Security compliance, without the spin.
Independent security compliance reference
Control-level detail for SOC 2, ISO 27001, GDPR, and HIPAA — written for engineers and compliance leads, not as a sales funnel.
Frameworks
Start with the framework your prospect or regulator asked for. Each overview links into control-level reference.
- SOC 2SOC 2
AICPA attestation against the Trust Services Criteria — the default ask for US B2B SaaS procurement. A CPA firm examines how you design and operate controls for Security and any optional categories you select, then issues a restricted-use report that buyers request under NDA during vendor security review.
2017 TSC (2022 Revised Points of Focus)
- ISO 27001ISO/IEC 27001
International ISMS certification under ISO/IEC 27001:2022 with 93 Annex A reference controls — widely recognized in EU, UK, and APAC procurement. An accredited certification body audits your management system through Stage 1 and Stage 2, then maintains oversight through surveillance on a multi-year cycle. SaaS teams typically reuse IAM, logging, change, and vendor controls from adjacent programs while adding risk methodology, Statement of Applicability discipline, internal audit, and management review as the distinctive ISMS lift.
ISO/IEC 27001:2022
- GDPRGDPR
Regulation (EU) 2016/679 — the General Data Protection Regulation — is the primary EU law governing processing of personal data. It defines roles (controller and processor), lawful bases, data-subject rights, breach notification, and Article 32 security-of-processing duties. Territorial scope can reach non-EU SaaS companies that offer services to people in the EEA or monitor their behavior. This hub orients product, security, and legal stakeholders; it is educational, not legal advice.
Regulation (EU) 2016/679
- HIPAAHIPAA
HIPAA's Privacy, Security, and Breach Notification Rules at 45 CFR Part 164 govern protected health information (PHI) for covered entities and their business associates. The Security Rule's administrative, physical, and technical safeguards — including Required and Addressable implementation specifications — shape how health-tech SaaS protects electronic PHI (ePHI). A Business Associate Agreement (BAA) is contractual infrastructure, not a substitute for safeguards. This hub is educational orientation for product and security teams, not legal advice.
45 CFR Part 164
Where to start
Pick the path that matches the question you already have.
- Control reference
What auditors expect, control by control.
- Tools & calculators
Framework selector, cost and timeline estimators.
- Cost ranges
Auditor and tooling ranges — not vendor pitch decks.
- Comparisons
SOC 2 vs ISO, Type I vs II, GDPR vs CCPA.
- Templates
Policy starters you can download and adapt.
- Glossary
Definitions without consultant fog.
Flagship controls
High-traffic reference pages — evidence, gaps, and cross-framework maps in one place.
Tools
Interactive estimators and selectors — no lead capture, no vendor ranking.
- Framework selector
Interactive tool to help you choose between SOC 2, ISO 27001, GDPR, and HIPAA based on buyers, geography, and data types.
- SOC 2 cost calculator
Heuristic estimate of SOC 2 program cost bands — auditor fees, optional automation, and internal effort — based on type, scope, and company size.
- SOC 2 timeline calculator
Work backwards from a target report or deal date to plan gap assessment, observation window, fieldwork, and report delivery for SOC 2.
- Framework readiness self-assessment
Interactive tool that scores your current posture against a chosen framework and highlights likely evidence gaps before an audit.
No product to sell
ComplianceBase is an independent reference. No demos, no email gates on content, no consulting funnel. If a claim cites a control, article, or CFR section, you should be able to verify it against the primary source.
From the blog
Practical notes on frameworks, evidence, and cost — same voice as the reference pages.
- What an Auditor Actually Does During a SOC 2 Type II Review
Demystifying Type II fieldwork — samples, walkthroughs, exceptions, and why “we have a policy PDF” is not enough.
- The $80K SOC 2 Surprise: What Founders Don't Budget For
Auditor invoices are only part of the story. Here is how startups accidentally turn a $25K fee quote into an $80K year.
- ISO 27001:2013 Certifications Are Dead — What the 2022 Transition Means for Your ISMS
The 2022 edition restructured Annex A into four themes. Here is what SaaS teams should update in scope, SoA, and buyer language.