Getting Started Guide

The Complete Compliance Checklist

A step-by-step guide to achieving SOC 2, ISO 27001, HIPAA, and GDPR compliance. Whether you are a startup closing your first enterprise deal or a growing company scaling your security program, this checklist covers everything you need to get audit-ready.

4-8Weeks to audit-ready
5Phases in the process
40+Checklist items
$0To start with Evidr

01The five phases

Assessment to audit, in order.

Each phase has the tasks that must be done before the next one starts. The critical ones are marked.

  1. PHASE 01Week 1-2

    Understand your compliance requirements

    Before diving into implementation, you need to understand what compliance frameworks apply to your business and what your current security posture looks like.

    TipUse Evidr AI onboarding to automatically profile your business across 60+ risk signals and get framework recommendations in minutes.
    • Identify which frameworks your customers require (SOC 2, ISO 27001, HIPAA, GDPR, etc.)Critical
    • Review existing security policies and procedures
    • Document your current tech stack and data flowsCritical
    • Identify sensitive data types you process (PII, PHI, payment data)Critical
    • Assess current access controls and authentication methods
    • Review vendor relationships and data sharing agreements
    • Identify compliance gaps between current state and target frameworksCritical
  2. PHASE 02Week 2-3

    Create your compliance roadmap

    With a clear understanding of your requirements and gaps, create a realistic plan that assigns ownership and sets deadlines.

    TipEvidr auto-generates control checklists mapped to your selected frameworks. Skip the spreadsheet and let AI identify exactly what evidence you need.
    • Select primary framework(s) to pursue firstCritical
    • Map controls to your specific business contextCritical
    • Assign control owners across your organizationCritical
    • Create timeline with milestones and deadlines
    • Budget for tools, auditors, and potential consultants
    • Identify evidence requirements for each controlCritical
    • Plan employee security awareness training
    • Select auditor and schedule audit windowCritical
  3. PHASE 03Week 3-6

    Build your compliance program

    The bulk of compliance work happens here. Implement controls, create policies, and collect evidence to demonstrate compliance.

    TipEvidr policy generation creates board-ready documents in seconds. AI understands your business context and generates policies tailored to your specific needs.
    • Implement technical controls (encryption, access controls, logging)Critical
    • Draft and approve security policies (Acceptable Use, Data Classification, etc.)Critical
    • Set up vulnerability scanning and penetration testingCritical
    • Implement endpoint security (MDM, antivirus, disk encryption)
    • Configure cloud security settings (AWS, GCP, Azure)Critical
    • Set up security monitoring and alertingCritical
    • Conduct background checks on employees
    • Train employees on security policies and proceduresCritical
    • Implement vendor risk management process
    • Set up business continuity and disaster recovery plans
  4. PHASE 04Week 6-8

    Prepare for your audit

    Collect and organize evidence, conduct internal reviews, and prepare for the external audit.

    TipEvidr AI reviews your evidence with confidence scoring and flags issues automatically. Share a read-only auditor portal instead of email chains.
    • Collect evidence for all controls (screenshots, configs, logs)Critical
    • Organize evidence by control and framework requirementCritical
    • Conduct internal control testing and gap remediationCritical
    • Review all policies for accuracy and completeness
    • Prepare auditor access portal with organized evidenceCritical
    • Brief team on audit process and interview expectations
    • Conduct mock audit or readiness assessment
    • Address any findings from readiness assessmentCritical
  5. PHASE 05Ongoing

    Maintain your certification

    Compliance is not a one-time event. Maintain your certification with continuous monitoring and regular evidence refresh.

    TipEvidr continuous monitoring tracks evidence expiry and sends alerts before things go stale. Never scramble before an audit again.
    • Set up automated evidence collection from integrationsCritical
    • Monitor evidence expiry and refresh before auditsCritical
    • Conduct quarterly access reviewsCritical
    • Review and update policies annually
    • Perform annual security awareness trainingCritical
    • Monitor vendors for security incidents and breaches
    • Track and remediate security incidentsCritical
    • Prepare for annual audit recertificationCritical

02Common mistakes

Where programmes go wrong.

  • Starting too late

    Enterprise deals often require SOC 2 as a procurement checkbox. Starting compliance after the deal is already in progress means you lose momentum and potentially the deal.

    InsteadStart compliance early, even before you need it. A free Evidr account lets you track readiness without committing to a full audit.

  • Treating compliance as a checkbox

    Compliance should improve your actual security posture, not just generate paperwork. Checkbox compliance leads to findings during audits and false confidence.

    InsteadUse compliance as a framework for building a real security program. The controls exist because they actually reduce risk.

  • No single owner

    When compliance is everyone responsibility, it becomes no one responsibility. Tasks fall through cracks and deadlines slip.

    InsteadAssign a compliance lead with authority to hold others accountable. Use Evidr to assign control owners and track progress.

  • Manual evidence collection

    Collecting screenshots and exporting configs manually is slow, error-prone, and does not scale. It also makes continuous compliance nearly impossible.

    InsteadAutomate evidence collection with integrations. Evidr connects to AWS, GitHub, Okta, and 18 more tools to pull evidence automatically.

  • Ignoring vendor risk

    Your compliance posture is only as strong as your weakest vendor. A breach at a critical vendor can invalidate your own compliance.

    InsteadMonitor vendors continuously. Evidr tracks 230+ vendors for breaches, CVEs, and regulatory actions with real-time alerts.

  • Forgetting about continuous compliance

    Getting certified is just the beginning. Evidence expires, employees change, and controls drift. Many companies fail recertification.

    InsteadBuild continuous compliance from day one. Evidr monitors evidence expiry and compliance drift so you are always audit-ready.

03Framework reference

Which framework, and how long.

FrameworkFocusTypical forTimelineControls
SOC 2 Security, availability, processing integrity, confidentiality, privacyB2B SaaS, cloud services4-6 weeks (Type I), 6-12 months (Type II observation)117 controls
ISO 27001 Information security management system (ISMS)International customers, enterprise deals6-12 months for initial certification93 controls
HIPAA Protected health information (PHI)Healthcare, health tech, insurance3-6 months for compliance program89 controls
GDPR EU personal data protection and privacy rightsAny company processing EU resident data3-6 months for compliance program72 controls

Work the checklist inside Evidr.

Every task above has a place in the platform: the onboarding builds the assessment, the frameworks bring the controls, the integrations bring the evidence.