<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Keel: GRC &amp; audit-readiness blog</title>
    <link>https://keelgrc.com/blog/</link>
    <description>Practical guides to SOC 2, ISO 27001, and getting audit-ready, from the team at Keel.</description>
    <language>en-us</language>
    <atom:link href="https://keelgrc.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Collect once, comply everywhere: the framework crosswalk explained</title>
      <link>https://keelgrc.com/blog/one-control-library-framework-crosswalk/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/one-control-library-framework-crosswalk/</guid>
      <description>Most compliance frameworks ask for the same controls in different words. A crosswalk maps one control library to every framework at once, so a second audit isn't a second project. Here's how it works.</description>
      <category>Guides</category>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Leaving your GRC tool? Take your evidence files, not just links</title>
      <link>https://keelgrc.com/blog/migrate-grc-tool-keep-your-files/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/migrate-grc-tool-keep-your-files/</guid>
      <description>Most GRC exports hand you a spreadsheet of records and a pile of links that break the day you cancel. Real portability means leaving with the actual files. Here is how keel-migrate does it, and why we built the exit in the open.</description>
      <category>Guides</category>
      <pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>AI governance you can start today, for free</title>
      <link>https://keelgrc.com/blog/ai-governance-framework-free/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/ai-governance-framework-free/</guid>
      <description>You do not need a six-figure program to govern AI responsibly. Start with a free baseline, then grow into ISO 42001, the NIST AI RMF, or the EU AI Act, on one control library.</description>
      <category>Frameworks</category>
      <pubDate>Tue, 21 Jul 2026 18:41:57 GMT</pubDate>
    </item>
    <item>
      <title>How to keep customers informed during a security incident (without a public status page)</title>
      <link>https://keelgrc.com/blog/incident-status-page-for-customers/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/incident-status-page-for-customers/</guid>
      <description>A public status page tells the whole internet your business is having a bad day. But affected customers still need the truth, fast. Here is a better model: a private, per-recipient status page that only the people you notify can open.</description>
      <category>Guides</category>
      <pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GRC for developers: an open API, an MCP server, and no lock-in</title>
      <link>https://keelgrc.com/blog/grc-for-developers/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/grc-for-developers/</guid>
      <description>Most compliance platforms treat your data as theirs. Keel ships a REST API, outbound webhooks, and a Model Context Protocol server, plus an open-source importer, so your GRC program is programmable and portable. Here is what that unlocks.</description>
      <category>Guides</category>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Crosswalk-native GRC: collect evidence once, comply everywhere</title>
      <link>https://keelgrc.com/blog/crosswalk-native-grc/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/crosswalk-native-grc/</guid>
      <description>Most compliance tools bolt cross-framework mapping on as a feature. When mapping is the architecture instead, adding your second framework stops being a second project. Here is what that means and why it matters.</description>
      <category>Guides</category>
      <pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to build a risk register for SOC 2 and ISO 27001</title>
      <link>https://keelgrc.com/blog/risk-register-for-soc-2-and-iso-27001/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/risk-register-for-soc-2-and-iso-27001/</guid>
      <description>A practical guide to building a risk register auditors accept: scoring likelihood and impact, choosing treatments, linking risks to controls, and keeping it current instead of letting it rot in a spreadsheet.</description>
      <category>Guides</category>
      <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The 18 CIS Controls that stop the most common attacks</title>
      <link>https://keelgrc.com/blog/cis-controls-v8-explained/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/cis-controls-v8-explained/</guid>
      <description>A plain-English guide to CIS Critical Security Controls v8.1: the 18 controls and 153 safeguards, the implementation groups, and how to adopt them without a security team.</description>
      <category>Frameworks</category>
      <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Getting Started with CIS 8.1 Controls: A Practical Guide</title>
      <link>https://keelgrc.com/blog/getting-started-with-cis-8-1-controls-a-practical-guide/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/getting-started-with-cis-8-1-controls-a-practical-guide/</guid>
      <description>Learn how to implement CIS Controls 8.1 for your business. We break down what you need to know, why it matters, and how to get compliant faster.</description>
      <category>Frameworks</category>
      <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>10 Risks to Shore Up Before Your First ISO 27001 Audit</title>
      <link>https://keelgrc.com/blog/10-risks-to-shore-up-before-your-first-iso-27001-audit/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/10-risks-to-shore-up-before-your-first-iso-27001-audit/</guid>
      <description>Before your ISO 27001 audit, address these 10 critical risks. A practical checklist to pass your first audit and strengthen your security posture.</description>
      <category>Audit prep</category>
      <pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What does a SOC 2 audit cost in 2026? Pricing and ROI</title>
      <link>https://keelgrc.com/blog/soc-2-audit-cost/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/soc-2-audit-cost/</guid>
      <description>A clear breakdown of SOC 2 costs, auditor fees, tooling, and internal time, plus how to think about the return when a report unblocks enterprise revenue.</description>
      <category>Costs &amp; ROI</category>
      <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to find and evaluate a SOC 2 auditor</title>
      <link>https://keelgrc.com/blog/how-to-choose-a-soc-2-auditor/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/how-to-choose-a-soc-2-auditor/</guid>
      <description>Where to find reputable CPA firms, the questions that separate good auditors from bad ones, and the red flags to avoid on your first engagement.</description>
      <category>Auditors</category>
      <pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to prepare for your first SOC 2 audit: a 12-week plan</title>
      <link>https://keelgrc.com/blog/soc-2-audit-prep-checklist/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/soc-2-audit-prep-checklist/</guid>
      <description>A week-by-week plan to go from zero to fieldwork-ready, scoping, remediation, policies, evidence, and picking an auditor, without a dedicated GRC team.</description>
      <category>Audit prep</category>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ISO 27001 vs SOC 2: which should you pursue first?</title>
      <link>https://keelgrc.com/blog/iso-27001-vs-soc-2/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/iso-27001-vs-soc-2/</guid>
      <description>A practical comparison of the two most-requested security frameworks, how they differ, which buyers expect which, and how to avoid doing the work twice.</description>
      <category>Frameworks</category>
      <pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SOC 2 for startups: the complete guide</title>
      <link>https://keelgrc.com/blog/soc-2-guide-for-startups/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/soc-2-guide-for-startups/</guid>
      <description>What SOC 2 actually is, the difference between Type I and Type II, how the five Trust Services Criteria work, and a realistic timeline to your first report.</description>
      <category>Frameworks</category>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ISO 27001 certification: a step-by-step roadmap</title>
      <link>https://keelgrc.com/blog/iso-27001-roadmap/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/iso-27001-roadmap/</guid>
      <description>The path to ISO 27001 certification explained in plain language, the ISMS, risk assessment, Statement of Applicability, internal audit, and the two-stage certification audit.</description>
      <category>Frameworks</category>
      <pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The SOC 2 evidence checklist auditors actually want</title>
      <link>https://keelgrc.com/blog/soc-2-evidence-checklist/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/soc-2-evidence-checklist/</guid>
      <description>The concrete artifacts a SOC 2 auditor asks for, organized by control area, so you collect the right evidence continuously instead of scrambling before fieldwork.</description>
      <category>Audit prep</category>
      <pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>User access reviews: what they are and what auditors look for</title>
      <link>https://keelgrc.com/blog/access-reviews-explained/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/access-reviews-explained/</guid>
      <description>Why periodic access reviews are one of the most-tested controls in SOC 2 and ISO 27001, how to run one, how often, and how to turn it into clean evidence.</description>
      <category>Guides</category>
      <pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How a trust center helps you close enterprise deals</title>
      <link>https://keelgrc.com/blog/trust-center-enterprise-deals/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/trust-center-enterprise-deals/</guid>
      <description>A public trust center answers security questions before they're asked, shortens procurement, and signals maturity. Here's what to put on one and how it speeds deals.</description>
      <category>Guides</category>
      <pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Vendor risk management for SMBs, without the spreadsheet</title>
      <link>https://keelgrc.com/blog/vendor-risk-management-smb/</link>
      <guid isPermaLink="true">https://keelgrc.com/blog/vendor-risk-management-smb/</guid>
      <description>Third-party risk is a required control in every major framework. Here's a lightweight way to inventory vendors, tier them by risk, and keep reviews from slipping.</description>
      <category>Guides</category>
      <pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
