Skip to content
compliancebase

Guides

Guides sit between the framework overview pages and the individual control reference — they answer the sequencing and decision questions that a single control page cannot: which Trust Services Categories to scope in, how to sequence SOC 2 and ISO 27001 if you need both, what changes when you are a healthcare vendor versus a general SaaS company, and what a Series A company's compliance program actually looks like versus a seed-stage one.

General guides below cover cross-cutting implementation questions that apply regardless of your industry or stage. Industry guides adjust for sector-specific requirements — a healthcare SaaS vendor has HIPAA obligations a fintech company does not, and vice versa with payment card data. Stage guides scope the same frameworks differently for a two-person seed-stage team versus a Series A company with a dedicated security hire.

Read a guide when you need to make a decision (which framework, which scope, which order) rather than look up a specific requirement. For the requirement itself, use the control reference once you know which controls apply to you.

Industry guides

Stage guides