Compliance Documentation Packs
Auditor-ready templates for ISO 27001, PCI DSS, SOC 1, combo packs, and the GRC Bundle. Two tiers. Two languages. Instant download.
Single frameworks & the GRC Bundle
Pick a single framework or the complete GRC Bundle. Starter for essentials, Pro for the full auditor-ready set.
ISO 27001:2022
Most popularInformation security management system — SoA, risk assessment, 93 Annex A controls, audit program, policies, evidence index.
- SoA template (Annex A mapping)
- Risk assessment worksheet
- Internal audit checklist
- 8 core policy templates
- Evidence folder structure
- Everything in Starter, plus:
- Full ISMS document set (25+ docs)
- DPIA templates (GDPR overlap)
- Management review agenda + minutes
- Internal audit program + reports
- Supplier assessment templates
- Incident response playbooks
- Auditor-ready evidence index
PCI DSS v4.0
Payment card data security — SAQ mapping, scope reduction, compensating controls, 6.4.3/11.6.1, QSA handoff package.
- SAQ mapping guide (which SAQ?)
- Scope reduction worksheet
- Network diagram template
- ASV scan remediation tracker
- Evidence folder structure
- Everything in Starter, plus:
- Full ROC/SAQ document set
- Compensating control worksheets
- Penetration test scope & rules
- Service provider management (DPAs)
- 6.4.3 / 11.6.1 change-detection docs
- Quarterly/annual task calendar
- QSA handoff package
SOC 1 (Type II)
Financial reporting controls — control matrix, PBC lists, bridge letters, exception trackers, auditor communication templates.
- Control matrix template
- Risk assessment for financial reporting
- Control design worksheet
- Evidence request list (PBC)
- Evidence folder structure
- Everything in Starter, plus:
- Full control narratives (design + operating)
- Subservice org management
- Bridge letter templates
- Exception/deficiency tracker
- Management assertion letter
- Auditor communication templates
- Continuous monitoring dashboards
GRC Bundle
Best valueAll three frameworks — ISO 27001 + PCI DSS + SOC 1 in a single evidence folder. For teams managing multiple audits at once.
- Unified control framework
- Crosswalk matrix (ISO ↔ PCI ↔ SOC)
- Single evidence folder structure
- Policy hierarchy map
- Risk register starter
- Everything in Starter, plus:
- GRC platform config (Drata/Vanta/OneTrust)
- Automated evidence collection scripts
- Continuous control monitoring rules
- Board reporting dashboards
- Multi-framework audit calendar
- Regulatory change tracking
- Vendor risk automation
Combo packs — save when you bundle two
Pick any two frameworks and save $9 on Starter or $69 on Pro vs buying individually.
ISO 27001 + PCI DSS
Information security management + payment card security — for teams handling both data protection and payment processing.
- ISO 27001 Starter essentials
- PCI DSS Starter essentials
- Shared control crosswalk (ISO ↔ PCI)
- Combined evidence folder structure
- Save $9 vs buying individually
- Everything in Starter, plus:
- Full ISMS document set (25+ docs)
- Full PCI DSS document set (ROC/SAQ)
- DPIA templates (GDPR overlap)
- Compensating control worksheets
- QSA handoff package
- Incident response playbooks
- Save $69 vs buying individually
PCI DSS + SOC 1
Payment card security + financial reporting controls — for payment processors and fintechs subject to both audits.
- PCI DSS Starter essentials
- SOC 1 Starter essentials
- Shared control crosswalk (PCI ↔ SOC)
- Combined evidence folder structure
- Save $9 vs buying individually
- Everything in Starter, plus:
- Full PCI DSS document set (ROC/SAQ)
- Full SOC 1 control narratives
- Compensating control worksheets
- Bridge letter templates
- QSA handoff package
- Exception/deficiency tracker
- Save $69 vs buying individually
SOC 1 + ISO 27001
Financial reporting controls + information security management — for service organizations needing both certifications.
- SOC 1 Starter essentials
- ISO 27001 Starter essentials
- Shared control crosswalk (SOC ↔ ISO)
- Combined evidence folder structure
- Save $9 vs buying individually
- Everything in Starter, plus:
- Full SOC 1 control narratives
- Full ISMS document set (25+ docs)
- Management review agenda + minutes
- Bridge letter templates
- Incident response playbooks
- Auditor-ready evidence index
- Save $69 vs buying individually
How it works
Choose your framework
ISO 27001, PCI DSS, SOC 1, or the GRC Bundle — pick what matches your audit scope.
Pick a tier
Starter for core templates if you’re DIY. Pro for the full auditor-ready document set.
Select your language
Each pack is sold in English or French separately — choose your language at checkout.
Download and implement
Get instant access to all files. Fill in the blanks, organize your evidence folder, and you’re audit-ready.
What’s inside every pack
Editable templates in .docx — compatible with Microsoft Word, Google Docs, and LibreOffice
Pre-mapped evidence folder structure — matches what auditors ask for
Available in English or French — choose your language at checkout
Stress-tested against real auditor requests — not theoretical, not generic
Instant download — no waiting, no consulting engagement required
Free updates when the standard changes — PCI DSS v4.0.1, ISO amendments, etc.
Ready to get compliant?
Browse all products — 4 frameworks, 3 combos, 1 bundle. 2 tiers. 2 languages.
Buy GRC Bundle Pro — $449 →Questions? Get in touch