Checklists

The checklists.

Full lists. No email wall.

GDPR Compliance Checklist

A GDPR checklist built for B2B SaaS — lawful bases, DPAs, sub-processors, data-subject rights, transfers, and breach clocks. Full list on-page.

ISO 27001 Checklist

A step-by-step ISO 27001 checklist — ISMS scoping, risk assessment, Annex A controls, internal audit, and the certification audit itself. Full list on-page.

Access Review Checklist

A step-by-step access review checklist — scope, pull, decide, revoke, record — that produces the artifact SOC 2 and ISO auditors sample first.

HIPAA Compliance Checklist

A HIPAA checklist for startups handling PHI — risk analysis, safeguards, BAAs, training, and breach readiness. Written for health-tech, not hospitals.

MAS TRM Checklist

A practical MAS TRM Guidelines checklist for fintechs — governance, resilience, cyber hygiene, vendor oversight, and incident reporting to MAS.

Pen Test Readiness Checklist

Prepare for a penetration test properly — scoping, environment prep, rules of engagement, and what to do with findings so the report satisfies auditors and buyers.

Security Audit Checklist

A framework-agnostic security audit checklist — governance, access, infrastructure, operations, and vendors — for any external audit or enterprise review.

PCI DSS Checklist

A PCI DSS v4 checklist that starts where the money is — scope reduction — then walks the 12 requirements, SAQ selection, and evidence. Full list on-page.

SOC 2 Compliance Checklist

A practical SOC 2 checklist covering scoping, controls, policies, evidence, and audit prep — the full list on-page, written by people who run these programs.

Vendor Due Diligence Checklist

A vendor security due diligence checklist — risk tiering, document requests, red flags, and contract clauses — used in real reviews, published in full.