…
How do I choose a SOC 2 auditor?
A SOC 2 audit must be performed by a licensed CPA firm, so start by confirming the firm is a licensed CPA. Then weigh experience w…
What does a SOC 2 audit cost?
Published vendor estimates put a SOC 2 Type I audit roughly in the $5,000 to $20,000 range and a Type II from about $7,000 into si…
Is SOC 2 required by law?
No. SOC 2 is a voluntary attestation developed by the AICPA, not a law or a government mandate. Companies pursue it because custom…
ISO 27001
How long does ISO 27001 take?
For most SMBs, ISO 27001 certification takes roughly 3 to 9 months from a standing start: a few weeks to months to build the ISMS,…
What policies are required for ISO 27001?
ISO 27001 requires a top-level information security policy, plus supporting policies driven by your risk assessment and Statement …
PCI DSS
What are the PCI DSS requirements?
PCI DSS 4.0.1 has 12 requirements grouped under 6 goals, and they apply to any organization that stores, processes, or transmits p…
Does my SaaS need to be PCI DSS compliant?
If your SaaS stores, processes, or transmits cardholder data — or can affect the security of the systems that do — PCI DSS applies…
HIPAA & privacy
What is a business associate agreement (BAA)?
A business associate agreement (BAA) is a contract required by HIPAA between a covered entity (or a business associate) and a vend…
Does my startup need to be HIPAA compliant?
You need to comply with HIPAA if you are a covered entity (a health plan, healthcare clearinghouse, or a healthcare provider that …
What is a data processing agreement (DPA)?
A data processing agreement (DPA) is a contract, required under GDPR Article 28, between a data controller and a data processor th…
Do I need to comply with GDPR if I am a US company?
Possibly yes. GDPR applies to organizations outside the EU/EEA when they offer goods or services to, or monitor the behavior of, p…
AI governance
Do I need ISO 42001?
ISO 42001 is voluntary, so no law requires it. You are a candidate for it if you build or deploy AI and your buyers, partners, or …
ISO 42001 vs the NIST AI RMF: what is the difference?
ISO/IEC 42001 is a certifiable management-system standard for AI (an AIMS), while the NIST AI Risk Management Framework is a volun…
How do I prepare for the EU AI Act?
Prepare for the EU AI Act by inventorying the AI systems you build or use, classifying each by the Act’s risk tiers, and then meet…
Buying GRC
How much does compliance software cost?
Compliance (GRC) software ranges widely: legacy enterprise platforms often run tens of thousands of dollars a year, while modern S…
What is the best compliance software for a small business?
The best compliance software for a small business is one that is affordable, fast to implement, covers the frameworks you need on …
What is the best GRC software for MSPs?
The best GRC software for an MSP manages many client workspaces from one console, supports white-labeling, prices per client rathe…
How do I migrate from Vanta or Drata to Keel?
You can move your program to Keel with keel-migrate, our open-source tool: export your vendors, risks, people, policies, and the a…
Risk & policies
How do I build a risk register?
Build a risk register by identifying risks from real sources, describing each clearly, scoring inherent likelihood and impact on a…
How often do I need a penetration test?
There is no single universal rule, but the widely accepted practice is at least once a year and after any significant change to yo…
How do I do a vendor security assessment?
A vendor security assessment checks whether a third party protects the data you would share with it. Tier the vendor by the data a…
How do I answer a security questionnaire?
Answer a security questionnaire from a maintained library of reviewed answers tied to your real controls and evidence, map incomin…
What is a penetration test report?
A penetration test report is the deliverable from a pen test: it documents the scope and methodology, lists the vulnerabilities fo…