# Governance Docs | ISO and Compliance Documentation Toolkits > Governance Docs LLC (Albuquerque, New Mexico, USA) provides auditor-written, instantly editable Microsoft Word/Excel ISO and compliance documentation toolkits (most $99-$199) spanning 70+ frameworks - including ISO 27001, ISO 42001, ISO 22301, SOC 2, NIS2, GDPR, HIPAA, PCI-DSS, NIST, CMMC, FedRAMP and DORA - for organizations worldwide. Instant download; templates are editable and licensed to a single organization. Generated automatically from live site content on 2026-09-22. Full-text companion: https://governancedocs.com/llms-full.txt ## About - [About Governance Docs](https://governancedocs.com/about-governance-docs/): Who we are, how the toolkits are written, and the audit experience behind them. - [Contact](https://governancedocs.com/contact-governance-docs/): Support, pre-sales questions and custom requests. - [Frequently Asked Questions](https://governancedocs.com/faq/): Licensing, delivery, customisation and refunds, answered in full. ## Choosing a Toolkit - [Which ISO Toolkit Do I Need?](https://governancedocs.com/which-iso-toolkit-do-i-need/): Decision guide matching your situation to the right standard and toolkit. - [All Toolkits](https://governancedocs.com/shop/): Full catalogue of documentation toolkits and assessment tools. ## Free Templates Free sample templates, sent by email. No purchase required. - [Free CMMC templates](https://governancedocs.com/free-cmmc-templates/): Five complete CMMC templates, free by email — real fill-in documents from the CMMC Documentation Toolkit, not outlines. One ZIP or five PDFs. - [Free DORA templates](https://governancedocs.com/free-dora-templates/): Five complete, fill-in documents from our DORA Documentation Toolkit, free. The forms a financial entity actually files and keeps, drawn from the full 109-document pack. What is in... - [Free GDPR templates](https://governancedocs.com/free-gdpr-templates/): Five complete GDPR templates, free by email — real fill-in documents from the GDPR Documentation Toolkit, not outlines. One ZIP or five PDFs. - [Free HIPAA templates](https://governancedocs.com/free-hipaa-templates/): Five complete HIPAA templates, free by email — real fill-in documents from the HIPAA Documentation Toolkit, not outlines. One ZIP or five PDFs. - [Free IEC 62443 templates](https://governancedocs.com/free-iec-62443-templates/): Five complete, fill-in documents from our IEC 62443 Documentation Toolkit, free. Records an assessor asks for, drawn from the full 117-document pack built on the IEC 62443-2-1:2024... - [Free ISO 13485 templates](https://governancedocs.com/free-iso-13485-templates/): Five complete ISO 13485 templates, free by email — real fill-in documents from the ISO 13485:2016 Documentation Toolkit, not outlines. One ZIP or five PDFs. - [Free ISO 22301 templates](https://governancedocs.com/free-iso-22301-templates/): Five complete ISO 22301 templates, free by email — real fill-in documents from the ISO 22301 Documentation Toolkit, not outlines. One ZIP or five PDFs. - [Free ISO 27001 templates](https://governancedocs.com/free-iso-27001-templates/): Five complete ISO 27001 templates, free by email — real fill-in documents from the ISO 27001 Documentation Toolkit, not outlines. One ZIP or five PDFs. - [Free ISO 42001 templates](https://governancedocs.com/free-iso-42001-templates/): Four complete ISO 42001 templates, free by email — real fill-in documents from the ISO 42001 AI Management System Toolkit, not outlines. One ZIP or four PDFs. - [Free ISO 9001 templates](https://governancedocs.com/free-iso-9001-templates/): Five complete ISO 9001:2026 templates, free by email — real fill-in forms and records from the rebuilt ISO 9001 Documentation Toolkit, not outlines. One ZIP or five PDFs. - [Free ISO and compliance document templates](https://governancedocs.com/free-iso-templates/): Five complete, fill-in-the-blank compliance templates from any Governance Docs toolkit, free by email. ISO 27001, ISO 13485, ISO 22301, HIPAA, GDPR and CMMC. - [Free ITIL templates](https://governancedocs.com/free-itil-templates/): Five complete, fill-in documents from our ITIL Version 5 Documentation Toolkit, free. Management tools from the full 57-document pack, including the experience-based artefacts new... - [Free Project Management templates](https://governancedocs.com/free-project-management-templates/): Five complete, fill-in documents from our Project Management Toolkit, free. Working project documents from a pack of over 400 templates. What is in the free set DocumentWhat it is... ## Toolkits and Assessment Tools (86) - [Comprehensive AS 9100/9110/9120 Aerospace QMS Toolkit – 38 Templates](https://governancedocs.com/product/as-9100-toolkit/): AS 9100 Toolkit delivers 38 ready-to-use Microsoft Office templates covering quality policy, product safety, counterfeit parts prevention, design and development, configuration man... - [Comprehensive Basel III Prudential Risk Toolkit – 25 Templates](https://governancedocs.com/product/basel-iii-toolkit/): Basel III Toolkit delivers 25 ready-to-use Microsoft Office templates covering governance and risk appetite, capital management, RWA calculation, credit risk, market risk and FRTB,... - [Comprehensive BSI C5:2026 Cloud Toolkit – 107 Compliance Templates](https://governancedocs.com/product/bsi-c52026-cloud-toolkit/): BSI C5:2026 Cloud Toolkit delivers 107 ready-to-use Microsoft Office templates covering all 17 domains of the BSI Cloud Computing Compliance Criteria Catalogue — from governance an... - [Comprehensive CCPA-CPRA Compliance Toolkit – 60+ Privacy Templates](https://governancedocs.com/product/ccpa-cpra-toolkit/): CCPA-CPRA Compliance Toolkit delivers 63 ready-to-use Microsoft Office templates covering consumer rights, privacy notices, data management, vendor oversight, and breach response —... - [Comprehensive CIS Controls v8.1 Toolkit – 40 Cybersecurity Templates](https://governancedocs.com/product/cis-controls-toolkit/): CIS Controls Toolkit delivers 40 ready-to-use Microsoft Office templates covering asset inventory, software inventory, data protection, secure configuration, account management, ac... - [Comprehensive CMMC Documentation Toolkit – 107 Compliance Templates](https://governancedocs.com/product/cmmc-toolkit/): CMMC Toolkit delivers 107 ready-to-use Microsoft Office templates covering all 14 NIST SP 800-171 practice families required for CMMC Level 2 certification. From policies and proce... - [Comprehensive COBIT 2019 IT Governance Toolkit – 31 Templates](https://governancedocs.com/product/cobit-2019-toolkit/): COBIT 2019 Toolkit delivers 31 ready-to-use Microsoft Office templates covering IT governance policy, information security, risk management, change management, incident management,... - [Comprehensive COSO ERM & Internal Control Toolkit – 21 Templates](https://governancedocs.com/product/coso-toolkit/): COSO Toolkit delivers 21 ready-to-use Microsoft Office templates covering internal control policy, ICFR, control design and documentation, control evaluation and testing, deficienc... - [Comprehensive CSA STAR Cloud Security Toolkit – 30 Templates](https://governancedocs.com/product/csa-star-toolkit/): CSA STAR Toolkit delivers 30 ready-to-use Microsoft Office templates covering cloud governance, application security, business continuity, change control, cryptography, datacenter... - [Comprehensive Cyber Essentials UK Toolkit – 25 Compliance Templates](https://governancedocs.com/product/cyber-essentials-toolkit/): Cyber Essentials Toolkit delivers 25 ready-to-use Microsoft Office templates aligned to Cyber Essentials Requirements for IT Infrastructure v3.3 covering firewalls and internet gat... - [Comprehensive Data Governance Toolkit – 91 DMBOK-Aligned Templates](https://governancedocs.com/product/data-governance-toolkit/): Data Governance Toolkit delivers 91 ready-to-use Microsoft Office templates covering data governance, data architecture, data modelling and design, data storage and operations, dat... - [Comprehensive DPDP Act Toolkit – 91 Privacy Templates](https://governancedocs.com/product/dpdp-act-toolkit/): DPDP Act Compliance Toolkit delivers 91 ready-to-use Microsoft Office templates covering all key obligations under India's Digital Personal Data Protection Act, 2023 — from consent... - [Comprehensive EU AI Act Toolkit – 60 Compliance Templates](https://governancedocs.com/product/eu-ai-act-toolkit/): EU AI Act Toolkit delivers 60 ready-to-use Microsoft Office templates covering governance, risk classification, high-risk AI systems, GPAI models, conformity assessment, and audit... - [Comprehensive EU CRA Toolkit – 74 Cyber Resilience Act Templates](https://governancedocs.com/product/eu-cra-toolkit/): EU CRA Toolkit delivers 74 ready-to-use Microsoft Office templates covering Regulation (EU) 2024/2847 as consolidated on 20 November 2024 — the Article 14 reporting cascades that a... - [Comprehensive EU IVDR Toolkit – 74 In Vitro Diagnostic Regulation Templates](https://governancedocs.com/product/eu-ivdr-toolkit/): EU IVDR Toolkit delivers 74 ready-to-use Microsoft Office templates covering Regulation (EU) 2017/746 as consolidated on 10 January 2025 — Annex II and Annex III technical document... - [Comprehensive EU MDR Toolkit – 68 Medical Device Regulation Templates](https://governancedocs.com/product/eu-mdr-toolkit/): EU MDR Toolkit delivers 68 ready-to-use Microsoft Office templates covering Regulation (EU) 2017/745 as consolidated on 19 July 2026 — Annex II and Annex III technical documentatio... - [Comprehensive FSSC 22000 Toolkit – 111 Food Safety Templates](https://governancedocs.com/product/fssc-22000-toolkit/): The FSSC 22000 Toolkit delivers 111 ready-to-use Microsoft Office templates written to Version 7.0 of the Scheme, published May 2026 — 80 Word documents and 31 Excel workbooks cove... - [Comprehensive GovRAMP (StateRAMP) TX-RAMP Compliance Toolkit – 50 Templates](https://governancedocs.com/product/stateramp-toolkit/): StateRAMP Toolkit delivers 50 ready-to-use GovRAMP / TX-RAMP Microsoft Office templates covering system security planning, FIPS 199 categorization, privacy impact assessment, acces... - [Comprehensive HITRUST CSF v11 Toolkit – 45 Compliance Templates](https://governancedocs.com/product/hitrust-csf-toolkit/): HITRUST CSF Toolkit delivers 45 ready-to-use Microsoft Office templates covering information protection programme, endpoint protection, portable media, mobile device security, wire... - [Comprehensive ISO 14971 Toolkit – 44 Risk Management Templates](https://governancedocs.com/product/iso-14971-toolkit/): ISO 14971 Toolkit delivers 44 ready-to-use Microsoft Office templates covering every clause of ISO 14971:2019 — the risk management plan and file, intended use and misuse, hazard i... - [Comprehensive ISO 15189 Toolkit – 82 Medical Laboratory Templates](https://governancedocs.com/product/iso-15189-toolkit/): ISO 15189 Toolkit delivers 82 ready-to-use Microsoft Office templates covering every clause of ISO 15189:2022 — obligations to patients, the laboratory director, risk management, t... - [Comprehensive ISO 17025 Toolkit – 70 Laboratory Templates](https://governancedocs.com/product/iso-17025-toolkit/): ISO 17025 Toolkit delivers 70 ready-to-use Microsoft Office templates covering every clause of ISO/IEC 17025:2017 — impartiality, competence, equipment and metrological traceabilit... - [Comprehensive ISO 21001 Educational Management Toolkit – 43 Templates](https://governancedocs.com/product/iso-21001-toolkit/): ISO 21001 Toolkit delivers 43 ready-to-use Microsoft Office templates covering learner admissions, learner support, accessibility and SEN, learner participation, curriculum design,... - [Comprehensive ISO 27017 Toolkit & ISO 27018 Cloud Pack – 67 Templates](https://governancedocs.com/product/iso-27017-27018-toolkit/): ISO 27017 Toolkit delivers 67 ready-to-use Microsoft Office templates that extend a certified ISO 27001 ISMS into the cloud — covering the seven ISO 27017 CLD controls, shared resp... - [Comprehensive ISO 28000 Supply Chain Security Toolkit – 29 Templates](https://governancedocs.com/product/iso-28000-toolkit/): ISO 28000 Toolkit delivers 29 ready-to-use Microsoft Office templates covering supply chain security risk assessment, physical security, transport and logistics security, personnel... - [Comprehensive ISO 31000 Risk Management Toolkit – 30 Templates](https://governancedocs.com/product/iso-31000-toolkit/): ISO 31000 Toolkit delivers 30 ready-to-use Microsoft Office templates covering risk management framework, risk management policy, risk appetite, risk identification, risk analysis,... - [Comprehensive ISO 37001 Anti-Bribery Toolkit – 55 Compliance Templates](https://governancedocs.com/product/iso-37001-toolkit/): ISO 37001 Toolkit delivers 55 ready-to-use Microsoft Office templates covering anti-bribery policy, governing body commitment, anti-bribery function charter, bribery risk assessmen... - [Comprehensive ISO 37301 Compliance Management Toolkit – 24 Templates](https://governancedocs.com/product/iso-37301-toolkit/): ISO 37301 Toolkit delivers 24 ready-to-use Microsoft Office templates covering compliance policy, code of conduct, anti-bribery, data protection, competition law, sanctions, AML, c... - [Comprehensive ISO 39001 Road Traffic Safety Toolkit – 10 Templates](https://governancedocs.com/product/iso-39001-toolkit/): ISO 39001 Toolkit delivers 10 ready-to-use Microsoft Office templates covering driver management, vehicle management, journey management, incident and near-miss reporting, emergenc... - [Comprehensive ISO 41001 Facility Management Toolkit – 17 Templates](https://governancedocs.com/product/iso-41001-toolkit/): ISO 41001 Toolkit delivers 17 ready-to-use Microsoft Office templates covering hard FM operations, soft FM operations, asset and space management, HSE in FM, supplier and contracto... - [Comprehensive ISO 50001 Energy Management Toolkit – 53 Templates](https://governancedocs.com/product/iso-50001-toolkit/): ISO 50001 Toolkit delivers 53 ready-to-use Microsoft Office templates covering energy policy, energy review, significant energy uses (SEUs), energy performance indicators (EnPIs),... - [Comprehensive ISO 55001 Asset Management Toolkit – 44 Templates](https://governancedocs.com/product/iso-55001-toolkit/): ISO 55001 Toolkit delivers 42 ready-to-use Microsoft Office templates covering asset lifecycle management, risk-based decision-making, condition assessment, whole-life costing, per... - [Comprehensive ITIL 5 Toolkit – 57 Templates (ITIL Version 5)](https://governancedocs.com/product/itil-toolkit/): ITIL 5 Toolkit delivers 57 ready-to-use Microsoft Office templates aligned to ITIL (Version 5): the ITIL Value System, the eight-activity product and service lifecycle (discover, d... - [Comprehensive NIST AI RMF Toolkit – 36 AI Governance Templates](https://governancedocs.com/product/nist-ai-rmf-toolkit/): NIST AI RMF Toolkit delivers 36 ready-to-use Microsoft Office templates covering AI governance, AI risk management policy, AI ethics, AI acceptable use, generative AI policy, AI pr... - [Comprehensive NIST SP 800-171 CUI Protection Toolkit – 33 Templates](https://governancedocs.com/product/nist-sp-800-171-toolkit/): NIST SP 800-171 Toolkit delivers 33 ready-to-use Microsoft Office templates covering CUI definition and identification, scoping and boundary, 14 control-family policies (access con... - [Comprehensive NIST SP 800-53 Security Controls Toolkit – 38 Templates](https://governancedocs.com/product/nist-sp-800-53-toolkit/): NIST SP 800-53 Toolkit delivers 38 ready-to-use Microsoft Office templates covering 20 control families covering access control, awareness and training, audit and accountability, a... - [Comprehensive NQA-1:2024 Nuclear Quality Assurance Toolkit – 100+ Templates](https://governancedocs.com/product/nuclear-quality-assurance-toolkit/): NQA-1:2024 Nuclear Quality Assurance Toolkit delivers 100+ ready-to-use Microsoft Office templates covering organization, quality assurance program management, design control, proc... - [Comprehensive SAMA Compliance Toolkit – 38 Documentation Templates](https://governancedocs.com/product/sama-toolkit/): SAMA Toolkit delivers 38 ready-to-use Microsoft Office templates covering cybersecurity, business continuity, IT governance, outsourcing, cloud computing, counter-fraud, and AML/CF... - [Comprehensive SOX Compliance Toolkit – 45 ICFR Templates](https://governancedocs.com/product/sox-toolkit/): SOX Toolkit delivers 45 ready-to-use Microsoft Office templates covering scoping and materiality, top-down risk assessment, fraud risk assessment, entity-level controls, process na... - [Comprehensive SWIFT CSP Compliance Toolkit – 32 Templates](https://governancedocs.com/product/swift-csp-toolkit/): SWIFT CSP Toolkit delivers 32 ready-to-use Microsoft Office templates aligned to CSCF v2026 covering secure zone architecture, access control and operator session management, netwo... - [Comprehensive TISAX Documentation Toolkit – 40 Compliance Templates](https://governancedocs.com/product/tisax-toolkit/): TISAX Toolkit delivers 40 ready-to-use Microsoft Office templates covering all assessment objectives of the VDA ISA2027 catalogue — from information security governance and prototy... - [Consultant Package — Every Toolkit, Licensed for Client Work](https://governancedocs.com/product/consultant-package/): The complete Governance Docs catalogue — 85 toolkits, 7,700+ editable documents — licensed for unlimited client engagements across your whole firm. One payment, perpetual licence,... - [Critical IT and Cybersecurity Indicators](https://governancedocs.com/product/it-and-cybersecurity-indicators/): Enhance your IT and cybersecurity risk management with our comprehensive Excel Templates. Featuring 153 meticulously designed Key Risk Indicators (KRI's), this high-quality tool pr... - [DORA Toolkit – 100+ Comprehensive Templates](https://governancedocs.com/product/dora-toolkit/): Achieve compliance with Regulation (EU) 2022/2554 (DORA) with 100+ ready-to-edit templates covering all five pillars — ICT risk management, incident classification and reporting, r... - [ESG Toolkit – 20+ Comprehensive Templates](https://governancedocs.com/product/esg-toolkit/): This ESG Toolkit (Environmental, Social, and Governance Toolkit) is the most complete and practical solution for building a robust ESG framework aligned with international sustaina... - [EU AMLR Toolkit – 99 AML Compliance Templates](https://governancedocs.com/product/eu-amlr-toolkit/): AML-CFT documentation toolkit for obliged entities under Regulation (EU) 2024/1624, the EU Anti-Money Laundering Regulation, which applies from 10 July 2027. 99 editable templates... - [FDA QMSR Toolkit – 21 CFR Part 820 Templates](https://governancedocs.com/product/fda-qmsr-toolkit/): 73 editable templates for 21 CFR Part 820 — the FDA Quality Management System Regulation effective 2 February 2026. Covers the FDA layer on top of ISO 13485: the four 820.10(b) bri... - [FedRAMP Toolkit – 52 Templates for the FedRAMP Consolidated Rules 2026](https://governancedocs.com/product/fedramp-toolkit/): FedRAMP Toolkit: 52 editable templates rebuilt for the FedRAMP Consolidated Rules for 2026. Certification Package Overview, Security Decision Record, Accepted Weaknesses List, Ongo... - [GDPR Toolkit – 100+ Comprehensive Templates](https://governancedocs.com/product/gdpr-toolkit/): Safeguard your business and ensure compliance with our GDPR Toolkit. Designed specifically for organizations handling sensitive data, this comprehensive pack equips you with the es... - [GENIUS Act Toolkit – 126 Stablecoin Compliance Templates](https://governancedocs.com/product/genius-act-toolkit/): Compliance documentation toolkit for payment stablecoin issuers under the GENIUS Act, Public Law 119-27, which takes effect on 18 January 2027. 126 editable templates - 98 Word doc... - [HACCP Toolkit – Comprehensive 30+ Templates](https://governancedocs.com/product/haccp-toolkit/): This HACCP Toolkit is one of the most comprehensive documentation packs available today. Developed in Microsoft Office format, all templates are fully editable and ready for quick... - [HIPAA Toolkit – Comprehensive 160+ Templates](https://governancedocs.com/product/hipaa-toolkit/): This is the most extensive HIPAA document toolkit on the market. Crafted in Microsoft Office format, these documents are prepared for customization to fit the unique requirements o... - [IATF 16949 Toolkit – 250+ Comprehensive Templates](https://governancedocs.com/product/iatf-16949-toolkit/): This is one of the most comprehensive IATF 16949 toolkits available for automotive quality management. All documents are developed in Microsoft Office format and are ready to be cu... - [IEC 62304 Toolkit – 97 Medical Device Software Templates](https://governancedocs.com/product/iec-62304-toolkit/): The IEC 62304 Toolkit delivers 97 ready-to-use Microsoft Office templates for medical device software — 84 Word documents and 13 Excel workbooks covering every one of the 98 requir... - [IEC 62443 Toolkit – 117 IACS Cybersecurity Templates](https://governancedocs.com/product/iec-62443-toolkit/): The IEC 62443 Toolkit delivers 117 ready-to-use Microsoft Office templates for industrial automation and control system asset owners — 82 Word documents and 35 Excel workbooks cove... - [IMS Toolkit – Comprehensive 90+ Templates](https://governancedocs.com/product/ims-toolkit/): This is one of the most comprehensive Integrated Management System (IMS) documentation toolkits available on the market, covering ISO 9001 (Quality), ISO 14001 (Environment), and I... - [ISO 13485 Toolkit – Comprehensive 126 Templates](https://governancedocs.com/product/iso-13485-toolkit/): This ISO 13485 document toolkit stands out as the most comprehensive option on the market. Crafted in Microsoft Office format, these documents are ready to be customized to meet th... - [ISO 14001 Toolkit – Comprehensive 65+ Templates](https://governancedocs.com/product/iso-14001-toolkit/): This toolkit is the most complete set of ISO 14001:2026 documents available today. Crafted in MS Office format, these documents can be customized to meet the unique requirements of... - [ISO 20000 Toolkit – Comprehensive ITSM Templates](https://governancedocs.com/product/iso-20000-toolkit/): This ISO 20000 Toolkit is the most comprehensive IT Service Management System (ITSMS) documentation pack available today. All templates are provided in fully editable Microsoft Off... - [ISO 22000 Toolkit – Comprehensive 35 Templates](https://governancedocs.com/product/iso-22000-toolkit/): This ISO 22000 toolkit is the most extensive one available today. Designed in Microsoft Office format, the documents are ready for customization to fit your organization's unique r... - [ISO 22301 Assessment Tool – Premium Quality](https://governancedocs.com/product/iso-22301-assessment-tool/): The ISO 22301 Assessment Tool is essential for evaluating and enhancing your organization's business continuity management system, ensuring compliance with the ISO 22301 standard.... - [ISO 22301 Toolkit – Comprehensive 75+ Templates](https://governancedocs.com/product/iso-22301-toolkit/): This is the most extensive ISO 22301 toolkit on the market. The documents are provided in Microsoft Office format and can be easily customized to meet your organization's unique re... - [ISO 27001 Assessment Tool – Premium Quality](https://governancedocs.com/product/iso-27001-assessment-tool/): Streamline your compliance with our ISO 27001 Assessment Tool. Identify risks, track progress, and receive recommendations for ISMS. - [ISO 27001 Toolkit – 165 Comprehensive Templates](https://governancedocs.com/product/iso-27001-toolkit/): This is the most comprehensive ISO 27001 documentation toolkit currently available. The documents are created in Microsoft Office format and are ready to be tailored to your organi... - [ISO 27701 Toolkit – Comprehensive 75+ Templates](https://governancedocs.com/product/iso-27701-toolkit/): This is the most extensive ISO 27701 toolkit on the market. The documents are provided in MS Office format and can be customized to meet your company requirements. Along with stand... - [ISO 42001 Toolkit – Comprehensive AI Governance Templates](https://governancedocs.com/product/iso-42001-toolkit/): This is the most complete ISO 42001 documentation pack available on the market. The documents are delivered in MS Office format and are fully editable to suit your organization's s... - [ISO 45001 Assessment Tool – Ultimate Solution](https://governancedocs.com/product/iso-45001-assessment-tool/): Optimize your Occupational Health and Safety system with the ISO 45001 Self-Assessment Tool. This essential tool helps identify and address gaps, ensuring ISO 45001 compliance and... - [ISO 45001 Toolkit – Comprehensive 50+ Templates](https://governancedocs.com/product/iso-45001-toolkit/): This toolkit is the most extensive collection of ISO 45001:2018 documents available today. Designed in Office format, these documents are ready to be customized to meet the specifi... - [ISO 9001 Toolkit – 84 Templates for ISO 9001:2026](https://governancedocs.com/product/iso-9001-toolkit/): The ISO 9001 Toolkit is now written to ISO 9001:2026, the sixth edition published in September 2026. 84 ready-to-use Microsoft Office templates — 60 Word documents and 24 Excel wor... - [MiCA Toolkit – 100+ Comprehensive Templates](https://governancedocs.com/product/mica-toolkit/): This is the most comprehensive MiCA compliance documentation toolkit currently available. The documents are created in Microsoft Office format and are ready to be tailored to your... - [NCA Cybersecurity Toolkit](https://governancedocs.com/product/nca-cybersecurity-toolkit/): This is one of the most comprehensive NCA Cybersecurity documentation toolkits currently available. The documents are created in Microsoft Office format and are ready to be tailore... - [NERC CIP Toolkit – 130 CIP Compliance Templates](https://governancedocs.com/product/nerc-cip-toolkit/): The NERC CIP Toolkit delivers 130 ready-to-use Microsoft Office templates for US-registered Responsible Entities — 90 Word documents and 40 Excel workbooks covering all 46 requirem... - [NIS2 Toolkit – 75+ Comprehensive Templates](https://governancedocs.com/product/nis2-toolkit/): This is the most comprehensive NIS2 compliance documentation toolkit currently available. The documents are created in Microsoft Office format and are ready to be tailored to your... - [NIST CSF Toolkit – 164 Cybersecurity Framework 2.0 Templates](https://governancedocs.com/product/nist-csf-toolkit/): The NIST CSF Toolkit is 164 editable documents covering all 106 Subcategories of the NIST Cybersecurity Framework 2.0 — 118 Word policies and procedures plus 46 Excel workbooks, in... - [NIST Cyber Risk Management Toolkit](https://governancedocs.com/product/nist-risk-management-toolkit/): The NIST Risk Management Toolkit is a comprehensive collection of over 50 professional files, designed to cover all aspects of information security risk management built on the NIS... - [NIST Privacy Framework Toolkit – 145 Privacy Templates](https://governancedocs.com/product/nist-privacy-framework-toolkit/): The NIST Privacy Framework Toolkit delivers 145 ready-to-use Microsoft Office templates for building a privacy program — 108 Word documents and 37 Excel workbooks covering every on... - [PCI PIN Security Toolkit – 149 Templates for PIN v3.1](https://governancedocs.com/product/pci-pin-security-toolkit/): The PCI PIN Security Toolkit delivers 149 ready-to-use Microsoft Office templates — 118 Word documents and 31 Excel workbooks — covering all 145 sub-requirements of PCI PIN Securit... - [PCI-DSS Toolkit – Comprehensive 180+ Templates](https://governancedocs.com/product/pci-dss-toolkit/): This toolkit is the most thorough PCI-DSS v4.0.1 document collection available today. Crafted in MS format, these documents are ready for customization to meet your organization’s... - [Project Management Toolkit – Comprehensive 370 Templates](https://governancedocs.com/product/project-management-toolkit/): This is one of the most comprehensive Project Management documentation toolkits available for PMI-aligned project delivery. All documents are provided in Microsoft Office format an... - [QHSE Documentation Bundles – Comprehensive 1,395 Templates](https://governancedocs.com/product/qhse-documentation-bundles/): This is one of the most comprehensive QHSE (Quality, Health, Safety & Environment) documentation bundles available, designed to support organizations in implementing and maintainin... - [Saudi PDPL Toolkit – 75 Saudi Data Protection Templates (SDAIA)](https://governancedocs.com/product/saudi-pdpl-toolkit/): Saudi PDPL Toolkit: 75 editable templates for the Saudi Personal Data Protection Law, its Implementing Regulation, the Transfer Regulation and SDAIA's rules. Policy, consent, priva... - [SOC 1 Toolkit – 87 SSAE 18 / ISAE 3402 Service Organization Templates](https://governancedocs.com/product/soc-1-toolkit/): SOC 1 Toolkit: 87 editable SOC 1 / ISAE 3402 templates built on AT-C section 320 — management's system description in every required section, 19 control objectives with 76 risks an... - [SOC2 Toolkit – Premium Documentation Pack](https://governancedocs.com/product/soc2-toolkit/): Safeguard your business and ensure compliance with our SOC 2 Toolkit. Designed specifically for service organizations that process customer data, this comprehensive toolkit equips... - [TPRM Toolkit – 86 Third-Party Risk Management Templates](https://governancedocs.com/product/tprm-toolkit/): TPRM Toolkit: 86 editable third-party risk management templates on the lifecycle every regulator uses — planning, due diligence, contracting, monitoring and exit — mapped to 188 re... - [UK GDPR Toolkit – 90 UK Data Protection Templates (DUAA 2025)](https://governancedocs.com/product/uk-gdpr-toolkit/): UK GDPR Toolkit: 90 editable UK data protection templates written for the UK GDPR as amended by the Data (Use and Access) Act 2025, the Data Protection Act 2018 and PECR. Policies,... - [WISP Toolkit – 74 FTC Safeguards Rule Templates](https://governancedocs.com/product/wisp-toolkit/): Written Information Security Plan toolkit for US tax and accounting practices. 74 editable templates covering all 10 elements of the FTC Safeguards Rule, 16 CFR Part 314 — includin... ## Guides and Articles (796) ### DORA (5) - [DORA Compliance Checklist & the January 2025 Deadline](https://governancedocs.com/dora-compliance-checklist/): A practical, pillar-by-pillar DORA compliance checklist covering ICT risk, incident reporting, testing, and third-party... - [DORA Explained: The Digital Operational Resilience Act Guide](https://governancedocs.com/digital-operational-resilience-act/): The DORA regulation makes the EU financial sector resilient to ICT and cyber disruption. A complete guide to its five pi... - [DORA Requirements: The 5 Pillars & What You Must Document](https://governancedocs.com/dora-requirements/): What does DORA actually require? A breakdown of the five pillars and the policies, procedures, and records you must docu... - [DORA vs NIS2: How They Overlap for Financial Firms](https://governancedocs.com/dora-vs-nis2/): DORA vs NIS2: one is a financial-sector regulation, the other a cross-sector directive. Here are the key differences and... - [Who Does DORA Apply To? Financial Entities & ICT Providers](https://governancedocs.com/who-does-dora-apply-to/): DORA reaches further than many expect. Learn which financial entities and technology providers are in scope - and check... ### GDPR (9) - [Building a Scalable Data Protection Strategy](https://governancedocs.com/data-protection-strategy/): Building a strong data protection strategy is essential for businesses aiming to safeguard sensitive information while g... - [GDPR Data Processing Agreement (DPA): A Complete Guide](https://governancedocs.com/gdpr-dpa/): A GDPR DPA is required whenever a third party processes personal data for you. Here is what a Data Processing Agreement... - [GDPR Data Subject Rights Explained](https://governancedocs.com/gdpr-data-subject-rights/): The GDPR data subject rights put individuals in control of their data. Here are all eight rights, how to respond to requ... - [GDPR Documentation Requirements Checklist](https://governancedocs.com/gdpr-documentation-requirements/): The accountability principle makes documentation central to GDPR. Here is a complete checklist of the records you need a... - [GDPR Explained: A Complete Compliance Guide](https://governancedocs.com/gdpr-compliance-tips/): GDPR compliance is a legal requirement for anyone handling EU personal data. A complete guide to the principles, lawful... - [How to Run a GDPR Gap Analysis](https://governancedocs.com/gdpr-gap-analysis/): A GDPR gap analysis shows exactly where you stand against the regulation. Here is a step-by-step method to run one and b... - [ISO 27701: A Guide to Privacy Information Management](https://governancedocs.com/iso-27701-privacy/): ISO 27701 is the international standard for privacy information management. This guide explains what a PIMS covers, what... - [ISO 27701:2025 vs 2019: What Changed and What You Must Do](https://governancedocs.com/iso-27701-2025-vs-2019/): Key TakeawaysISO/IEC 27701:2025 replaced the 2019 edition on 14 October 2025 and is now a standalone standard.An ISO 270... - [The 7 GDPR Principles Explained](https://governancedocs.com/gdpr-principles/): The seven GDPR principles are the foundation of the whole regulation. Here is what each one requires in practice - and w... ### HIPAA (6) - [HIPAA Business Associate Agreement (BAA): A Guide](https://governancedocs.com/hipaa-baa/): A HIPAA BAA is required whenever a vendor handles protected health information for you. Here is what a Business Associat... - [HIPAA Compliance Checklist for Vendors & Small Practices](https://governancedocs.com/hipaa-compliance-checklist/): A practical HIPAA compliance checklist, organised by the Privacy and Security Rules, breach notification, and business a... - [HIPAA Explained: A Complete Compliance Guide](https://governancedocs.com/hipaa-compliance-tips/): HIPAA compliance is a legal requirement for anyone handling US health data. A complete guide to the rules, PHI, covered... - [HIPAA Required Policies & Documentation Checklist](https://governancedocs.com/hipaa-policies/): HIPAA requires documented policies and procedures. Here are the essential HIPAA policies, the records you must keep, and... - [HIPAA Security Rule vs Privacy Rule Explained](https://governancedocs.com/hipaa-security-rule-vs-privacy-rule/): HIPAA Security Rule vs Privacy Rule: one protects electronic health data, the other governs its use and disclosure. Here... - [How to Conduct a HIPAA Risk Assessment](https://governancedocs.com/hipaa-risk-assessment/): The HIPAA risk assessment is the foundation of the Security Rule. Here is what it is, why it is required, and a step-by-... ### ISO 27001 (34) - [CIS Controls ISO 27001 Mapping: All 18 Controls to Annex A (2026)](https://governancedocs.com/cis-controls-iso-27001-mapping/): CIS Controls ISO 27001 mapping: all 18 Controls to the 93 Annex A controls of ISO 27001:2022, where CIS goes deeper, wha... - [Cloud Service Agreement: 8 Essential ISO 27017 Security Clauses](https://governancedocs.com/cloud-service-agreement/): Cloud service agreement security under ISO 27017 and ISO 27002 5.20/5.23: the 8 clauses, the controls each implements, e... - [Cyber Essentials vs ISO 27001: 10 Clear Differences (2026)](https://governancedocs.com/cyber-essentials-vs-iso-27001/): Cyber Essentials vs ISO 27001 on 10 points: 5 prescribed controls vs a risk-based ISMS, cost, validity, who needs which,... - [How Much Does ISO 27001 Certification Cost? (Complete 2026 Breakdown)](https://governancedocs.com/how-much-does-iso-27001-certification-cost-2026-breakdown/): A practical 2026 breakdown of what ISO 27001 certification actually costs, from certification-body audit fees to the int... - [How to Choose an ISO 27001 Certification Body: The Complete 2026 Guide](https://governancedocs.com/iso-27001-certification-body/): A practical 2026 guide to choosing an accredited ISO 27001 certification body: what changed on 1 January 2026, seven sel... - [How to Get ISO 27001 Certified: A Step-by-Step Guide](https://governancedocs.com/iso-27001-certification/): ISO 27001 certification proves how you protect information. Here is the step-by-step process, how long it takes, and wha... - [How to Prepare for an ISO 27001 Audit](https://governancedocs.com/iso-27001-audit/): The ISO 27001 audit tests your ISMS in practice. Here is what auditors check, how the stages work, and how to prepare fo... - [ISO 20000 vs ISO 27001: 5 Clear Differences Explained (2026)](https://governancedocs.com/iso-20000-vs-iso-27001/): ISO 20000 vs ISO 27001 on 5 differences: purpose, what the audit tests, who asks, overlap, and which to certify first —... - [ISO 27001 Annex A Controls Explained (2022)](https://governancedocs.com/iso-27001-2022-controls/): The ISO 27001 Annex A controls turn security principles into practice. Here are the 93 controls, the four 2022 themes, a... - [ISO 27001 Assessment Report: A Clear Guide to the 6 Sections](https://governancedocs.com/iso-27001-assessment-report/): The ISO 27001 assessment report in 6 sections — summary, method, clause results, Annex A results, findings, action plan... - [ISO 27001 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-27001-certification-cost/): ISO 27001 certification cost in 2026 runs $8,000 to $30,000 for most small US companies. A full line-item breakdown of a... - [ISO 27001 Control Assessment: A Clear Annex A Scoring Guide](https://governancedocs.com/iso-27001-control-assessment/): The ISO 27001 control assessment: scoring all 93 Annex A controls for applicability, implementation and evidence, with t... - [ISO 27001 Explained: The Complete Guide to Information Security](https://governancedocs.com/iso-27001-2022/): ISO 27001 is the world's leading information security standard. A complete guide to the ISMS, clause structure, the 93 A... - [ISO 27001 Gap Analysis: The Complete 2026 Step-by-Step Guide](https://governancedocs.com/iso-27001-gap-analysis/): An ISO 27001 gap analysis compares what you actually do against clauses 4-10 and the 93 Annex A controls. Here is the se... - [ISO 27001 Gap Assessment: A Clear Guide to the 4 Outputs](https://governancedocs.com/iso-27001-gap-assessment/): An ISO 27001 gap assessment delivers 4 outputs: a gap register, a prioritized remediation plan, a draft SoA and a readin... - [ISO 27001 Internal Audit: The Complete 2026 Guide to Clause 9.2](https://governancedocs.com/iso-27001-internal-audit/): What ISO 27001 clause 9.2 requires from an internal audit, who can run it, a seven-step method, and the records certific... - [ISO 27001 Management Review: The Complete 2026 Guide](https://governancedocs.com/iso-27001-management-review/): What ISO 27001 clause 9.3 requires: the seven management review inputs, how often to meet, what to minute, and the mista... - [ISO 27001 Mandatory Documents Checklist (2022)](https://governancedocs.com/iso-27001-mandatory-documents/): What documents does ISO 27001 require? A complete checklist of the mandatory ISO 27001 documents and records - and how t... - [ISO 27001 Policy Templates & Examples](https://governancedocs.com/iso-27001-policy-templates/): The right ISO 27001 policy templates turn documentation from daunting to achievable. Here are the policies you need and... - [ISO 27001 Risk Assessment: The Complete 2026 Method](https://governancedocs.com/iso-27001-risk-assessment/): How to run an ISO 27001 risk assessment that survives an audit: what clause 6.1.2 actually requires, the six steps in or... - [ISO 27001 Risk Treatment Plan: The Complete 2026 Guide](https://governancedocs.com/iso-27001-risk-treatment-plan/): An ISO 27001 risk treatment plan is required by clause 6.1.3. Here are the fields it needs, the four treatment options,... - [ISO 27001 Self-Assessment: A Clear Guide to Scoring All 93 Controls](https://governancedocs.com/iso-27001-self-assessment/): An ISO 27001 self-assessment scores clauses 4–10 and all 93 Annex A controls on a 5-point scale with evidence: how to ru... - [ISO 27001 Stage 1 vs Stage 2: The Complete 2026 Audit Guide](https://governancedocs.com/iso-27001-stage-1-vs-stage-2/): ISO 27001 Stage 1 vs Stage 2 explained by clause: what each audit checks, how audit days are set, the gap between them,... - [ISO 27001 Statement of Applicability: The Complete 2026 Guide](https://governancedocs.com/iso-27001-statement-of-applicability/): The ISO 27001 Statement of Applicability is mandatory under clause 6.1.3(d). What it must contain for all 93 Annex A con... - [ISO 27001 Surveillance Audit: The Complete 2026 Guide](https://governancedocs.com/iso-27001-surveillance-audit/): What an ISO 27001 surveillance audit covers, when it is due, what it costs in 2026, and how to prepare — with the exact... - [ISO 27001 Timeline: How Long Does Certification Take?](https://governancedocs.com/iso-27001-timeline/): A realistic look at the ISO 27001 timeline: how long certification takes by company size, the seven phases involved, and... - [ISO 27001 vs NIST CSF: Which One Do You Need? (Complete 2026 Guide)](https://governancedocs.com/iso-27001-vs-nist-csf/): ISO 27001 vs NIST CSF compared: certification versus self-assessment, 93 Annex A controls versus 106 CSF outcomes, and w... - [ISO 27017 Certification Cost: The Complete 2026 Breakdown](https://governancedocs.com/iso-27017-certification-cost/): ISO 27017 certification cost: an ISO 27001 extension, $6k–25k first year — gap analysis, cloud controls, 0.5–2 extra aud... - [ISO 27017 vs CSA STAR: 6 Essential Differences for Cloud Providers](https://governancedocs.com/iso-27017-vs-csa-star/): ISO 27017 vs CSA STAR: a standard audited inside ISO 27001 vs a public registry on the CCM (207 objectives), assessment,... - [ISO 27017 vs ISO 27018: 6 Clear Differences and Which You Need](https://governancedocs.com/iso-27017-vs-iso-27018/): ISO 27017 vs ISO 27018: cloud security for providers and customers vs PII processor privacy, the 2026 and 2025 editions,... - [NIST 800-53 vs ISO 27001: 5 Clear Differences Explained](https://governancedocs.com/nist-800-53-vs-iso-27001/): NIST 800-53 vs ISO 27001 on 5 differences: catalogue vs certifiable system, baseline vs risk assessment, granularity, as... - [NIST CSF vs ISO 27001: 5 Clear Differences Explained (2026)](https://governancedocs.com/nist-csf-vs-iso-27001/): NIST CSF vs ISO 27001 on 5 differences: outcome framework vs certifiable system, Profiles vs certificate, scope, prescri... - [PII Processor: 9 Essential ISO 27018 Obligations in the Cloud](https://governancedocs.com/pii-processor/): PII processor obligations under ISO 27018:2025: 9 duties by ISO/IEC 29100 principle, the GDPR Article 28 mapping, the 20... - [Supplier Security Assessment: A Clear ISO 27001 Guide for 2026](https://governancedocs.com/supplier-security-assessment/): A supplier security assessment under ISO 27001 controls A.5.19–A.5.22: tier suppliers, what to ask, what evidence to acc... ### ISO 42001 & AI governance (25) - [AI Controls Matrix: 247 Essential CSA Controls and STAR for AI](https://governancedocs.com/ai-controls-matrix/): AI Controls Matrix v1.1 (22 June 2026): 247 objectives in 18 domains, 5 pillars, 5 roles, mappings to ISO 42001, the EU... - [EU AI Act Compliance Cost: A Clear 2026 Breakdown](https://governancedocs.com/eu-ai-act-compliance-cost/): EU AI Act compliance cost by risk tier: the Commission's €6,000-€7,000 per high-risk system, the €400,000 critics' figur... - [EU AI Act Compliance Deadlines & Timeline (2025-2027)](https://governancedocs.com/eu-ai-act-deadlines/): The EU AI Act applies in phases, not on one date. Here is the full timeline of deadlines from 2024 to 2027 and how to se... - [EU AI Act Conformity Assessment: A Clear 2026 Guide](https://governancedocs.com/eu-ai-act-conformity-assessment/): The EU AI Act conformity assessment under Article 43: which of 2 routes applies, Annex VI internal control step by step,... - [EU AI Act Documentation Requirements Checklist](https://governancedocs.com/eu-ai-act-documentation-requirements/): Compliance rests on evidence. This EU AI Act documentation requirements checklist covers every record high-risk systems... - [EU AI Act Penalties: A Clear 2026 Guide to the 3 Fine Tiers](https://governancedocs.com/eu-ai-act-penalties/): EU AI Act penalties: 3 tiers to €35m or 7%, the lower-of rule for SMEs and small mid-caps, Article 101 GPAI fines, the 1... - [EU AI Act Risk Categories: Prohibited, High-Risk & Limited](https://governancedocs.com/eu-ai-act-risk-categories/): Every AI system falls into one of four EU AI Act risk tiers. Here is what prohibited, high, limited and minimal risk eac... - [EU AI Act Transparency Obligations: A Clear Article 50 Guide](https://governancedocs.com/eu-ai-act-transparency-obligations/): EU AI Act transparency obligations under Article 50, in force since 2 August 2026: the 4 duties, who carries each, the 2... - [How to Get ISO 42001 Certified: A Step-by-Step Guide](https://governancedocs.com/iso-42001-certification/): ISO 42001 certification proves you govern AI responsibly. Here is the step-by-step process, how long it takes, and what... - [ISO 27001 vs ISO 42001: The Complete 2026 Comparison Guide](https://governancedocs.com/iso-27001-vs-iso-42001/): ISO 27001 vs ISO 42001 compared for 2026: 93 security controls versus 38 AI controls, the shared clause structure, what... - [ISO 42001 Annex A Controls Explained](https://governancedocs.com/iso-42001-controls/): The ISO 42001 Annex A controls turn responsible-AI principles into auditable practice. Here is what they cover and how t... - [ISO 42001 Certification Cost in 2026: A Complete Breakdown](https://governancedocs.com/iso-42001-certification-cost/): A practical 2026 breakdown of ISO 42001 certification cost - readiness, implementation, Stage 1 and Stage 2 audit fees,... - [ISO 42001 Certification Timeline: A Clear 2026 Roadmap](https://governancedocs.com/iso-42001-certification-timeline/): An ISO 42001 certification timeline in 8 phases: 6-12 months for a first AIMS, 3-6 with ISO 27001, the phase you cannot... - [ISO 42001 Explained: The AI Management System Standard](https://governancedocs.com/iso-42001-responsible-ai/): ISO 42001 is the world's first AI management system standard. A complete guide to the AIMS, its structure, Annex A contr... - [ISO 42001 Internal Audit: A Clear 2026 Guide to Clause 9.2](https://governancedocs.com/iso-42001-internal-audit/): An ISO 42001 internal audit under clause 9.2: the 6 things it must show, how it differs from an ISO 27001 audit, what to... - [ISO 42001 Requirements & Mandatory Documents](https://governancedocs.com/iso-42001-requirements/): What does ISO 42001 actually require? A practical guide to the standard's clauses, mandatory documents, the AI impact as... - [ISO 42001 Risk Assessment: A Clear Guide to Clause 6.1.2](https://governancedocs.com/iso-42001-risk-assessment/): The ISO 42001 risk assessment under clause 6.1.2: 5 requirements, Annex C's 11 objectives and 7 risk sources, and how it... - [ISO 42001 Statement of Applicability: A Clear 2026 Guide](https://governancedocs.com/iso-42001-statement-of-applicability/): The ISO 42001 Statement of Applicability under clause 6.1.3: all 38 Annex A controls, the 5 columns that make it auditab... - [ISO 42001 vs NIST AI RMF: Which AI Framework?](https://governancedocs.com/iso-42001-vs-nist-ai-rmf/): ISO 42001 vs NIST AI RMF: one is a certifiable standard, the other a voluntary framework. Here are the key differences a... - [NIST AI RMF Implementation: A Clear 8-Step Plan for 2026](https://governancedocs.com/nist-ai-rmf-implementation/): NIST AI RMF implementation in 8 steps: inventory, governance, profiles, Map, Measure, Manage, operate, with the output o... - [NIST AI RMF Playbook: A Clear Guide to All 72 Subcategories](https://governancedocs.com/nist-ai-rmf-playbook/): The NIST AI RMF Playbook explained: what its 72 subcategory entries contain, the 4 sections in each, how to use it witho... - [NIST AI RMF vs EU AI Act: A Clear 2026 Comparison](https://governancedocs.com/nist-ai-rmf-vs-eu-ai-act/): NIST AI RMF vs EU AI Act: voluntary framework against binding law with fines to €35m or 7%. An 8-point comparison, the f... - [The EU AI Act Explained: A Complete Compliance Guide](https://governancedocs.com/eu-ai-act-explained/): The EU AI Act is the world's first comprehensive AI law. A clear guide to who it applies to, the four risk tiers, high-r... - [Trustworthy AI Characteristics: A Clear Guide to NIST’s 7](https://governancedocs.com/trustworthy-ai-characteristics/): The 7 trustworthy AI characteristics in the NIST AI RMF: what each means, how they relate, the 3 trade-offs NIST names,... - [Who Does the EU AI Act Apply To? Provider vs. Deployer](https://governancedocs.com/who-does-the-eu-ai-act-apply-to/): The EU AI Act applies by role and reaches far beyond Europe. Learn the difference between providers and deployers, and c... ### ISO 9001 (10) - [AS9100 vs ISO 9001: 14 Essential Aerospace Additions (2026)](https://governancedocs.com/as9100-vs-iso-9001/): AS9100 vs ISO 9001: the same 10 clauses with 14 aerospace additions — operational risk, configuration, product safety, c... - [How to Get ISO 9001 Certified: A Step-by-Step Guide](https://governancedocs.com/iso-9001-certification/): ISO 9001 certification is the world's most recognised quality credential. Here is the step-by-step process, how long it... - [ISO 17025 vs ISO 9001: 7 Clear Differences for Laboratories](https://governancedocs.com/iso-17025-vs-iso-9001/): ISO 17025 vs ISO 9001: competence accreditation vs system certification, schedule vs scope, the technical clauses, impar... - [ISO 21001 vs ISO 9001: 7 Clear Differences Explained (2026)](https://governancedocs.com/iso-21001-vs-iso-9001/): ISO 21001 vs ISO 9001: same harmonized structure, different beneficiary. The 7 differences, the 2025 and 2026 editions,... - [ISO 9001 Certification Cost: A Complete 2026 Breakdown](https://governancedocs.com/iso-9001-cost/): What ISO 9001 certification actually costs in 2026, broken down by company size, with a worked example, one-time versus... - [ISO 9001 Clauses Explained (Clauses 4-10)](https://governancedocs.com/iso-9001-clauses/): The ISO 9001 clauses hold every requirement. Here is a plain-language walkthrough of clauses 4 to 10, from context and l... - [ISO 9001 Explained: The Complete Quality Management Guide](https://governancedocs.com/iso-9001-quality-management/): ISO 9001 is the world's most-used quality management standard. A complete guide to the QMS, the seven principles, clause... - [ISO 9001 Internal Audit: The Complete 2026 Checklist Guide](https://governancedocs.com/iso-9001-internal-audit/): ISO 9001 internal audit guide for the 2026 edition: what clause 9.2 requires, a 65-line checklist on the new numbering,... - [ISO 9001 Mandatory Documents & Records List](https://governancedocs.com/iso-9001-mandatory-documents/): What documents does ISO 9001 require? A complete list of the mandatory ISO 9001:2015 documents and records - and how to... - [QHSE Policy: 8 Essential Commitments for 3 Standards (2026)](https://governancedocs.com/qhse-policy/): The QHSE policy: the clause 5.2 requirements of ISO 9001:2026, ISO 14001:2026 and ISO 45001 side by side, the 8 commitme... ### Management systems (423) - [10 CFR 50 Appendix B: A Clear Guide to the 18 Criteria](https://governancedocs.com/10-cfr-50-appendix-b/): 10 CFR 50 Appendix B sets 18 QA criteria for nuclear facilities. How NQA-1 satisfies them, which editions the NRC endors... - [10 CFR Part 21: A Clear Guide to Reporting Defects in 2026](https://governancedocs.com/10-cfr-part-21/): 10 CFR Part 21 explained: who it reaches, the 4 definitions that decide reportability, the 60-, 5-, 2- and 30-day clocks... - [AI Governance in ITSM: A Practical 2026 Guide](https://governancedocs.com/ai-governance-in-itsm/): AI governance in ITSM starts with an inventory, not a policy. How to scale oversight to capability and evidence controls... - [AI System Impact Assessment: A Clear Guide to ISO 42005](https://governancedocs.com/ai-system-impact-assessment/): An AI system impact assessment looks outward, not inward. What ISO/IEC 42005:2025 asks for in 7 steps, how it differs fr... - [Annex SL Explained: The Best Guide to 10 ISO Clauses](https://governancedocs.com/what-is-annex-sl/): Annex SL is the harmonized structure behind ISO 9001, 14001, 27001 and 45001. The 10 clauses explained, the 2021 rename,... - [Anti-Bribery Due Diligence: A Complete Guide to ISO 37001 Cl. 8.2](https://governancedocs.com/anti-bribery-due-diligence/): Anti-bribery due diligence under ISO 37001:2025 clause 8.2: the trigger, tiering associates and personnel, 7 checks and... - [AS9110 vs AS9120: A Clear Guide to Which You Need (2026)](https://governancedocs.com/as9110-vs-as9120/): AS9110 vs AS9120: the maintenance and distributor variants of AS9100 — what each adds, 6 scenarios for deciding which ap... - [Asset Criticality: 5 Essential Steps to Rank Assets (ISO 55001)](https://governancedocs.com/asset-criticality/): Asset criticality assessment: 5 steps, 5 consequence categories on anchored scales, consequence separate from likelihood... - [Asset Inventory: A Clear Guide to CIS Controls 1 and 2](https://governancedocs.com/it-asset-inventory/): The asset inventory is CIS Control 1 because everything below it assumes the output. What each record needs, 5 discovery... - [Asset Management Policy: 6 Essential ISO 55001 Clause 5.2 Sections](https://governancedocs.com/asset-management-policy/): Asset management policy under ISO 55001:2024 clause 5.2: the 6 sections, the framework for objectives, alignment with th... - [Asset Register: 12 Essential Fields for ISO 55001 Decisions (2026)](https://governancedocs.com/asset-register/): Asset register for ISO 55001:2024: the 12 fields clauses 7.6, 8.1 and 4.5 need, aligning financial and non-financial reg... - [Authorised Economic Operator: A Clear Guide to the 4 Tests](https://governancedocs.com/authorised-economic-operator/): Authorised Economic Operator status comes as AEOC or AEOS, against 4 cumulative criteria. What the audit examines, and h... - [Authorization Boundary: 6 Proven Steps for FedRAMP 2026](https://governancedocs.com/fedramp-authorization-boundary/): The 2026 Consolidated Rules do not define an authorization boundary. Scope now comes from the Minimum Assessment Scope r... - [Automated Decision-Making Technology: A Clear 2027 Guide](https://governancedocs.com/automated-decision-making-technology/): Automated decision-making technology under the CCPA: what counts, which decisions are caught, the 3 rights, and why HR s... - [Backup Policy: 6 Proven Rules DORA Article 12 Sets](https://governancedocs.com/backup-policy/): Scope, frequency derived from classification, segregation from the source system, RTOs that hold in extreme scenarios, a... - [Basel III in 2026: Adoption Is Still Incomplete](https://governancedocs.com/basel-iii/): Basel III was set to be in effect from 1 January 2023, but adoption runs jurisdiction by jurisdiction and element by ele... - [Benefit-Risk Analysis: The Complete ISO 14971 Clause 7.4 Guide](https://governancedocs.com/benefit-risk-analysis/): Benefit-risk analysis under ISO 14971:2019: when clauses 7.4 and 8 require it, what benefit means (3.2), how to evidence... - [Benefits Realisation: A Clear Guide to All 4 Stages](https://governancedocs.com/benefits-realisation/): Benefits realisation in 4 stages: identification, planning, realisation and transition. Why baselines matter and how to... - [Bow Tie Analysis: The 6 Essential Elements Explained (2026)](https://governancedocs.com/bow-tie-analysis/): Bow tie analysis under IEC 31010: the 6 elements (hazard, top event, threats, consequences, preventive and mitigative ba... - [Breach Notification: Two Thresholds, Two Clocks](https://governancedocs.com/breach-notification/): GDPR breach notification is not one 72-hour rule. Two thresholds, two audiences, phased notification, and the log you mu... - [Breach Risk Assessment: A Clear Guide to the 4 HIPAA Factors](https://governancedocs.com/hipaa-breach-risk-assessment/): A HIPAA breach risk assessment starts with 3 exclusions, then the 4 factors in 45 CFR 164.402 - and the burden of showin... - [Bribery Risk Assessment: A Complete Guide to ISO 37001 Clause 4.5](https://governancedocs.com/bribery-risk-assessment/): Bribery risk assessment under ISO 37001:2025 clause 4.5: what it requires, 7 risk factors, the 8-step method, defining l... - [Bridge Letter: What It Covers, and What It Does Not](https://governancedocs.com/soc-2-bridge-letter/): A SOC 2 bridge letter is written by management, not the auditor, and nothing in it is tested. How to read one, how long... - [BSI C5 Attestation: A Clear Guide to Type 1 and Type 2](https://governancedocs.com/bsi-c5-attestation/): A BSI C5 attestation is an assurance report, not a certificate. Type 1 vs type 2, what the report contains, and how ofte... - [BSI C5 vs ISO 27001: A Clear Guide to the 4 Differences](https://governancedocs.com/bsi-c5-vs-iso-27001/): BSI C5 vs ISO 27001 is report against certificate, service against organization. The 4 differences that matter, and how... - [BSI C5:2026: What the Revision Changed and Why EUCS Matters](https://governancedocs.com/bsi-c5/): BSI C5:2026 explained — the EUCS Substantial alignment, the new subcriteria structure, sharpen versus complement, and th... - [Business Continuity Exercise: 6 Proven Steps to Test the Switchover](https://governancedocs.com/business-continuity-exercise/): DORA requires yearly testing of continuity, recovery and crisis communication plans, including cyber-attack and switchov... - [Business Continuity Plan: What ISO 22301 Requires It to Contain](https://governancedocs.com/iso-22301-business-continuity-plan/): What a business continuity plan must contain under ISO 22301 clause 8.4: response structure, triggers, warning and commu... - [Business Impact Analysis: How to Do One That Holds Up](https://governancedocs.com/iso-22301-business-impact-analysis/): How to run a business impact analysis under ISO 22301 clause 8.2: prioritized activities, MTPD, RTO and RPO, dependencie... - [BYOD Policy: The Essential 2026 Guide for ISO 27001](https://governancedocs.com/byod-policy/): A BYOD policy that survives an ISO 27001 audit: the 7 Annex A controls it satisfies, the 9 clauses it needs, and the MDM... - [C-TPAT: The Complete Guide to the Minimum Security Criteria (2026)](https://governancedocs.com/c-tpat/): C-TPAT (CTPAT): who can join, the Minimum Security Criteria — 3 focus areas, 12 categories, 93 importer criteria — the s... - [CASP Authorisation: A Clear Guide to the 2026 MiCA Licence](https://governancedocs.com/casp-authorisation/): CASP authorisation under MiCA: the 9 parts of the file, the 25 and 40 working day clock, capital by service class, and w... - [CCPA Compliance in 2026: Every New Deadline Explained](https://governancedocs.com/ccpa-compliance/): CCPA compliance changed on 1 January 2026. The risk assessment, ADMT and cybersecurity audit deadlines, read from the ap... - [CCPA Service Provider vs Contractor: A Clear 2026 Guide](https://governancedocs.com/ccpa-service-provider-vs-contractor/): CCPA service provider, contractor or third party: the section 1798.140 definitions, the 5 contract terms that create the... - [CertiKit Alternative: The Best Options Before It Closes in 2026](https://governancedocs.com/certikit-alternative/): CertiKit closes on 18 December 2026. A CertiKit alternative covering all nine of their frameworks plus 66 more, at $99 p... - [CIS Benchmarks vs CIS Controls: A Clear Guide for 2026](https://governancedocs.com/cis-benchmarks-vs-cis-controls/): CIS Benchmarks are configuration guides; CIS Controls are a prioritized program. What each covers, the 3 profile levels,... - [CIS Controls v8.1: The 18 Controls and 3 Implementation Groups](https://governancedocs.com/cis-controls/): A practical guide to CIS Controls v8.1 — the 18 Controls, the 153 Safeguards, and how the three Implementation Groups de... - [Clean Desk Policy: 9 Essential Rules for 2026](https://governancedocs.com/clean-desk-policy/): A clean desk policy that passes an ISO 27001 audit: what Annex A 7.7 requires, the 9 rules to include, and the clear scr... - [Cloud Controls Matrix: A Clear Guide to CCM v4.1 and the CAIQ](https://governancedocs.com/cloud-controls-matrix/): The Cloud Controls Matrix explained: 17 domains, how the CAIQ turns it into a STAR submission, what CCM v4.1 changed, an... - [Cloud Cybersecurity Controls: A Clear CCC-2:2024 Guide](https://governancedocs.com/cloud-cybersecurity-controls/): The Cloud Cybersecurity Controls split obligations between provider and tenant. CCC-2:2024, the 6 responsibility areas,... - [CMMC Compliance: The Four-Phase Rollout Explained](https://governancedocs.com/cmmc-compliance/): CMMC compliance explained: the three levels, the four phases, and why Phase 2 on 10 November 2026 is when a Level 2 self... - [COBIT 2019 Implementation: A Clear Guide to the 7 Phases](https://governancedocs.com/cobit-2019-implementation/): A COBIT 2019 implementation is a 7-phase improvement cycle, not a rollout of 40 objectives. The phases, the design facto... - [COBIT 2019: The 40 Objectives and Why There Is No Certificate](https://governancedocs.com/cobit-2019/): COBIT 2019 explained — the 40 governance and management objectives, the five domains, the design factors that tailor the... - [Combined Internal Audit: A Clear Guide for QHSE in 2026](https://governancedocs.com/combined-internal-audit/): A combined internal audit covers several standards in one visit. What merges, what stays separate, and the coverage matr... - [Commercial Grade Dedication: A Clear Guide to 4 Methods](https://governancedocs.com/commercial-grade-dedication/): Commercial grade dedication under NQA-1 Subpart 2.14: the 4 acceptance methods, identifying critical characteristics, an... - [Complementary User Entity Controls: The Half You Must Do](https://governancedocs.com/complementary-user-entity-controls/): A SOC 2 report lists controls the provider assumes you operate. Nobody tests them. How to extract, own and evidence comp... - [Compliance Consultant Certifications: 6 Essential Credentials](https://governancedocs.com/compliance-consultant-certifications/): Compliance consultant certifications: Lead Auditor, CISA, CISSP, CISM/CRISC, CCEP, CIPP/E — what each proves, the issuer... - [Compliance Consulting Practice: A Clear Guide to 6 Decisions](https://governancedocs.com/compliance-consulting-practice/): The 6 structural decisions behind a compliance consulting practice: framework breadth, delivery model, documentation, in... - [Compliance Consulting Rates in 2026: The Complete Breakdown](https://governancedocs.com/compliance-consulting-rates/): Compliance consulting rates in 2026: day rates by seniority and market, fixed-fee ranges for ISO 27001, SOC 2, GDPR and... - [Compliance Culture: The Complete ISO 37301 Guide to the 5 Signals](https://governancedocs.com/compliance-culture/): Compliance culture under ISO 37301: the definition (3.28), where the requirement sits, the 5 signals an auditor reads, l... - [Compliance Function: The Complete ISO 37301 Guide to Independence](https://governancedocs.com/compliance-function/): The compliance function under ISO 37301: what 3.23 requires, 4 tests of independence, sizing, what it owns and does not,... - [Compliance Monitoring: A Clear ISO 37301 Guide for 2026](https://governancedocs.com/compliance-monitoring/): Compliance monitoring tests whether controls work now. How it differs from audit, the 6 steps to a monitoring plan, and... - [Compliance Obligations Register: A Clear Guide for ISO 37301](https://governancedocs.com/compliance-obligations-register/): A compliance obligations register for ISO 37301 clause 4.5: what counts as an obligation, the 8 columns it needs, and ho... - [Compliance Risk Assessment: A Complete Guide to ISO 37301 Cl. 4.6](https://governancedocs.com/compliance-risk-assessment/): Compliance risk assessment under ISO 37301 clause 4.6: build it from the obligations register, defensible criteria, cont... - [Consent Manager: A Clear Guide to DPDP Rule 4 in 2026](https://governancedocs.com/dpdp-consent-manager/): A consent manager is India's registered consent intermediary, and Rule 4 is the first DPDP deadline. The bar, the duties... - [Cookie Consent: 6 Proven Rules Article 5(3) Sets](https://governancedocs.com/cookie-consent/): The rule never says cookies and never says personal data. What Article 5(3) covers, the two exemptions read literally, a... - [Coordinated Vulnerability Disclosure: 7 Essential CRA Steps](https://governancedocs.com/coordinated-vulnerability-disclosure/): The CRA requires you to put in place and enforce a CVD policy. What Annex I Part II(5), Article 13(8), Article 13(17) an... - [Corrective Action Program: A Clear NQA-1 Guide for 2026](https://governancedocs.com/corrective-action-program/): A corrective action program turns on one classification decision. What conditions adverse to quality require, what signi... - [COSO 17 Principles: A Clear Guide to the 5 Components](https://governancedocs.com/coso-17-principles/): The COSO 17 principles listed by component, plus the present-and-functioning test, what counts as a major deficiency, an... - [COSO: Two Frameworks, and the New Generative AI Guidance](https://governancedocs.com/coso-framework/): COSO explained — the 2013 internal control framework, the 2017 ERM framework, and the supplemental guidance on sustainab... - [Counterfeit Parts Prevention: A Complete AS9100 8.1.4 Guide (2026)](https://governancedocs.com/as9100-counterfeit-parts/): Counterfeit parts prevention under AS9100 8.1.4: the 7 process elements, the sourcing hierarchy, detection at receipt, s... - [CRA Conformity Assessment: Do You Need a Notified Body?](https://governancedocs.com/cra-conformity-assessment/): No harmonised standard has been cited under the CRA, so Article 32(2) currently sends every Annex III product to a notif... - [CRA Penalties: The 3 Fine Tiers up to €15 Million Explained](https://governancedocs.com/cra-penalties/): CRA penalties under Article 64: EUR 15m/2.5%, 10m/2% and 5m/1% tiers, what each attaches to, the SME and open-source exe... - [CRA Product Classification: Default, Class I, Class II, Critical](https://governancedocs.com/cra-classification/): Classification decides whether you need a notified body. Article 7(1) contains the two rules that settle most cases, inc... - [Critical ICT Third-Party Providers: A Clear DORA Guide for 2026](https://governancedocs.com/critical-ict-third-party-providers/): Critical ICT third-party providers under DORA: the 4 designation criteria, how a Lead Overseer is chosen, and the 12-mon... - [Critical Limits in HACCP: 6 Essential Rules for Setting Them](https://governancedocs.com/haccp-critical-limits/): Critical limits explained: the Codex definition, limit vs operating limit, where the numbers come from, 4-part validatio... - [Critical Value Reporting: Getting the Result to Someone Who Can Act](https://governancedocs.com/critical-value-reporting/): Building a critical value list that works, the read-back, escalation when nobody answers, and the one measure that shows... - [Crypto-Asset White Paper: A Clear Guide to the 9 MiCA Parts](https://governancedocs.com/crypto-asset-white-paper/): A crypto-asset white paper under MiCA: when it is required, the 9 Annex I parts, the mandatory statements, notification,... - [CSA STAR: The Levels, Valid-AI-ted and STAR for AI](https://governancedocs.com/csa-star/): CSA STAR explained — the Cloud Controls Matrix, the free Level 1 self-assessment, Valid-AI-ted scoring, and the new STAR... - [Customer-Specific Requirements: A Clear Guide for 10 OEMs](https://governancedocs.com/customer-specific-requirements/): 10 OEMs publish customer-specific requirements via IATF. The matrix that makes CSRs auditable, handling conflicts, and w... - [Cyber Essentials Certification: The Five Controls](https://governancedocs.com/cyber-essentials-certification/): Cyber Essentials certification explained: the five technical controls, why scope decides the outcome, and the four failu... - [Cyber Essentials Plus: A Clear Guide to the 2026 Audit](https://governancedocs.com/cyber-essentials-plus/): Cyber Essentials Plus tests the same 5 controls independently. What the 2026 Danzell update changed, the new auto-fail r... - [Cyber Essentials Questionnaire: A Clear 2026 Danzell Guide](https://governancedocs.com/cyber-essentials-questionnaire/): The Cyber Essentials questionnaire is the whole assessment. What Danzell changed in April 2026, the auto-fail answers, a... - [Cybersecurity Governance: The Definitive 2026 Board Guide](https://governancedocs.com/cybersecurity-governance/): Cybersecurity governance after NIS2: what boards must approve, why NIST CSF 2.0 added a 6th function, and the 6 artefact... - [Cybersecurity Metrics: A Clear Guide to the 4 Types That Matter](https://governancedocs.com/cybersecurity-metrics/): Cybersecurity metrics that survive scrutiny: the 4 measure types in NIST SP 800-55, the 10 fields that document one, and... - [Cybersecurity Risk Register: A Clear Guide to the 10 Elements](https://governancedocs.com/cybersecurity-risk-register/): A cybersecurity risk register in 10 elements, from NIST IR 8286 Revision 1 - what each field is for, current vs inherent... - [Data (Use and Access) Act 2025: Every Data Protection Change, Dated](https://governancedocs.com/data-use-and-access-act-2025/): Data (Use and Access) Act 2025 summary: each amendment to the UK GDPR, the DPA 2018 and PECR, the date it commenced, who... - [Data Classification: 6 Proven Steps for ISO 27001](https://governancedocs.com/data-classification/): Most schemes classify confidentiality only and have no rule for mixed data. What FIPS 199 and ISO 27001 Annex A 5.12 and... - [Data Governance and the DMBOK: What It Is, and Is Not](https://governancedocs.com/data-governance/): Data governance explained through the DAMA-DMBOK — what the framework covers, the boundaries DAMA sets explicitly, and t... - [Data Protection Complaints Procedure: The Section 164A Duty From June 2026](https://governancedocs.com/data-protection-complaints-procedure/): Data protection complaints procedure under DPA 2018 s.164A: facilitate complaints, acknowledge within 30 days, respond w... - [Data Protection Officer: When Article 37 Makes One Mandatory](https://governancedocs.com/data-protection-officer/): A DPO is mandatory in three cases, and all of them turn on core activities. What Article 38 protects, and why most obvio... - [Data Quality Dimensions: A Clear Guide to the 6 DAMA Measures](https://governancedocs.com/data-quality-dimensions/): The 6 DAMA data quality dimensions defined, with the measure for each - plus why validity and accuracy differ and which... - [Data Steward: A Clear Guide to the 4 Governance Roles](https://governancedocs.com/data-steward/): A data steward does the work a data owner authorises. The 4 roles separated, what stewardship involves weekly, and why t... - [Data Subject Access Request: The Copy Is Only Half of It](https://governancedocs.com/data-subject-access-request/): Article 15 asks for the data plus eight further items. The extension you must claim inside month one, the two narrow fee... - [Decision Rules and Statements of Conformity Under ISO 17025](https://governancedocs.com/decision-rules/): You measure 9.8 against a maximum of 10.0, with an uncertainty of 0.4. Does it pass? It depends on a rule that should ha... - [DORA Exit Strategy: 6 Proven Steps for Article 28(8)](https://governancedocs.com/dora-exit-strategy/): Article 28(8) requires exit plans that are documented and tested, and Article 30(3)(f) requires a mandatory transition p... - [DORA Incident Reporting: A Clear Guide to the 4-Hour Rule](https://governancedocs.com/dora-incident-reporting/): DORA incident reporting has 3 deadlines: 4 hours from classification, 72 hours for the intermediate report, one month fo... - [DORA Subcontracting: A Clear Guide to the 2025 RTS](https://governancedocs.com/dora-subcontracting/): DORA subcontracting under Regulation (EU) 2025/532: what the RTS requires, why the chain is now the unit of analysis, an... - [Double Materiality Assessment: A Clear Guide in 6 Steps](https://governancedocs.com/double-materiality-assessment/): A double materiality assessment in 6 steps, what the 2026 simplified ESRS changed about running one, and the 4 mistakes... - [DPDP Rules 2025: A Clear Guide to the 2 Compliance Deadlines](https://governancedocs.com/dpdp-rules-2025/): The DPDP Rules 2025 commence in 3 tranches: 13 Nov 2025, 13 Nov 2026 and 13 May 2027. What each rule requires and which... - [DPIA: What GDPR Article 35 Actually Requires](https://governancedocs.com/dpia/): A DPIA has four mandatory elements and two of them get skipped. What Article 35 requires, when Article 36 consultation b... - [Driver Fatigue: The Complete ISO 39001 Guide to Managing It (2026)](https://governancedocs.com/driver-fatigue/): Driver fatigue under ISO 39001: the EU 561/2006 and 49 CFR 395 legal floor, what clause 6.3 expects beyond it, the cause... - [ECC 2-2024: A Clear Guide to All 4 Domains](https://governancedocs.com/ecc-2-2024/): ECC 2-2024 replaced ECC-1:2018 and deleted a whole domain. The 4 domains, 109 controls, where the ICS controls went, and... - [Energy Baseline: A Complete ISO 50001 Guide to Clause 6.5 (2026)](https://governancedocs.com/energy-baseline/): The energy baseline under ISO 50001 clause 6.5: the period, the 3 forms, normalisation with a worked regression example,... - [Energy Performance Indicators: A Clear Guide to 4 ISO 50001 Clauses](https://governancedocs.com/energy-performance-indicators/): Energy performance indicators under ISO 50001: clauses 6.3 to 6.6, normalization for relevant variables, and when you ma... - [Energy Review: A Clear Guide to ISO 50001 Clause 6.3](https://governancedocs.com/energy-review/): The energy review drives every other ISO 50001 clause. The 3 questions it answers, how to choose significant energy uses... - [Entity-Level Controls: A Clear Guide to the 3 Types](https://governancedocs.com/entity-level-controls/): Entity-level controls come in 3 kinds, and only one can carry a specific risk on its own. How precision decides what the... - [EOMS Policy: The Complete ISO 21001 Guide to the 11 Principles](https://governancedocs.com/eoms-policy/): EOMS policy under ISO 21001:2025 clause 5.2: 7 harmonized requirements, the 11 EOMS principles as testable commitments,... - [Ergonomic Risk Assessment: A Clear Guide to the 4 Tools](https://governancedocs.com/ergonomic-risk-assessment/): Ergonomic risk assessment with RULA, REBA, the NIOSH lifting equation and MAC: what each measures, which task it fits, a... - [ESG KPIs: A Clear Guide to the 12 Metrics Boards Ask For](https://governancedocs.com/esg-kpis/): The 12 ESG KPIs boards ask for across E, S and G, each with its unit and source standard (ESRS, ISSB, GRI), how material... - [ESG Policy: A Clear Guide to the 6 Sections](https://governancedocs.com/esg-policy/): An ESG policy in 6 sections — scope, material topics, dated commitments, accountability, implementation and KPIs, review... - [ESG Reporting in 2026: What the EU Simplification Changed](https://governancedocs.com/esg-reporting/): ESG reporting after the EU Omnibus — stop-the-clock, the ESRS quick fix, the value chain cap and VSME, read from the Com... - [ESG vs CSR: A Clear Guide to the 4 Differences in 2026](https://governancedocs.com/esg-vs-csr/): ESG vs CSR on 4 differences — audience, basis, measurement, consequence — where a CSR program becomes an ESG obligation,... - [ESG: Turning Commitments into Governance Outcomes](https://governancedocs.com/esg-governance/): Achieving the best governance outcomes is essential for organizations committed to ESG, as it builds trust, drives trans... - [EU CRA: The Cyber Resilience Act Explained](https://governancedocs.com/eu-cra/): What Regulation (EU) 2024/2847 requires, the four dates that matter, and the provisions manufacturers reliably get wrong... - [EU IVDR: Regulation (EU) 2017/746 Explained](https://governancedocs.com/eu-ivdr/): Most guides to the EU IVDR are medical device guides with the words changed. This guide covers what Regulation (EU) 2017... - [EU MDR Transition Deadlines and the Conditions That Closed](https://governancedocs.com/eu-mdr-transition-deadlines/): The EU MDR transition runs to 31 December 2027 and 2028 — but the extension was conditional, and two conditions had dead... - [EU MDR: Regulation (EU) 2017/745 Explained](https://governancedocs.com/eu-mdr/): The EU MDR has been amended eight times and consolidated eight times. This guide covers what Regulation (EU) 2017/745 re... - [EUDAMED Registration: What Became Mandatory in May 2026](https://governancedocs.com/eudamed-registration/): Four EUDAMED modules became mandatory on 28 May 2026. This guide covers actor and device registration, the Single Regist... - [Evaluation of Compliance: A Clear Guide to ISO 45001 9.1.2](https://governancedocs.com/iso-45001-evaluation-of-compliance/): The evaluation of compliance under ISO 45001 clause 9.1.2: the 5 obligations, how it differs from an internal audit, and... - [Experience Level Agreements: A Complete Guide](https://governancedocs.com/experience-level-agreement/): An experience level agreement measures what using a service feels like. The metrics that work, paired with the performan... - [External Providers: A Clear Guide to ISO 9001 Clause 8.4](https://governancedocs.com/iso-9001-external-providers/): External providers under ISO 9001 clause 8.4: the 3 sub-clauses, how to band control by effect on conformity, and the ou... - [Facilitation Payments: The Complete Guide to 5 Laws and ISO 37001](https://governancedocs.com/facilitation-payments/): Facilitation payments in 5 laws — UK Bribery Act, U.S. FCPA, Canada, Australia, Brazil — what each says, what ISO 37001... - [Facility Condition Assessment: A Complete Guide to the FCI (2026)](https://governancedocs.com/facility-condition-assessment/): Facility condition assessment and the FCI: what is surveyed, ASTM E2018 as the baseline, FCI = deferred maintenance ÷ re... - [Facility Management KPIs: A Clear Guide to the 4 Groups](https://governancedocs.com/facility-management-kpis/): Facility management KPIs in 4 groups, what ISO 41001 clause 9.1 asks you to determine, and how to write a measure that s... - [Facility Management SLA: A Clear Guide to the 5 Elements](https://governancedocs.com/facility-management-sla/): A facility management SLA needs 5 elements, and the last 2 are usually missing. Writing service levels that mean somethi... - [Facility Management Strategy: The Complete ISO 41001 Guide (2026)](https://governancedocs.com/facility-management-strategy/): Facility management strategy per ISO 41011 and ISO 41014: the inputs, the 6 sections, how it differs from the strategic... - [FedRAMP ATO: A Clear Guide to the 5 Agency Steps in 2026](https://governancedocs.com/fedramp-ato/): A FedRAMP ATO is the agency's risk decision, not FedRAMP's. The 5 steps of initial agency authorization in 2026, and the... - [FedRAMP Authorization: What FedRAMP 20x Changed](https://governancedocs.com/fedramp-authorization/): FedRAMP authorization has changed. 20x is past the pilots and in wide-scale adoption, Key Security Indicators replaced y... - [FedRAMP Compliance Checklist: The Best 8 Steps for 2027](https://governancedocs.com/fedramp-compliance-checklist/): A FedRAMP compliance checklist for 2026: the 8 steps in order, the Rev5 and 20x paths, and the 3 dates that decide which... - [FedRAMP SSP: A Clear Guide to the 2 Documents That Replaced It](https://governancedocs.com/fedramp-ssp/): The FedRAMP SSP was retired in 2026. What replaced it: the Certification Package Overview and the Security Decision Reco... - [First Article Inspection: A Clear Guide to the 3 AS9102 Forms](https://governancedocs.com/first-article-inspection/): A first article inspection proves the process, not the part. The 3 AS9102 forms, what triggers a re-accomplishment, and... - [Fixed Fee vs Time and Materials: A Clear Guide for Consultants](https://governancedocs.com/fixed-fee-vs-time-and-materials/): Fixed fee vs time and materials for compliance consultants: the 6 differences, which engagements suit each, the hybrids,... - [Fleet Safety Policy: The Complete Guide to the 7 Sections (2026)](https://governancedocs.com/fleet-safety-policy/): Fleet safety policy under ISO 39001 clause 5.2: the 7 sections and the rules in each — drivers, vehicles, journeys, fitn... - [Fourth-Party Risk: Managing the Subcontractor You Never Contracted With (2026)](https://governancedocs.com/fourth-party-risk/): Fourth-party risk explained: the subcontractor you never contracted with, the regimes that reach it (DORA, GDPR, HIPAA),... - [Fundamental Rights Impact Assessment: 7 Proven Steps for Article 27](https://governancedocs.com/fundamental-rights-impact-assessment/): Article 27 falls on deployers, not providers. Who owes a FRIA, the six required elements, the duty to notify the regulat... - [Gantt Chart: A Clear Guide to All 6 Elements](https://governancedocs.com/gantt-chart/): A Gantt chart needs 6 elements to be a plan rather than a drawing. Dependencies, baselines, the critical path, and the 5... - [GDPR vs HIPAA: The Differences That Actually Matter](https://governancedocs.com/gdpr-vs-hipaa/): GDPR vs HIPAA compared: scope, who they bind, consent and lawful basis, breach deadlines and penalties — and what to do... - [Generative AI Profile: A Clear Guide to the 12 NIST AI Risks](https://governancedocs.com/nist-ai-rmf-generative-ai-profile/): The Generative AI Profile, NIST AI 600-1, names 12 risks unique to or exacerbated by generative AI, with suggested actio... - [Gifts and Hospitality: A Clear ISO 37001 Guide for 2026](https://governancedocs.com/gifts-and-hospitality-policy/): A gifts and hospitality policy has to fix 5 things a salesperson can apply at dinner. What ISO 37001:2025 requires, and... - [GovRAMP Status: A Clear Guide to All 8 Levels in 2026](https://governancedocs.com/govramp-status-levels/): GovRAMP status runs across 8 levels in 2 families. What each verified status means, what the 2026 snapshot rules changed... - [Greenwashing: The EU Rules That Apply From 27 September 2026](https://governancedocs.com/greenwashing/): EU greenwashing rules from 27 September 2026 under Directive 2024/825: Annex I bans on generic claims, self-made labels... - [HACCP Certification Cost: A Realistic 2026 Breakdown](https://governancedocs.com/haccp-certification-cost/): HACCP certification cost for people ($100–1,200 training) and sites: audit days × $1,200–2,000/day, $4,200–28,000 in fee... - [HACCP Hazard Analysis: A Complete Worksheet Guide (2026)](https://governancedocs.com/haccp-hazard-analysis/): HACCP hazard analysis in 2 stages: identification and evaluation, a 9-column worksheet with a worked row, the categories... - [HACCP Plan: A Clear Guide to the 12 Codex Steps](https://governancedocs.com/haccp-plan/): A HACCP plan is built from the 12 Codex steps - 5 preliminary steps then the 7 principles. What each step produces, and... - [HACCP Team: 5 Essential Roles and the Training Rules (2026)](https://governancedocs.com/haccp-team/): The HACCP team: 5 roles, who must hold which qualification (9 CFR 417.7, PCQI, EU 852/2004), how a small business assemb... - [HACCP Validation vs Verification: A Clear 2026 Guide](https://governancedocs.com/haccp-validation-vs-verification/): HACCP validation proves a control measure can work; verification proves it is working. The 3 terms separated, the eviden... - [HACCP vs HARPC: 8 Essential FSMA Differences Explained (2026)](https://governancedocs.com/haccp-vs-harpc/): HACCP vs HARPC on 8 points from 21 CFR 117 and 9 CFR 417: hazard analysis, controls beyond CCPs, PCQI, recall plan, rean... - [HACCP: The 7 Principles of Food Safety](https://governancedocs.com/haccp-principles/): Mastering the 7 must-have HACCP principles is key to ensuring food safety from farm to table, helping prevent hazards be... - [Hard FM vs Soft FM: 6 Essential Differences Explained (2026)](https://governancedocs.com/hard-fm-vs-soft-fm/): Hard FM vs soft FM: what belongs in each, the 6 differences that change how you manage them, how ISO 41001 clause 8.3 in... - [Hazardous Situation vs Hazard vs Harm: The Clear ISO 14971 Guide](https://governancedocs.com/hazardous-situation/): Hazardous situation vs hazard vs harm in ISO 14971:2019: the 3 definitions, the sequence-of-events model with 5 worked e... - [HIPAA Notice of Privacy Practices: What Changed in February 2026](https://governancedocs.com/hipaa-notice-of-privacy-practices/): What a HIPAA notice of privacy practices must contain, the 42 CFR Part 2 update that took effect on 16 February 2026, an... - [HIPAA Risk Assessment Template: What It Must Contain](https://governancedocs.com/hipaa-risk-assessment-template/): What a HIPAA risk assessment template must contain to satisfy the Security Rule risk analysis requirement at 45 CFR 164.... - [HIPAA Safeguards: Addressable Does Not Mean Optional](https://governancedocs.com/hipaa-safeguards/): The HIPAA Security Rule labels specifications Required or Addressable. Addressable means assess, then implement or docum... - [HITRUST Assessments: A Clear Guide to e1, i1 and r2](https://governancedocs.com/hitrust-assessments/): The 3 HITRUST assessments compared: 43 controls at e1, 182 at i1, a tailored set at r2 - with the validity periods and t... - [HITRUST Scoring: A Clear Guide to the 5 Maturity Levels](https://governancedocs.com/hitrust-scoring/): HITRUST scoring evaluates every requirement at 5 maturity levels, weighted so documentation alone cannot certify you. Wh... - [How to Implement GDPR: A Ten-Step Plan](https://governancedocs.com/gdpr-implementation-guide/): A practical GDPR implementation plan in ten steps: records of processing, lawful basis, DPIAs, data subject rights and b... - [How to Implement HIPAA: A Ten-Step Plan](https://governancedocs.com/hipaa-implementation-guide/): A practical HIPAA implementation plan in ten steps: risk analysis, policies, business associates, training and breach re... - [How to Implement ISO 13485: A Ten-Step Plan](https://governancedocs.com/iso-13485-implementation-guide/): A practical ISO 13485 implementation plan in ten steps, with realistic timings, what QMSR changed for US manufacturers,... - [How to Implement ISO 14001: A Ten-Step Plan](https://governancedocs.com/iso-14001-implementation-guide/): A practical ISO 14001 implementation plan in ten steps for the 2026 edition, with realistic timings and the three steps... - [How to Implement ISO 20000: A Ten-Step Plan](https://governancedocs.com/iso-20000-implementation-guide/): A practical ISO/IEC 20000-1 implementation plan in ten steps: service portfolio, SLAs, the service management processes... - [How to Implement ISO 22301: A Ten-Step Plan](https://governancedocs.com/iso-22301-implementation-guide/): A practical ISO 22301 implementation plan in ten steps, with realistic timings, who must be involved, and the three step... - [How to Implement ISO 27001: A Ten-Step Plan](https://governancedocs.com/iso-27001-implementation-guide/): A practical ISO 27001 implementation plan in ten steps for the 2022 edition, with realistic timings and the three steps... - [How to Implement ISO 42001: A Ten-Step Plan](https://governancedocs.com/iso-42001-implementation-guide/): A practical ISO 42001 implementation plan in ten steps: AI inventory, risk assessment, the AI system impact assessment i... - [How to Implement ISO 45001: A Ten-Step Plan](https://governancedocs.com/iso-45001-implementation-guide/): A practical ISO 45001 implementation plan in ten steps, with realistic timings, who needs to be involved, and the three... - [How to Implement ISO 9001: A Ten-Step Plan](https://governancedocs.com/iso-9001-implementation-guide/): A practical ISO 9001 implementation plan in ten steps, with realistic timings, and the three steps quality projects cons... - [IA9100: A Clear Guide to the 2026 AS9100 Revision](https://governancedocs.com/ia9100/): IA9100 is the new name for AS9100 and the first rewrite since Rev D. What the IAQG has published, what is expected to ch... - [IATF 16949 Core Tools: A Clear Guide to All 5 Manuals](https://governancedocs.com/iatf-16949-core-tools/): The 5 IATF 16949 core tools explained: APQP, Control Plan, PPAP, FMEA, MSA and SPC - the 2024 manual split, the OEM dead... - [IATF 16949 Second Edition: 5 Priorities and a Clear 2027 Timeline](https://governancedocs.com/iatf-16949-second-edition/): The IATF 16949 second edition is planned for mid-2027. The 5 priorities, the transition tied to ISO 9001, and what to do... - [IATF 16949: Quality Management for Automotive Suppliers](https://governancedocs.com/iatf-16949-compliance/): Achieving IATF 16949 compliance is key to unlocking top-tier quality and operational excellence in automotive manufactur... - [ICAAP: A Clear Guide to the 6 Building Blocks in 2026](https://governancedocs.com/icaap/): The ICAAP is the bank's own capital argument. The 6 building blocks, the 2 perspectives, what the 2026 SREP cycle change... - [ICT Concentration Risk: 6 Essential Checks Before You Sign](https://governancedocs.com/ict-concentration-risk/): Article 29 calls it a preliminary assessment, so it belongs in procurement. Substitutability, closely connected provider... - [IEC 31010: The Complete Guide to All 41 Risk Assessment Techniques](https://governancedocs.com/iec-31010/): IEC 31010:2019 explained: the 41 techniques in 10 categories, what changed from 2009, how clause 7 says to choose, the c... - [IMS Implementation: A Clear 7-Step Plan for 2026](https://governancedocs.com/ims-implementation/): IMS implementation in 7 steps: decide the integration level (IAF MD 11), map the clauses, build the common core once, ad... - [Inherent vs Residual Risk: The Complete 4-Column Register Guide](https://governancedocs.com/inherent-vs-residual-risk/): Inherent vs residual risk defined by COSO ERM and ISO 31000, the 4 register columns (inherent, current, residual, target... - [Integrated Management Review: A Clear Guide to One 12-Item Agenda](https://governancedocs.com/integrated-management-review/): One integrated management review for ISO 9001, 14001 and 45001 clause 9.3: the inputs each standard adds, a 12-item agen... - [Integrated Management System Manual: A Clear 2026 Guide](https://governancedocs.com/integrated-management-system-manual/): An integrated management system manual is optional and still worth writing. What it contains, how the harmonized structu... - [Integrated Management Systems: Combining ISO Standards](https://governancedocs.com/integrated-management-system/): An Integrated Management System is the must-have best solution for businesses looking to streamline operations and boost... - [International Data Transfers: Chapter V in Priority Order](https://governancedocs.com/international-data-transfers/): GDPR Chapter V has a strict order: adequacy, then safeguards, then situational derogations. Why the last route is design... - [Is ISO 45001 a Legal Requirement? The Clear Answer for 2026](https://governancedocs.com/is-iso-45001-a-legal-requirement/): Is ISO 45001 a legal requirement? No, in any country. But the OH&S law underneath it is mandatory. What actually applies... - [ISAE 3402 Explained: The Essential 2026 Guide vs SOC 1](https://governancedocs.com/isae-3402/): ISAE 3402 explained: the international SOC 1, the seven differences from AT-C 320 that change what management must do, d... - [ISO 13485 Certification Explained: A Clear, Essential Guide](https://governancedocs.com/iso-13485-certification/): ISO 13485 certification explained: the audit stages, realistic timeline and cost drivers, what a notified body actually... - [ISO 13485 Internal Audit: Checklist and Programme Guide](https://governancedocs.com/iso-13485-internal-audit-checklist/): How to plan and run an ISO 13485 internal audit: a risk-based programme, a clause 4 to 8 checklist, auditor independence... - [ISO 13485 Mandatory Documents and Records Explained](https://governancedocs.com/iso-13485-mandatory-documents/): Every document and record ISO 13485:2016 requires by name, clause by clause, including the quality manual and medical de... - [ISO 13485 Purchasing: A Clear Guide to Clause 7.4](https://governancedocs.com/iso-13485-purchasing/): ISO 13485 purchasing in 3 parts: supplier evaluation, purchasing information and verification - plus the change-notifica... - [ISO 13485 Risk Assessment Template: What It Must Contain](https://governancedocs.com/iso-13485-risk-assessment-template/): What an ISO 13485 risk assessment template needs to contain to satisfy clause 7.1 and ISO 14971: the fields, the scoring... - [ISO 13485 Risk Management and ISO 14971 Explained](https://governancedocs.com/iso-13485-risk-management/): How ISO 13485 risk management works across the product lifecycle, how ISO 14971 fits, and why treating risk as a single... - [ISO 13485 Templates: A Clear Guide to the Document Set](https://governancedocs.com/iso-13485-templates/): ISO 13485 templates are not an ISO 9001 set relabelled. The clause structure, the 4 documents unique to medical devices,... - [ISO 13485 vs ISO 9001: The Differences That Matter](https://governancedocs.com/iso-13485-vs-iso-9001/): ISO 13485 vs ISO 9001 compared clause by clause: why 13485 rejected Annex SL, where the documentation demands differ, an... - [ISO 13485: Quality Management for Medical Devices](https://governancedocs.com/iso-13485-quality-standard/): Achieving the ISO 13485 quality standard is essential for medical device manufacturers who want to ensure their products... - [ISO 14001 Certification: How the Process Actually Works](https://governancedocs.com/iso-14001-certification/): ISO 14001 certification explained under the 2026 edition: the two audit stages, realistic timings, what drives the cost,... - [ISO 14001 Internal Audit Checklist: Clause 4 to 10](https://governancedocs.com/iso-14001-internal-audit-checklist/): A clause-by-clause ISO 14001 internal audit checklist for the 2026 edition, how to build a risk-based programme under 9.... - [ISO 14001 Mandatory Documents and Records, Clause by Clause](https://governancedocs.com/iso-14001-mandatory-documents/): Every document and record ISO 14001 requires, clause by clause under the 2026 edition, plus the ones no clause names tha... - [ISO 14001: A Guide to Environmental Management](https://governancedocs.com/iso-14001-compliance/): Discover how ISO 14001 compliance can simplify your journey to sustainable business practices, helping you meet environm... - [ISO 14001:2026 Is Published — What Changed and What You Must Do](https://governancedocs.com/iso-14001-2026-transition/): ISO 14001:2015 is withdrawn. What changed in the 2026 fourth edition, the 36-month transition timeline, and a practical... - [ISO 14971 Risk Management Plan: A Clear Guide to Its Content](https://governancedocs.com/iso-14971-risk-management-plan/): The ISO 14971 risk management plan is written before the analysis and judged against everything after it. What it must c... - [ISO 14971 vs ISO 13485: 5 Clear Differences Explained (2026)](https://governancedocs.com/iso-14971-vs-iso-13485/): ISO 14971 vs ISO 13485: process vs QMS, device file vs certificate, every ISO 13485 clause that points at ISO 14971, the... - [ISO 14971: The Risk Management File and Where Files Break](https://governancedocs.com/iso-14971/): What ISO 14971:2019 requires, the four places risk management files reliably break, and one widely repeated error about... - [ISO 15189 Accreditation Cost: The Complete 2026 Breakdown](https://governancedocs.com/iso-15189-accreditation-cost/): ISO 15189 accreditation cost in 2026: UKAS's published rates (£1,796 to apply, ~£1,195 a day), initial assessment £10k–2... - [ISO 15189 vs ISO 17025: 7 Clear Differences for Laboratories](https://governancedocs.com/iso-15189-vs-iso-17025/): ISO 15189 vs ISO 17025: patients vs customers, the laboratory director, risk in governance, pre-examination vs sampling,... - [ISO 15189: Patients, Pre-examination and Where Medical Laboratories Lose Findings](https://governancedocs.com/iso-15189/): What ISO 15189:2022 requires, what the fourth edition changed, and the four areas where medical laboratories most often... - [ISO 15189:2022 Changes: A Clear Guide to the 15 Major Clauses](https://governancedocs.com/iso-15189-2022-changes/): ISO 15189:2022 changes: the 3 headline changes, the 15 clauses UKAS graded major, 4 new clauses, and what the 6 December... - [ISO 17025: Accreditation, Scope and Where Laboratories Lose Findings](https://governancedocs.com/iso-17025/): Laboratories are accredited, not certified — and only for a defined scope. What ISO 17025 requires, how Option A and Opt... - [ISO 20000 Certification: How the Process Actually Works](https://governancedocs.com/iso-20000-certification/): ISO 20000 certification explained: what ISO/IEC 20000-1 requires, the audit stages, realistic timings, and why an ITIL-m... - [ISO 20000 Internal Audit Checklist: Clause 4 to 10](https://governancedocs.com/iso-20000-internal-audit-checklist/): A clause-by-clause ISO 20000 internal audit checklist for ISO/IEC 20000-1:2018, how to build a risk-based programme, and... - [ISO 20000 Mandatory Documents and Records, Clause by Clause](https://governancedocs.com/iso-20000-mandatory-documents/): The documents and records ISO/IEC 20000-1:2018 requires, clause by clause, plus the ones no clause names that every serv... - [ISO 20000 vs ITIL: The Differences That Matter](https://governancedocs.com/iso-20000-vs-itil/): ISO 20000 vs ITIL compared: one is a certifiable standard, the other a body of practice. What each gives you, where they... - [ISO 20000: Aligning IT Service Management with the Business](https://governancedocs.com/iso-20000-alignment/): Discover how ISO 20000 alignment can transform your IT services into a powerful driver of business success—affordably an... - [ISO 21001 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-21001-certification-cost/): ISO 21001 certification cost: audit fees over the 3-year cycle, EOMS build, consultancy and staff time — $11,000 to $137... - [ISO 21001 Implementation: A Clear Guide in 6 Steps](https://governancedocs.com/iso-21001-implementation/): ISO 21001 implementation in 6 steps for a school or training provider: beneficiary mapping, learner needs, what to docum... - [ISO 21001 Internal Audit: A Clear Checklist for 2026](https://governancedocs.com/iso-21001-internal-audit-checklist/): An ISO 21001 internal audit has to test whether learning happened. What to check clause by clause, the 4 questions that... - [ISO 21001 Mandatory Documents: The Complete Clause-by-Clause List](https://governancedocs.com/iso-21001-mandatory-documents/): ISO 21001 mandatory documents under the 2025 edition: 16 clause requirements — 4 maintained, 12 retained — and the 6 edu... - [ISO 21001:2025: The Educational Management System Standard](https://governancedocs.com/iso-21001/): ISO 21001:2025 is now the current edition and the 2018 standard is withdrawn. What an educational organization managemen... - [ISO 22000 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-22000-certification-cost/): ISO 22000 certification cost: audit days from ISO 22003-1, fees by site size at $1,200–2,000/day, 30–60 staff days of pr... - [ISO 22000 Implementation: 10 Clear Steps in Order (2026)](https://governancedocs.com/iso-22000-implementation/): ISO 22000 implementation in 10 steps in dependency order: scope and team, gap, PRPs, preliminary steps, hazard analysis,... - [ISO 22000 Mandatory Documents: All 30 Explained by Clause (2026)](https://governancedocs.com/iso-22000-mandatory-documents/): ISO 22000 mandatory documents: all 30 items by clause — 9 in clauses 4–7, 18 in clause 8, 3 in clauses 9–10 — maintain v... - [ISO 22000 vs HACCP: 5 Clear Differences Explained (2026)](https://governancedocs.com/iso-22000-vs-haccp/): ISO 22000 vs HACCP on 5 differences: method vs management system, CCPs vs OPRPs, scope, legal vs certifiable status, aud... - [ISO 22000: How the Food Safety Management Standard Works](https://governancedocs.com/iso-22000-food-safety/): Discover how ISO 22000 food safety sets a gold standard by providing a clear, effective framework that keeps every step... - [ISO 22301 Assessment: The Complete Guide to the 4 Types (2026)](https://governancedocs.com/iso-22301-assessment/): ISO 22301 assessment: the 4 types — gap analysis, self-assessment, readiness, maturity — what each decides, when and who... - [ISO 22301 Certification: How the Process Actually Works](https://governancedocs.com/iso-22301-certification/): ISO 22301 certification explained: the two audit stages, why the exercise programme decides the outcome, realistic timin... - [ISO 22301 Gap Analysis: 6 Proven Rules for a Plan That Lands](https://governancedocs.com/iso-22301-gap-analysis/): Clause 8.2 carries everything built on top of it, and 8.5 cannot be closed on paper. How to weight a BCMS gap analysis s... - [ISO 22301 Internal Audit Checklist: Clause 4 to 10](https://governancedocs.com/iso-22301-internal-audit-checklist/): A clause-by-clause ISO 22301 internal audit checklist, how to build a risk-based audit programme under 9.2, and the find... - [ISO 22301 Mandatory Documents and Records, Clause by Clause](https://governancedocs.com/iso-22301-mandatory-documents/): Every document and record ISO 22301:2019 requires by name, clause by clause, plus the ones no clause names that no certi... - [ISO 22301 Maturity Assessment: The Complete Guide to 5 Levels](https://governancedocs.com/iso-22301-maturity-assessment/): ISO 22301 maturity assessment: 5 levels from initial to embedded, scored across 8 dimensions of the BCMS, the evidence p... - [ISO 22301 Readiness Assessment: 6 Proven Checks Before the Audit](https://governancedocs.com/iso-22301-readiness-assessment/): ISO 22301 readiness assessment: 6 checks on clauses 8.2–8.5, 9.2 and 9.3, what ready looks like, how stage 1 and 2 test... - [ISO 22301 Risk Assessment: A Clear Guide to Clause 8.2](https://governancedocs.com/iso-22301-risk-assessment/): The ISO 22301 risk assessment is the half of clause 8.2 that gets skipped. What it covers, how it differs from the BIA,... - [ISO 22301 Self-Assessment: A Clear Guide to Clauses 4–10 (2026)](https://governancedocs.com/iso-22301-self-assessment/): ISO 22301 self-assessment: 3 columns per requirement, clauses 4–10 with clause 8 scored at 8.1–8.6, the surprises in eac... - [ISO 22301 Templates: A Clear Guide to the BCMS Document Set](https://governancedocs.com/iso-22301-templates/): ISO 22301 templates split into a familiar governance layer and a much larger operational one. What clause 8 demands, and... - [ISO 22301: A Guide to Business Continuity Management](https://governancedocs.com/iso-22301-organizational-resilience/): Discover how ISO 22301 organizational resilience can transform your business by helping you proactively manage risks and... - [ISO 27001 Maturity Assessment: A Clear Guide to 6 Levels](https://governancedocs.com/iso-27001-maturity-assessment/): An ISO 27001 maturity assessment scores how well a control works, not whether it exists. The 6 levels, what to score, an... - [ISO 27001 Readiness Assessment: 6 Proven Checks](https://governancedocs.com/iso-27001-readiness-assessment/): A gap analysis asks what is missing. A readiness assessment asks whether you would pass Stage 2 — and three clauses cann... - [ISO 27001 Tools: Complete Guide to the 4 Categories](https://governancedocs.com/iso-27001-tools/): ISO 27001 tools range from a spreadsheet to a GRC platform. The 4 categories, what an assessment tool must cover, and ho... - [ISO 27001 vs ISO 22301: Which One Do You Actually Need?](https://governancedocs.com/iso-27001-vs-iso-22301/): ISO 27001 vs ISO 22301 compared: information security versus business continuity, where the two overlap, and why 27001's... - [ISO 27018: A Clear Guide to the 2025 Cloud Privacy Rules](https://governancedocs.com/iso-27018/): ISO 27018 applies in one narrow case: public cloud, personal data, acting as processor. The 6 obligations that carry com... - [ISO 27701 Controls: A Clear Guide to the 3 Annex A Tables](https://governancedocs.com/iso-27701-controls/): The ISO 27701 controls now sit in one Annex A with 3 tables - controller, processor and shared security controls. What e... - [ISO 28000 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-28000-certification-cost/): ISO 28000 certification cost: audit fees over 3 years, SMS build, consultancy, staff time — $13,000 to $149,000+ cash by... - [ISO 28000 Mandatory Documents: The Complete Clause-by-Clause List](https://governancedocs.com/iso-28000-mandatory-documents/): ISO 28000 mandatory documents under the 2022 edition: 15 clause requirements, the 5 security-specific ones (8.2–8.6), an... - [ISO 28000 vs C-TPAT: 4 Clear Differences Explained (2026)](https://governancedocs.com/iso-28000-vs-c-tpat/): ISO 28000 vs C-TPAT: a certifiable standard against a CBP customs programme — eligibility, prescription, assurance, what... - [ISO 28000: A Clear Guide to the 2022 Security Standard](https://governancedocs.com/iso-28000-2022/): ISO 28000 was retitled and widened in 2022. What the current edition requires, the 6 clause 8 requirements, and what to... - [ISO 31000 Risk Management: The 3 Components Explained](https://governancedocs.com/iso-31000-risk-management/): ISO 31000:2018 explained — the three components, why there is no certification, and the third edition now at committee d... - [ISO 31000 vs COSO ERM: 5 Clear Differences Explained (2026)](https://governancedocs.com/iso-31000-vs-coso-erm/): ISO 31000 vs COSO ERM on 5 differences: purpose and audience, structure, the risk process, strategy, origin — with an el... - [ISO 37001 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-37001-certification-cost/): ISO 37001 certification cost: audit fees over 3 years, ABMS build, due diligence, staff time — $18,000 to $360,000+ cash... - [ISO 37001 vs ISO 37301: 6 Clear Differences Explained (2026)](https://governancedocs.com/iso-37001-vs-iso-37301/): ISO 37001 vs ISO 37301: one risk in depth against all obligations in breadth — the 6 differences, the 2025 and 2026 edit... - [ISO 37001:2025 Anti-Bribery: What the New Edition Requires](https://governancedocs.com/iso-37001-anti-bribery/): ISO 37001:2025 is the current edition and the 2016 standard is withdrawn. What the anti-bribery management system requir... - [ISO 37301 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-37301-certification-cost/): ISO 37301 certification cost: audit fees over 3 years, CMS build, consultancy, legal input, staff time — $15,000 to $235... - [ISO 37301 vs ISO 19600: The Clear Guide to What Changed (2026)](https://governancedocs.com/iso-37301-vs-iso-19600/): ISO 37301 vs ISO 19600: guidelines to certifiable requirements — the 2 changes the foreword names, clause by clause, 5 r... - [ISO 37301: The Certifiable Compliance Management Standard](https://governancedocs.com/iso-37301/): ISO 37301:2021 explained — what a compliance management system must contain, the free 2024 climate amendment, and how it... - [ISO 39001 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-39001-certification-cost/): ISO 39001 certification cost: audit fees over 3 years, RTS system build, consultancy, staff time — $11,000 to $117,000+... - [ISO 39001 vs ISO 45001: 5 Clear Differences for Fleets (2026)](https://governancedocs.com/iso-39001-vs-iso-45001/): ISO 39001 vs ISO 45001: who is in scope, Safe System against the hierarchy of controls, worker participation, crash inve... - [ISO 39001: Road Traffic Safety Management Explained](https://governancedocs.com/iso-39001/): ISO 39001 explained — the Safe System approach, exposure and performance factors, the free 2024 amendment, and the revis... - [ISO 41001 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-41001-certification-cost/): ISO 41001 certification cost: audit fees over 3 years, FM system build, consultancy, staff time — $12,000 to $149,000+ c... - [ISO 41001 Mandatory Documents: The Complete Clause-by-Clause List](https://governancedocs.com/iso-41001-mandatory-documents/): ISO 41001 mandatory documents under the 2018 edition: 14 clause requirements, the 6 FM-specific ones (7.6, 8.2, 8.3, 10.... - [ISO 41001: The Facility Management Standard, and Its Revision](https://governancedocs.com/iso-41001/): ISO 41001:2018 is current and certifiable, but its replacement has reached DIS stage. What the standard requires, the 20... - [ISO 42001 Checklist: 7 Clauses, 38 Controls, 1 Big Mistake](https://governancedocs.com/iso-42001-checklist/): An ISO 42001 checklist covering both halves: the 7 mandatory clauses and the 38 Annex A controls, plus the Statement of... - [ISO 42001 Policy Template: A Clear Guide to the AI Set](https://governancedocs.com/iso-42001-policy-template/): An ISO 42001 policy template is rarely one document. The 7 policies an AI management system needs, the change-control ga... - [ISO 42001 vs the EU AI Act: Standard, Regulation, and How They Fit](https://governancedocs.com/iso-42001-vs-eu-ai-act/): ISO 42001 vs the EU AI Act: one is a voluntary certifiable standard, the other binding law. What each requires, how they... - [ISO 45001 Assessment: A Clear Guide to the 4 Types](https://governancedocs.com/iso-45001-assessment/): An ISO 45001 assessment can mean 4 things: self-assessment, gap analysis, internal audit or certification audit. What ea... - [ISO 45001 Certification: How the Process Actually Works](https://governancedocs.com/iso-45001-certification/): ISO 45001 certification explained end to end: the two audit stages, a realistic timeline, what drives the cost, and the... - [ISO 45001 Gap Analysis: What to Check Before You Certify](https://governancedocs.com/iso-45001-gap-analysis/): How to run an ISO 45001 gap analysis before certification: what to score, how to weight the gaps, and how to turn the ou... - [ISO 45001 Internal Audit Checklist: Clause 4 to 10](https://governancedocs.com/iso-45001-internal-audit-checklist/): A clause-by-clause ISO 45001 internal audit checklist, how to build a risk-based audit programme under 9.2, and the find... - [ISO 45001 Mandatory Documents and Records, Clause by Clause](https://governancedocs.com/iso-45001-mandatory-documents/): Every document and record ISO 45001:2018 requires by name, clause by clause, plus the ones that are not mandatory but ar... - [ISO 45001 Maturity Assessment: A Clear Guide to 5 Levels](https://governancedocs.com/iso-45001-maturity-assessment/): An ISO 45001 maturity assessment on 5 levels, reactive to generative, across 7 dimensions anchored to the clauses, with... - [ISO 45001 Readiness Assessment: 6 Proven Checks Before the Audit](https://governancedocs.com/iso-45001-readiness-assessment/): An ISO 45001 readiness assessment on the 6 checks that decide audits: worker participation, hazards and controls, compli... - [ISO 45001 Risk Assessment: Hazard Identification That Holds Up](https://governancedocs.com/iso-45001-risk-assessment/): How ISO 45001 risk assessment works under clause 6.1.2: hazard identification, the scoring method you must document, and... - [ISO 45001 Self-Assessment: A Clear Guide to Scoring Clauses 4–10](https://governancedocs.com/iso-45001-self-assessment/): An ISO 45001 self-assessment clause by clause: the 3 columns per requirement, where clauses 4–10 most often score No, an... - [ISO 45001: A Guide to Occupational Health & Safety](https://governancedocs.com/iso-45001-workplace-safety/): Discover how ISO 45001 workplace safety standards can transform your organization by creating a proactive, safer work en... - [ISO 50001 Certification Cost: A Realistic 2026 Breakdown](https://governancedocs.com/iso-50001-certification-cost/): ISO 50001 certification cost: audit days set by ISO 50003 from energy complexity × $1,200–2,500/day, $8,000–78,000 over... - [ISO 50001 Mandatory Documents: The Complete List of 20 (2026)](https://governancedocs.com/iso-50001-mandatory-documents/): ISO 50001 mandatory documents: all 20 by clause with maintain vs retain, the energy-specific set no other standard suppl... - [ISO 50001 vs ISO 14001: 5 Clear Differences Explained (2026)](https://governancedocs.com/iso-50001-vs-iso-14001/): ISO 50001 vs ISO 14001: shared clauses, different demands — 10 points compared, the 5 differences that decide the work,... - [ISO 50001: The Standard Held Still, the Family Did Not](https://governancedocs.com/iso-50001/): ISO 50001:2018 is confirmed and stable, but ISO 50100:2026 and the rebuilt ISO 50002 audit series changed the landscape... - [ISO 55001 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-55001-certification-cost/): ISO 55001 certification cost: $15k–40k first year for a single-site portfolio, 4–10 audit days, why the asset register a... - [ISO 55001:2024: The Asset Management Standard, Rewritten](https://governancedocs.com/iso-55001-2024/): ISO 55001:2024 replaced the 2014 edition in July 2024. What the asset management system requires, why the SAMP matters m... - [ISO 9001 Change Management: What the Template Must Contain](https://governancedocs.com/iso-9001-change-management-template/): What an ISO 9001 change management template must contain to satisfy clause 6.3 and change control in clause 8.5 — the fi... - [ISO 9001 Design and Development: The Records Clause 8.3 Requires](https://governancedocs.com/iso-9001-design-and-development-templates/): What ISO 9001 design and development templates must capture under clause 8.3 — planning, inputs, controls, outputs and c... - [ISO 9001 Gap Analysis: What to Check Before You Certify](https://governancedocs.com/iso-9001-gap-analysis/): How to run an ISO 9001 gap analysis before certification: what to score, how to weight the gaps by lead time, and how to... - [ISO 9001 Procedures and Forms: What a Working QMS Actually Contains](https://governancedocs.com/iso-9001-procedures-and-forms/): The ISO 9001 procedures and forms a working quality management system contains, clause by clause — including the ones no... - [ISO 9001:2026 Is Published: What Changed and How to Transition](https://governancedocs.com/iso-9001-2026-transition/): ISO 9001:2026 is published and replaces ISO 9001:2015. The six changes, the clause-by-clause map, the transition period,... - [ISO Clause 10: Improvement Explained](https://governancedocs.com/iso-clause-10-improvement/): What clause 10 of the ISO harmonized structure requires, why the sub-clause numbers differ between standards, and correc... - [ISO Clause 4: Context of the Organization Explained](https://governancedocs.com/iso-clause-4-context-of-the-organization/): What clause 4 of the ISO harmonized structure requires: context, interested parties, scope and processes, including the... - [ISO Clause 5: Leadership Explained](https://governancedocs.com/iso-clause-5-leadership/): What clause 5 of the ISO harmonized structure requires: leadership and commitment, policy, and roles, responsibilities a... - [ISO Clause 6: Planning Explained](https://governancedocs.com/iso-clause-6-planning/): What clause 6 of the ISO harmonized structure requires: risks and opportunities, measurable objectives, and the 2021 add... - [ISO Clause 7: Support Explained](https://governancedocs.com/iso-clause-7-support/): What clause 7 of the ISO harmonized structure requires: resources, competence, awareness, communication and documented i... - [ISO Clause 8: Operation Explained](https://governancedocs.com/iso-clause-8-operation/): What clause 8 of the ISO harmonized structure requires, and how far it expands in ISO 9001, ISO 27001, ISO 45001, ISO 22... - [ISO Clause 9: Performance Evaluation Explained](https://governancedocs.com/iso-clause-9-performance-evaluation/): What clause 9 of the ISO harmonized structure requires: monitoring and measurement, risk-based internal audit, and manag... - [ISO Climate Change Amendment: 2 Sentences, 31 Standards, 1 Trap](https://governancedocs.com/iso-climate-change-amendment/): The ISO climate change amendment added 2 sentences to clauses 4.1 and 4.2 across 31 standards. What auditors want as evi... - [ISO/TR 24971: The Complete Guide to the ISO 14971 Guidance (2026)](https://governancedocs.com/iso-tr-24971/): ISO/TR 24971:2020 explained: what the guidance is and is not, what moved into it from ISO 14971:2007, clause-by-clause c... - [ITIL 4 in 2026: Still Current, But Version 5 Has Started](https://governancedocs.com/itil-4/): ITIL 4 explained, and where it stands now that ITIL (Version 5) is released — what carries over, what actually changed,... - [ITIL 4 to ITIL 5: What Needs Rewriting](https://governancedocs.com/itil-4-to-itil-5/): ITIL 4 to ITIL 5 means rewriting one document, not the set. What changes, what does not, and the sequence that saves the... - [ITIL 5 Explained: The Complete 2026 Guide](https://governancedocs.com/itil-5/): ITIL 5 changed the value chain, the practice categories and added AI governance. Here is what actually changed from ITIL... - [ITIL 5 Practices: All 34 and the 2 Categories](https://governancedocs.com/itil-5-practices/): ITIL 5 practices still number 34 with the same names. Three categories became two and five practices moved. The full lis... - [ITIL AI Capability Model: The 6 Capabilities](https://governancedocs.com/itil-ai-capability-model/): The ITIL AI Capability Model classifies AI by what it does across six capabilities, so oversight scales to function rath... - [ITIL Product and Service Lifecycle: 8 Activities](https://governancedocs.com/itil-product-and-service-lifecycle/): The ITIL product and service lifecycle has eight activities, not six. What each one does, why it is not a sequence, and... - [ITIL Value Stream Mapping: A Complete Guide](https://governancedocs.com/itil-value-stream-mapping/): ITIL value stream mapping in five steps, with the four time metrics that reveal why a stream is slow. Usually the waitin... - [IVDR Classification: Annex VIII, Seven Rules, Classes A to D](https://governancedocs.com/ivdr-classification/): IVDR classification decides whether a notified body is involved at all, which conformity route applies, and which transi... - [IVDR In-House Devices: The 9 Essential Article 5(5) Conditions](https://governancedocs.com/ivdr-in-house-devices/): IVDR in-house devices: the 9 Article 5(5) conditions, 7 applying since 26 May 2024 and condition (d) from 31 Dec 2030, A... - [IVDR Notified Body: The 4 Essential Routes and When You Need One](https://governancedocs.com/ivdr-notified-body/): IVDR notified body: who needs one under Article 48 (every class above A), the 4 routes, class D and companion diagnostic... - [IVDR Performance Evaluation: Scientific Validity, Analytical and Clinical Performance](https://governancedocs.com/ivdr-performance-evaluation/): IVDR performance evaluation has no medical device equivalent to borrow from. Article 56 requires three separate demonstr... - [IVDR Technical Documentation: 8 Essential Annex II and III Parts](https://governancedocs.com/ivdr-technical-documentation/): IVDR technical documentation under Article 10(4): the 8 parts, the assay evidence Section 6 demands — 3-lot stability, c... - [IVDR Transition Deadlines: The Conditions That End Them](https://governancedocs.com/ivdr-transition-deadlines/): The IVDR transition deadlines everyone can name — 31 December 2027, 2028 and 2029 — are the least dangerous dates in Art... - [IVDR vs IVDD: 8 Clear Differences Every IVD Maker Must Know](https://governancedocs.com/ivdr-vs-ivdd/): IVDR vs IVDD: lists became 7 rules and classes A–D, notified bodies for every class above A, 3-limb performance evaluati... - [Journey Risk Assessment: A Clear Guide to the 5 Factors](https://governancedocs.com/journey-risk-assessment/): A journey risk assessment weighs 5 factors, and the first is whether the trip is needed. Which journeys need one, and th... - [KRI Reporting: A Clear Guide to the 4 Core Fields](https://governancedocs.com/kri-reporting/): KRI reporting fails when indicators are picked for easy data. The 4 fields every KRI needs, RAG thresholds that hold, an... - [Laboratory Impartiality: 5 Essential ISO 17025 Clause 4.1 Rules](https://governancedocs.com/laboratory-impartiality/): Laboratory impartiality under ISO/IEC 17025:2017 clause 4.1: the 5 requirements, 8 sources of risk, the ongoing risk ass... - [Laboratory Quality Indicators: 8 Essential ISO 15189 Measures](https://governancedocs.com/laboratory-quality-indicators/): Laboratory quality indicators under ISO 15189:2022 clause 8.8.2: 8 measures across the pathway, how to define each so it... - [Layered Process Audit: A Clear IATF 16949 Guide to GM’s 9 Rules](https://governancedocs.com/layered-process-audit/): The layered process audit explained: CQI-8, GM's 9 requirements under 9.2.2.3, Stellantis's all-shift rule, and how it d... - [Learner Satisfaction: The Clear Guide to ISO 21001 Clause 9.1](https://governancedocs.com/learner-satisfaction/): Learner satisfaction under ISO 21001:2025 clause 9.1: 3 groups to measure — learners, other beneficiaries, staff — instr... - [Legitimate Interests Assessment: The Test and the Trap](https://governancedocs.com/legitimate-interests-assessment/): A legitimate interests assessment has three parts, one hard exclusion, and an Article 21 consequence most teams miss — i... - [MDR Harmonised Standards: What Is and Is Not on the List](https://governancedocs.com/mdr-harmonised-standards/): IEC 62304, IEC 62366-1 and EN ISO 20417 are not harmonised under the EU MDR. What a presumption of conformity actually g... - [MDR Technical Documentation: 8 Essential Annex II and III Parts](https://governancedocs.com/mdr-technical-documentation/): MDR technical documentation under Article 10(4): the 6 Annex II sections and 2 Annex III parts, what the notified body s... - [Measurement Uncertainty: How to Build a Budget That Holds Up](https://governancedocs.com/measurement-uncertainty/): A budget built from repeatability alone can understate uncertainty fourfold. How contributions are identified, converted... - [Method Validation: The 5 Essential ISO 17025 Clause 7.2 Records](https://governancedocs.com/method-validation/): Method validation under ISO/IEC 17025:2017 clause 7.2: verify vs validate, 9 performance characteristics, the 5 records... - [MiCA: The Grandfathering Period Has Now Expired Everywhere](https://governancedocs.com/mica-regulation/): MiCA grandfathering ended on 1 July 2026 in every Member State. What Article 143(3) allowed, what ESMA's register now sh... - [Multi-Framework Compliance: A Clear Guide to 4 Overlaps](https://governancedocs.com/multi-framework-compliance/): Multi-framework compliance done once: the 4 areas that genuinely overlap, what cannot be shared, and why the control map... - [NCA Cybersecurity Controls: A Clear Guide to All 7 Sets](https://governancedocs.com/nca-cybersecurity-controls/): The 7 NCA cybersecurity controls sets and their current editions, which apply to you, and why CSCC is Critical Systems r... - [NCA ECC Implementation: A Clear Guide in 6 Steps](https://governancedocs.com/nca-ecc-implementation/): NCA ECC implementation in 6 steps: scope, gap assessment, governance, remediation, internal review and assessment - plus... - [NIS2 Management Liability: Three Duties on Named People](https://governancedocs.com/nis2-management-liability/): NIS2 Article 20 makes management approve, oversee and be liable for cybersecurity measures — and Article 32(5) can bar a... - [NIST 800-171 Templates: Complete Rev 2 Document Set Guide](https://governancedocs.com/nist-800-171-templates/): NIST 800-171 templates must cite the right revision. Why CMMC still requires Rev 2 though NIST withdrew it, and the docu... - [NIST 800-53 Control Families: A Clear Guide to All 20](https://governancedocs.com/nist-800-53-control-families/): All 20 NIST 800-53 control families with their two-letter IDs, base controls versus enhancements, and the 3 families tha... - [NIST 800-53 Tailoring: A Clear Guide to the 5 Actions](https://governancedocs.com/nist-800-53-tailoring/): NIST 800-53 tailoring turns a baseline into a control set you can implement. The 5 tailoring actions, how overlays work,... - [NIST AI RMF Templates: A Clear Guide to All 4 Functions](https://governancedocs.com/nist-ai-rmf-templates/): NIST AI RMF templates are the question the framework will not answer. What Govern, Map, Measure and Manage each produce,... - [NIST AI RMF: The Four Functions, and the Revision Underway](https://governancedocs.com/nist-ai-rmf/): The NIST AI RMF is voluntary, widely referenced, and version 1.0 is being revised under the White House AI Action Plan.... - [NIST CSF Organizational Profile: A Clear Guide to the 5 Steps](https://governancedocs.com/nist-csf-organizational-profile/): A NIST CSF organizational profile in 5 steps from NIST SP 1301: scope, gather, create, analyze gaps, implement - plus th... - [NIST Risk Assessment Template: A Clear Guide to 4 Steps](https://governancedocs.com/nist-risk-assessment-template/): What a NIST risk assessment template must contain, the 4 steps of SP 800-30, and how it differs from a risk register and... - [NIST RMF: A Clear Guide to the 7 Steps of SP 800-37](https://governancedocs.com/nist-rmf/): The NIST RMF in 7 steps, from Prepare to Monitor, with the publication behind each - and how it differs from the Cyberse... - [NIST SP 800-171: Which Revision Your Contract Actually Names](https://governancedocs.com/nist-sp-800-171/): NIST published SP 800-171 Rev 3 in May 2024, but CMMC still runs on Rev 2 because 32 CFR 170.14 incorporates it by refer... - [NIST SP 800-30: The Three Tiers of Risk Assessment](https://governancedocs.com/nist-sp-800-30/): NIST SP 800-30 explained — the three tiers a risk assessment must run at, the four-step process, and why most registers... - [NIST SP 800-53: The Baselines, and Release 5.2.0](https://governancedocs.com/nist-sp-800-53/): NIST SP 800-53 Rev 5 now ships patch releases. What Release 5.2.0 added, why SP 800-53B matters more than the catalog, a... - [NQA-1 Graded Approach: A Clear Guide to Quality Levels in 2026](https://governancedocs.com/nqa-1-graded-approach/): The NQA-1 graded approach sits in Part I Requirement 2: defining quality levels, what varies by level, and the 5 questio... - [NQA-1 Software Quality Assurance: A Clear Subpart 2.7 Guide](https://governancedocs.com/nqa-1-software-quality-assurance/): NQA-1 software quality assurance under Subpart 2.7: what counts as software, the 7 programme elements, and why bought co... - [NQA-1 vs ISO 9001: A Clear Guide to the 6 Differences](https://governancedocs.com/nqa-1-vs-iso-9001/): NQA-1 vs ISO 9001 on 6 differences — legal status, certification, structure, design control, procurement, grading — with... - [NQA-1: Nuclear Quality Assurance and Which Edition Binds You](https://governancedocs.com/nqa-1/): ASME NQA-1 explained — what the standard covers, commercial grade dedication, and why the newest edition is not automati... - [OPRP vs CCP: A Clear Guide to Effective ISO 22000 Hazard Control](https://governancedocs.com/iso-22000-oprp-vs-ccp/): OPRP vs CCP under ISO 22000: a CCP has a measurable critical limit, an OPRP an action criterion. The 3-question test, an... - [OTCC: A Clear Guide to Saudi OT Cybersecurity in 2026](https://governancedocs.com/otcc-operational-technology-controls/): The OTCC absorbed the ECC's industrial control systems domain in 2024. What it covers, how it differs from IT security,... - [PCI DSS Documentation: The Complete 2026 Evidence Checklist](https://governancedocs.com/pci-dss-documentation/): PCI DSS documentation a QSA actually asks for: the 12 requirement areas, the 51 future-dated controls effective 31 March... - [PCI DSS Scope: A Clear Guide to All 3 Categories](https://governancedocs.com/pci-dss-scope/): How PCI DSS scope is decided: the 3 system categories in priority order, the annual confirmation under Requirement 12.5.... - [PCI DSS Validation: Who Requires It, and What to Do First](https://governancedocs.com/pci-dss-validation/): PCI SSC does not require PCI DSS validation — your acquirer or payment brand does. How scope really works, and why the P... - [PDPL Compliance Checklist: 20 Items in Order for Saudi Arabia](https://governancedocs.com/pdpl-compliance-checklist/): PDPL compliance checklist for Saudi Arabia: 20 items in dependency order, from SDAIA registration and legal basis to con... - [Phishing-Resistant MFA: The Complete 2026 Guide](https://governancedocs.com/phishing-resistant-mfa/): Phishing-resistant MFA under NIST SP 800-63B-4: which methods qualify, what AAL2 and AAL3 each require, and why synced p... - [Plan of Action and Milestones: A Clear POA&M Guide for 2026](https://governancedocs.com/plan-of-action-and-milestones/): A plan of action and milestones in 9 fields, where the POA&M is still required in 2026, where FedRAMP retired it, and th... - [PMO Charter: A Clear Guide to All 8 Sections](https://governancedocs.com/pmo-charter/): A PMO charter sets purpose, scope, authority and measures. The 3 PMO models, the 8 sections, and the 4 ways charters fai... - [Point-of-Care Testing Governance After ISO 22870](https://governancedocs.com/point-of-care-testing/): ISO 22870 is withdrawn and point-of-care testing now sits inside ISO 15189. Deployment, operator authorisation at ward s... - [Post-Production Information: A Clear ISO 14971 Guide](https://governancedocs.com/post-production-information/): Post-production information is where an ISO 14971 file meets reality. The 6 sources, the 3 outcomes of a review, and the... - [Pre-analytical Errors: Where Laboratory Mistakes Actually Happen](https://governancedocs.com/pre-analytical-errors/): What goes wrong before the examination starts, why the laboratory's controls are weakest exactly where the risk is highe... - [Product Recall: A Clear ISO 22000 Guide to Clause 8.9.5](https://governancedocs.com/product-recall-procedure/): A product recall procedure under ISO 22000 clause 8.9.5: withdrawal against recall, the 6 things it must contain, and th... - [Product Safety Under AS9100: 5 Essential Process Elements (2026)](https://governancedocs.com/as9100-product-safety/): Product safety under AS9100 clause 8.1.3: the definition, the 5 process elements with evidence, safety-critical items, e... - [Proficiency Testing: Coverage, Scores and What Follows a Bad Result](https://governancedocs.com/proficiency-testing/): Internal controls tell a laboratory it is consistent. Only comparison with others tells it whether it is right. Planning... - [Prohibited AI Practices: Article 5 Is Already In Force](https://governancedocs.com/prohibited-ai-practices/): The EU AI Act's eight prohibited AI practices have applied since 2 February 2025, with fines up to 7% of turnover. Each... - [Project Closure: A Clear Guide to 7 Essential Steps](https://governancedocs.com/project-closure/): Project closure in 7 steps: confirming delivery, formal acceptance, handover and hypercare, commercial closure, lessons... - [Project Initiation Document: A Clear PID Guide for 2026](https://governancedocs.com/project-initiation-document/): What goes in a project initiation document, how the PID differs from a project charter and business case, and the 9 sect... - [Project Status Report: A Clear Guide to 5 Sections](https://governancedocs.com/project-status-report/): A project status report in 5 sections. Defining RAG thresholds, stopping watermelon reporting, and the 5 things a status... - [PRRC: The 5 Essential Duties of the MDR Article 15 Role](https://governancedocs.com/prrc/): PRRC under MDR Article 15: the 2 qualification routes, the 5 duties, where the person must sit, micro and small enterpri... - [Pseudonymisation vs Anonymisation: 6 Proven GDPR Rules](https://governancedocs.com/pseudonymisation-vs-anonymisation/): Pseudonymised data is still personal data. What Article 4(5) requires, and the Recital 26 test — singling out, other per... - [Psychosocial Risk: 6 Proven Steps for ISO 45001](https://governancedocs.com/psychosocial-risk/): The Framework Directive named work pace and social relationships as hazards in 1989. ISO 45003 is guidance on method, an... - [QHSE Documentation: A Clear Guide to the 4 Tiers](https://governancedocs.com/qhse-documentation/): QHSE documentation works when the tiers are decided first: manual, procedures, work instructions, records. What belongs... - [QHSE KPIs: 12 Essential Indicators With Formulas (2026 Guide)](https://governancedocs.com/qhse-kpis/): QHSE KPIs: 12 indicators — 4 per discipline, 4 leading and 8 lagging — with formulas, sources and traps, the clause 9.1... - [QHSE Management Review: The 3-Standard Agenda in 10 Items (2026)](https://governancedocs.com/qhse-management-review/): The QHSE management review: the union of the three clause 9.3 input lists, the required outputs, a 10-item agenda, how t... - [QHSE Manager: 6 Essential Duties and the Competences (2026)](https://governancedocs.com/qhse-manager/): The QHSE manager role: what top management keeps under clause 5.1, the 6 duties across ISO 9001, ISO 14001 and ISO 45001... - [QHSE vs HSE: The Difference and 6 Questions That Decide (2026)](https://governancedocs.com/qhse-vs-hse/): QHSE vs HSE: what adding quality (ISO 9001) to health, safety and environment changes — owners, documents, audits — 6 qu... - [RAID Log: A Clear Guide to All 4 Elements](https://governancedocs.com/raid-log/): A RAID log covers risks, assumptions, issues and dependencies in one sheet. What each means, how to score them, and what... - [Recognised Legitimate Interests: The New UK GDPR Lawful Basis Explained](https://governancedocs.com/recognised-legitimate-interests/): Recognised legitimate interests under UK GDPR Article 6(1)(ea): the five Annex 1 purposes, no balancing test, the Articl... - [Records of Processing: Why the 250-Employee Exemption Fails](https://governancedocs.com/records-of-processing/): GDPR Article 30 records of processing: the exemption almost never applies, controllers and processors keep different rec... - [Register of Information: What DORA Article 28(3) Requires](https://governancedocs.com/register-of-information/): DORA's register of information carries four obligations, and the forward-looking ones get missed. All arrangements, pres... - [Risk Acceptability Criteria: The Complete ISO 14971 Matrix Guide](https://governancedocs.com/risk-acceptability-criteria/): Risk acceptability criteria under ISO 14971:2019: the 4.2 policy, 4.4 plan criteria, severity and probability scales, P1... - [Risk Appetite: A Clear Guide to the 3 Terms People Confuse](https://governancedocs.com/risk-appetite/): Risk appetite, tolerance and capacity answer 3 different questions, and ISO 31000 uses none of them. What a usable appet... - [Risk Criteria: A Clear Guide to Setting Them Under ISO 31000](https://governancedocs.com/risk-criteria/): Risk criteria under ISO 31000: the 6 decisions to make before assessing anything, how they differ from risk appetite, an... - [Risk Management Policy: The 8 Essential ISO 31000 Sections (2026)](https://governancedocs.com/risk-management-policy/): The risk management policy ISO 31000 clause 5.2 asks leadership to issue: 8 sections in 3–6 pages, what each must say, t... - [Road Traffic Safety Objectives: A Complete ISO 39001 Guide (2026)](https://governancedocs.com/road-traffic-safety-objectives/): Road traffic safety objectives under ISO 39001 clause 6.4: derive them from the performance factors, worked objectives p... - [RTO and RPO: A Clear Guide to the 4 Recovery Metrics](https://governancedocs.com/rto-and-rpo/): RTO and RPO measure different things, and 2 more metrics decide whether either is achievable. Where each number comes fr... - [RTS Performance Factors: A Clear Guide to ISO 39001 Clause 6.3](https://governancedocs.com/rts-performance-factors/): RTS performance factors under ISO 39001: exposure, intermediate and final safety outcomes - why a system measured only o... - [Safety Culture Assessment: A Clear Guide to the 5 Methods](https://governancedocs.com/safety-culture-assessment/): A safety culture assessment with 5 methods: climate survey, interviews, observation, incident data and the maturity ladd... - [SAMA Compliance: The Cyber Security Framework Maturity Levels](https://governancedocs.com/sama-compliance/): SAMA compliance explained — the four domains of the Cyber Security Framework, the six maturity levels you are audited ag... - [SAMA CSF vs NCA ECC: A Clear Guide for Saudi Firms in 2026](https://governancedocs.com/sama-csf-vs-nca-ecc/): SAMA CSF vs NCA ECC: who each binds, why one scores maturity 0-5 and the other tests compliance, and how to run 1 contro... - [SAMA Outsourcing: A Clear Guide to the 4 Core Rules](https://governancedocs.com/sama-outsourcing/): SAMA outsourcing rules make material arrangements supervised. The materiality test, the prior no-objection, the contract... - [Saudi PDPL Implementing Regulations: The 38 Articles Mapped](https://governancedocs.com/saudi-pdpl-implementing-regulations/): Saudi PDPL implementing regulations mapped article by article: the 30-day clock, consent, processor contracts, 72-hour b... - [Saudi PDPL vs GDPR: The 11 Differences That Change What You Do](https://governancedocs.com/saudi-pdpl-vs-gdpr/): Saudi PDPL vs GDPR: consent by default, 30-day clocks, platform registration, 72 hours to SDAIA, no adequacy list, riyal... - [Saudi PDPL: The Complete 2026 Guide to the Personal Data Protection Law](https://governancedocs.com/saudi-pdpl/): Saudi PDPL explained for 2026: the law and Implementing Regulation, SDAIA and its platform, consent by default, the cloc... - [Saudi Standard Contractual Clauses: Transfers With No Adequacy List](https://governancedocs.com/saudi-standard-contractual-clauses/): Saudi standard contractual clauses: the exemption cases, SDAIA's four templates, the three appendices, the no-edit rule,... - [SBOM Requirements: 6 Proven Steps to CRA Compliance](https://governancedocs.com/sbom-requirements/): The CRA asks for an SBOM in four separate places. What Annex I Part II(1), Annex VII, Article 13(25) and Annex II point... - [Scope 1, 2 and 3 Emissions: A Clear Guide for ESG Reporting](https://governancedocs.com/scope-1-2-3-emissions/): Scope 1, 2 and 3 emissions under the GHG Protocol: what each scope holds, the 15 Scope 3 categories, the 2 Scope 2 metho... - [SDAIA Registration: The National Data Governance Platform Explained](https://governancedocs.com/sdaia-registration/): SDAIA registration on the National Data Governance Platform: who must register, the representative, DPO details, the fiv... - [Segregation of Duties: 6 Proven Steps for SOX and ISO 27001](https://governancedocs.com/segregation-of-duties/): One term covers three problems: transaction level, entitlement level and function level. What SOX 404, DORA Article 6(4)... - [Shared Responsibility Matrix: A Clear Guide for ISO 27017](https://governancedocs.com/shared-responsibility-matrix/): A shared responsibility matrix decides who patches, configures and restores. What goes in it across IaaS, PaaS and SaaS,... - [Significant Energy Uses: A Complete ISO 50001 Guide (2026)](https://governancedocs.com/significant-energy-uses/): Significant energy uses in ISO 50001: the definition, the 2 criteria with a worked 8-use selection, what the standard re... - [SOC 1 Audit Checklist: The Essential 2026 Readiness Guide](https://governancedocs.com/soc-1-audit-checklist/): SOC 1 audit checklist for service organisations: the acknowledgements, scope and period decisions, control objectives, d... - [SOC 1 Audit Cost: A Practical 2026 Breakdown](https://governancedocs.com/soc-1-audit-cost/): SOC 1 audit cost explained: why there is no list price, the one dated CPA-firm range worth citing, the eight drivers, th... - [SOC 1 Control Objectives: The Essential 2026 Guide to Writing Them](https://governancedocs.com/soc-1-control-objectives/): SOC 1 control objectives explained: the four attributes that make them reasonable, the business-process and ITGC familie... - [SOC 1 Report Explained: The Complete 2026 Guide](https://governancedocs.com/soc-1-report/): SOC 1 report explained: what it covers, who writes each of its three parts, type 1 vs type 2, control objectives, CUECs,... - [SOC 1 Type 2 vs Type 1: The Essential 2026 Comparison](https://governancedocs.com/soc-1-type-2-vs-type-1/): SOC 1 Type 2 vs Type 1: what each report covers, why user auditors ask for Type 2, when a Type 1 comes first, and how th... - [SOC 1 vs SOC 2: The Complete 2026 Comparison Guide](https://governancedocs.com/soc-1-vs-soc-2/): SOC 1 vs SOC 2: what each report covers, who asks for which, when a service organisation needs both, and what changes in... - [SOX 404: Who Needs the Auditor Attestation](https://governancedocs.com/sox-404/): SOX 404(a) applies to every issuer; 404(b) only to some. The public float and revenue tests that decide it, read from th... - [Special Characteristics: A Clear IATF 16949 Guide to All 6 Documents](https://governancedocs.com/special-characteristics/): Special characteristics are one designation flowing through 6 documents. Where each must appear, what it obliges, and th... - [SPRS Score: A Clear Guide to the 2026 Scoring Rules](https://governancedocs.com/sprs-score/): An SPRS score runs from 110 to -203. How the weighting works, the 2 requirements with partial credit, how long it stays... - [SSAE 18 Explained: The Essential 2026 Guide for Service Organizations](https://governancedocs.com/ssae-18/): SSAE 18 explained: what the AICPA statement is, the SAS 70 and SSAE 16 lineage, the amendments since, why nobody is cert... - [Stakeholder Register: A Clear Guide to All 7 Fields](https://governancedocs.com/stakeholder-register/): A stakeholder register needs 7 fields to drive behaviour. The power-interest quadrants, and the 4 questions that find th... - [STAR Level 2: A Clear Guide to Certification vs Attestation](https://governancedocs.com/star-level-2/): STAR Level 2 comes in 2 forms: certification built on ISO 27001, attestation built on SOC 2. Which route to take, and th... - [Statement of Work: A Clear Guide to All 8 Sections](https://governancedocs.com/statement-of-work/): A statement of work in 8 sections: scope, deliverables, acceptance criteria, price and change control - plus how to revi... - [StateRAMP Is Now GovRAMP: The Verification Pathway Explained](https://governancedocs.com/stateramp/): StateRAMP has been renamed GovRAMP. The verification pathway, the 60 Core controls, the overlays, and why TX-RAMP is a s... - [Strategic Asset Management Plan: A Clear 2026 Guide](https://governancedocs.com/strategic-asset-management-plan/): The strategic asset management plan converts organizational objectives into asset objectives. The 9 sections, who writes... - [Structured Project Management: Reducing Delivery Risk](https://governancedocs.com/structured-project-management/): Discover how structured project management can transform your approach to handling risks by providing a clear, methodica... - [Subject Access Request Time Limit UK: The Article 12A Clock Explained](https://governancedocs.com/subject-access-request-time-limit-uk/): Subject access request time limit UK rules since 2026: the relevant time, the clarification pause, the two-month extensi... - [Supplier Business Continuity Assessment: 7 Essential Checks (2026)](https://governancedocs.com/supplier-business-continuity-assessment/): Supplier business continuity assessment under ISO 22301 and ISO/TS 22318: tiering from the BIA, 7 question areas, 0–3 sc... - [Supply Chain Security Risk Assessment: A Complete ISO 28000 Guide](https://governancedocs.com/supply-chain-security-risk-assessment/): Supply chain security risk assessment under ISO 28000 clause 8.3: map the handovers, assess deliberate threats, score, t... - [SWIFT Architecture Types: A Clear Guide to All 5 Types](https://governancedocs.com/swift-architecture-types/): SWIFT architecture types A1 to B decide how much of the CSCF applies to you. What sets your type, what changed in v2026,... - [SWIFT CSCF: Your Independent Assessment Can Be Internal](https://governancedocs.com/swift-cscf/): The SWIFT CSCF independent assessment can be performed by your own second or third line of defence, not only an external... - [The CRA Reporting Deadline: 11 September 2026](https://governancedocs.com/cra-reporting-deadline/): Article 14 applies from 11 September 2026, and Article 69(3) reaches products you placed on the market years ago. The tw... - [The DPDP Act Timeline: What Applies in 2026 and 2027](https://governancedocs.com/dpdp-act/): India's DPDP Act is commencing in three tranches. What is already in force, what lands on 13 November 2026, and the full... - [The HIPAA Security Rule Overhaul: What Is Proposed and When](https://governancedocs.com/hipaa-security-rule-update/): The proposed HIPAA Security Rule overhaul explained: what would change, why the final rule slipped to 2027, and what is... - [The Interagency Guidance on Third-Party Relationships: A Complete 2026 Guide](https://governancedocs.com/interagency-guidance-third-party-relationships/): The 2023 Interagency Guidance on Third-Party Relationships explained: what it rescinded, its lifecycle, the 14 due dilig... - [The ISO 14001 Registers: Aspects, Impacts and Compliance Obligations](https://governancedocs.com/iso-14001-register/): What an ISO 14001 register must contain — the environmental aspects and impacts register and the compliance obligations... - [The TPRM Lifecycle: Five Stages, Their Records and Where Programmes Stall (2026)](https://governancedocs.com/tprm-lifecycle/): The TPRM lifecycle stage by stage: planning, due diligence, contracting, monitoring and exit, with the entry and exit cr... - [Third-Party Risk Assessment: Tiering, Due Diligence Depth and Scoring (2026 Guide)](https://governancedocs.com/third-party-risk-assessment/): How to run a third-party risk assessment: the 12 inherent-risk tiering questions, how a score becomes a tier, the depth... - [Third-Party Risk Management Framework: One Lifecycle, Twelve Regimes (2026 Guide)](https://governancedocs.com/third-party-risk-management-framework/): A third-party risk management framework mapped to 12 regimes at once: Interagency Guidance, NIST CSF 2.0, DORA, ISO 2700... - [Third-Party Risk Management: One Inventory, Four Regimes](https://governancedocs.com/third-party-risk-management/): DORA, NIS2, ISO 27001 and sector schemes ask about the same suppliers in different formats. Build one inventory that ans... - [Threat Intelligence: A Clear Guide to ISO 27001 Control 5.7](https://governancedocs.com/iso-27001-threat-intelligence/): Threat intelligence under ISO 27001 control 5.7: the 3 levels, the 5 artefacts that make it auditable, and why a subscri... - [Threat-Led Penetration Testing: Who DORA Actually Requires It From](https://governancedocs.com/threat-led-penetration-testing/): DORA TLPT applies only to entities their regulator identifies. Live production systems, a scope the authority validates,... - [TISAX Audit Checklist: A Clear Guide to the 7 ISA 2027 Steps](https://governancedocs.com/tisax-audit-checklist/): A TISAX audit checklist for ISA 2027: which catalogue applies from 1 January 2027, the 7 preparation steps, and the cont... - [TISAX Exchange: The Half of TISAX Suppliers Never Use](https://governancedocs.com/tisax-exchange/): TISAX is an exchange mechanism, not a certificate. The four steps, why scope decides what customers receive, and the pas... - [TPRM Policy: What It Must Contain and What Makes It Evidence (2026 Guide)](https://governancedocs.com/tprm-policy/): What a TPRM policy must contain, which regimes require it (NIST CSF GV.SC-01, SR-1, ISO 27001 5.19, EBA, NYDFS), and wha... - [Traceability System: The Complete ISO 22000 Clause 8.3 Guide](https://governancedocs.com/traceability-system/): The traceability system under ISO 22000 clause 8.3: supplier lot to first customer, rework, shelf-life retention, mass-b... - [Turtle Diagram: A Clear Guide to All 6 Elements](https://governancedocs.com/turtle-diagram/): A turtle diagram has 6 elements and is not required by IATF 16949 - the process approach is. A worked example and how au... - [TX-RAMP: A Clear Guide to the 2 Texas Certification Levels](https://governancedocs.com/tx-ramp-certification/): TX-RAMP explained: who must comply, the 2 certification levels, the 18-month provisional route, and which FedRAMP and Go... - [UK GDPR Automated Decision Making: Articles 22A to 22C Explained](https://governancedocs.com/uk-gdpr-automated-decision-making/): UK GDPR automated decision making since 2026: meaningful human involvement, significant decisions, the special category... - [UK GDPR Privacy Notice: What It Must Say in 2026 (and What It Must Not)](https://governancedocs.com/uk-gdpr-privacy-notice/): UK GDPR privacy notice requirements in 2026: Article 13 and 14 content, the section 164A complaint route, the new lawful... - [UK GDPR vs EU GDPR: The 11 Differences That Matter in 2026](https://governancedocs.com/uk-gdpr-vs-eu-gdpr/): UK GDPR vs EU GDPR in 2026: lawful bases, rights time limits, automated decisions, transfers, complaints, age of consent... - [UK GDPR: The Complete 2026 Guide After the Data (Use and Access) Act](https://governancedocs.com/uk-gdpr/): UK GDPR explained for 2026: the three statutes, who enforces it, the Data (Use and Access) Act 2025 changes and dates, a... - [Unified Management Systems: Aligning Quality & Safety](https://governancedocs.com/unified-management-system/): A Unified Management System brings all your quality and safety processes together under one roof, making it easier to st... - [Unique Device Identification: 6 Proven Rules Article 27 Sets](https://governancedocs.com/unique-device-identification/): The UDI-DI and UDI-PI split, where carriers go and where they do not, the Basic UDI-DI on your declaration of conformity... - [Vendor Due Diligence Checklist: 14 Factors, Three Depths, One Evidence Rule (2026)](https://governancedocs.com/vendor-due-diligence-checklist/): A vendor due diligence checklist built on the Interagency Guidance's 14 factors, tiered by risk, with the evidence rule... - [Virtual CISO: A Clear Guide to All 5 Service Elements](https://governancedocs.com/virtual-ciso/): What a virtual CISO does, the 5 elements of the service, how to structure and price an engagement, and where the model f... - [What Is TPRM? Third-Party Risk Management Explained (2026 Guide)](https://governancedocs.com/what-is-tprm/): TPRM, third-party risk management, explained: the five-stage lifecycle regulators use, the twelve regimes that require i... - [Whistleblowing Policy: 6 Proven Rules the EU Directive Sets](https://governancedocs.com/whistleblowing-policy/): Seven days to acknowledge, three months to give feedback, and a reversed burden of proof that makes every later decision... - [White Label Compliance Templates: A Clear Guide to 5 Terms](https://governancedocs.com/white-label-compliance-templates/): Can you use white label compliance templates on client work? The 5 licence terms to check, how to tailor properly, and t... - [Whole Life Cost: 7 Essential Elements for ISO 55001 Decisions](https://governancedocs.com/whole-life-cost/): Whole life cost: the 7 cost elements, how to build the model for an ISO 55001 clause 4.5 decision, discount rate and hor... ### NIS2 (7) - [CRA vs NIS2: 7 Clear Differences Explained for 2026](https://governancedocs.com/cra-vs-nis2/): CRA vs NIS2: products vs entities, Article 14 vs Article 23 clocks, EUR 15m/2.5% vs EUR 10m/2% fines, and the dates — 11... - [NIS2 Directive Explained: A Complete Compliance Guide](https://governancedocs.com/nis2-directive-compliance/): The NIS2 Directive is the EU's most far-reaching cybersecurity law. A complete guide to its scope, security requirements... - [NIS2 Incident Reporting: A Clear Guide to the 3 Deadlines](https://governancedocs.com/nis2-incident-reporting/): NIS2 incident reporting under Article 23: 24-hour early warning, 72-hour notification, one-month final report, and the t... - [NIS2 Penalties & Deadlines Explained](https://governancedocs.com/nis2-penalties/): NIS2 penalties are among the toughest in EU cyber law, with personal liability for management. Here are the fines, enfor... - [NIS2 Requirements & Documentation Checklist](https://governancedocs.com/nis2-requirements/): What does NIS2 actually require? A practical checklist of the security measures, incident-reporting timelines, and docum... - [NIS2 vs ISO 27001: Use Your ISMS to Comply](https://governancedocs.com/nis2-vs-iso-27001/): NIS2 vs ISO 27001: one is a mandatory law, the other a certifiable standard. Here is how they align and how ISO 27001 he... - [Who Does NIS2 Apply To? Essential vs. Important Entities](https://governancedocs.com/who-does-nis2-apply-to/): NIS2 widened EU cybersecurity rules to thousands of new organizations. Learn who is covered, the essential vs important... ### SOC 2 (7) - [How to Prepare for a SOC 2 Audit](https://governancedocs.com/soc-2-audit/): The SOC 2 audit tests your controls independently. Here is what it involves, the process, how to prepare, and the pitfal... - [ISO 27001 vs SOC 2: Which Do You Need?](https://governancedocs.com/iso-27001-vs-soc-2/): ISO 27001 vs SOC 2: one is an international certificate, the other a US attestation report. Here are the key differences... - [SOC 2 Cost & Timeline: What to Expect](https://governancedocs.com/soc-2-cost/): What does SOC 2 cost and how long does it take? Here are the main cost factors, the Type 1 and Type 2 timelines, and how... - [SOC 2 Explained: The Complete Compliance Guide](https://governancedocs.com/soc-2-compliance/): SOC 2 compliance is a gatekeeper to enterprise sales for SaaS. A complete guide to the Trust Services Criteria, Type 1 v... - [SOC 2 Policies & Documentation Checklist](https://governancedocs.com/soc-2-documentation/): SOC 2 documentation turns security practice into an auditable report. Here are the essential policies, the evidence you... - [SOC 2 Trust Services Criteria Explained](https://governancedocs.com/soc-2-trust-services-criteria/): The SOC 2 Trust Services Criteria define what your auditor evaluates. Here are all five - security, availability, proces... - [SOC 2 Type 1 vs Type 2: What’s the Difference?](https://governancedocs.com/soc-2-type-1-vs-type-2/): SOC 2 Type 1 vs Type 2: one tests control design at a point in time, the other operating effectiveness over a period. He... ### Security frameworks (134) - [201 CMR 17.00: The Complete Massachusetts WISP Guide (2026)](https://governancedocs.com/201-cmr-17-wisp/): 201 CMR 17.00 explained: who it binds, personal information defined, the 10 WISP elements of 17.03, the 8 technical requ... - [Aerospace Quality Management: 3 Essential AS9100 Standards](https://governancedocs.com/aerospace-quality-management/): In most industries a quality escape costs money. In aerospace and nuclear it can cost lives, and the quality regimes ref... - [AI Risk Register: 12 Essential Fields and 7 Risk Sources (2026)](https://governancedocs.com/ai-risk-register/): How to build an AI risk register: the 12 fields, 7 AI risk sources, scoring, and how it maps to NIST AI RMF, ISO 42001 c... - [Asset-Referenced Token vs E-Money Token: 5 Essential MiCA Rules](https://governancedocs.com/art-vs-emt/): Asset-referenced token vs e-money token under MiCA: definitions, who may issue, own funds, reserves, redemption at par v... - [Basel III Endgame: Where the US Final Rule Stands in 2026](https://governancedocs.com/basel-iii-endgame/): Basel III endgame: the July 2023 proposal, the 19 March 2026 re-proposal (3 NPRs, comments closed 18 June 2026), the eSL... - [Board Cybersecurity Reporting: A Clear Guide to the 6 Indicators](https://governancedocs.com/board-cybersecurity-reporting/): Board cybersecurity reporting built on 6 indicators — exposure, control coverage, detection and response speed, incident... - [BSI C5 Attestation Cost: A Realistic 2026 Estimate by Profile](https://governancedocs.com/bsi-c5-attestation-cost/): BSI C5 attestation cost estimated by provider profile: assessor days × €1,500–2,500, type 1 vs type 2, the internal effo... - [BSI C5 vs SOC 2: 5 Clear Differences and the Mapping (2026)](https://governancedocs.com/bsi-c5-vs-soc-2/): BSI C5 vs SOC 2: same report shape, different content — 10 points compared, the 5 differences that matter, the 17 C5 obj... - [C3PAO: A Clear Guide to Choosing a CMMC Assessor in 2026](https://governancedocs.com/c3pao/): What a C3PAO must be under 32 CFR 170.9, six checks before you sign, what the Level 2 assessment involves, and whether t... - [C5 Criteria: All 17 Objectives and 168 Criteria Explained (2026)](https://governancedocs.com/bsi-c5-criteria/): The C5 criteria in C5:2026: 17 objectives, 168 criteria, basic and additional subcriteria, 6 general conditions, complem... - [California Delete Act: The Complete Guide to DROP in 2026](https://governancedocs.com/california-delete-act/): California Delete Act (SB 362): who is a data broker, the $6,000 registration, DROP's 45-day cycle since 1 Aug 2026, re-... - [Capital Buffers: CCB, CCyB and G-SIB Surcharges Explained (2026)](https://governancedocs.com/capital-buffers/): Capital buffers under Basel III: the 2.5% conservation buffer, 0–2.5% countercyclical buffer, G-SIB surcharges of 1–3.5%... - [CCPA Cybersecurity Audit: Who Must File and When (2028–2030)](https://governancedocs.com/ccpa-cybersecurity-audit/): CCPA cybersecurity audit under Article 9: the §7120 trigger, first reports 1 Apr 2028/2029/2030, auditor independence, 1... - [CCPA Penalties: The 4 Fine Channels and 2025 Amounts Explained](https://governancedocs.com/ccpa-penalties/): CCPA penalties: $2,663 / $7,988 per violation, $107–$799 per consumer for breaches, $200/day Delete Act fines, no cure p... - [CCPA Risk Assessment: 9 Essential Elements and 3 Deadlines (2026)](https://governancedocs.com/ccpa-risk-assessment/): CCPA risk assessment under Article 10: the triggers, the 9 elements of §7152, the 31 Dec 2027 deadline for existing proc... - [CCPA vs GDPR: 8 Clear Differences Explained for 2026](https://governancedocs.com/ccpa-vs-gdpr/): CCPA vs GDPR: thresholds vs universal scope, opt-out vs lawful basis, rights, risk assessments vs DPIAs, service provide... - [CIS Controls Assessment: The Complete CIS CSAT Scoring Guide](https://governancedocs.com/cis-controls-assessment/): CIS Controls assessment with CIS CSAT: scope to IG1, IG2 or IG3, score every Safeguard on policy, implementation, automa... - [CIS Controls Implementation Cost in 2026: The Complete Breakdown](https://governancedocs.com/cis-controls-implementation-cost/): CIS Controls implementation cost by Implementation Group: IG1 $15k–80k, IG2 $150k–600k, IG3 $800k–3m+ in year one — tool... - [CIS Controls Implementation: The Essential 6-Step IG1 Plan (2026)](https://governancedocs.com/cis-controls-implementation/): CIS Controls implementation for IG1: the 56 Safeguards by Control, a 6-step plan from inventory to incident response, ti... - [CIS Controls vs NIST CSF: 5 Clear Differences Explained](https://governancedocs.com/cis-controls-vs-nist-csf/): CIS Controls vs NIST CSF on 5 differences: prescriptive Safeguards (153, IG1 56) vs outcome-based CSF 2.0 (106 Subcatego... - [Cloud Security Certification: 4 Essential Routes Compared](https://governancedocs.com/cloud-security-certification/): Sooner or later a prospect asks a cloud provider to prove its security, and the honest first answer is a question: prove... - [CMMC Level 1: A Clear Guide to the 15 Self-Assessment Requirements](https://governancedocs.com/cmmc-level-1/): CMMC Level 1 explained: the 15 FAR 52.204-21 requirements mapped to 800-171A, the annual self-assessment and SPRS affirm... - [CMMC Level 3: A Clear Guide to the 24 NIST 800-172 Requirements](https://governancedocs.com/cmmc-level-3/): CMMC Level 3 explained: all 24 NIST SP 800-172 requirements with DoD parameters, the Final Level 2 (C3PAO) prerequisite,... - [CMMC Phase 2 Suspended: A Clear Guide to What Still Applies in 2026](https://governancedocs.com/cmmc-phase-2/): CMMC Phase 2 was due 10 November 2026 and was suspended on 13 July 2026. What stopped, what still applies (Phase 1, SPRS... - [CMMC Scoping: A Clear Guide to the 5 Asset Categories](https://governancedocs.com/cmmc-scoping/): CMMC scoping under 32 CFR 170.19: the 5 Level 2 asset categories and how each is assessed, the ESP and cloud rules, Leve... - [COBIT Capability Levels: The 0–5 Scale Explained (2026 Guide)](https://governancedocs.com/cobit-capability-levels/): COBIT capability levels 0–5 defined, how a process is rated on the 4-point achievement scale, setting targets from the d... - [COBIT Certification Cost: A Realistic 2026 Breakdown](https://governancedocs.com/cobit-certification-cost/): COBIT certification cost: ISACA's US$175 Foundation and US$275 Design & Implementation exams, training, the COBIT 7 swit... - [COBIT Design Factors: All 11 Explained With a Worked Example](https://governancedocs.com/cobit-design-factors/): The 11 COBIT design factors with their values and the objectives each raises, the 4-stage design workflow, a worked exam... - [COBIT Domains: EDM, APO, BAI, DSS and MEA Explained (2026 Guide)](https://governancedocs.com/cobit-domains/): The 5 COBIT domains and all 40 COBIT 2019 objectives by identifier and name, what separates the EDM governance domain fr... - [COBIT vs ITIL: 4 Clear Differences and How They Map (2026)](https://governancedocs.com/cobit-vs-itil/): COBIT vs ITIL: governance framework vs service management framework — 8 points compared, the 4 differences that matter,... - [Complementary Customer Controls: A Complete C5 Guide (2026)](https://governancedocs.com/complementary-customer-controls/): Complementary customer controls in C5:2026: what CUEC are, the 3 audiences, where they cluster by area, the customer's 4... - [Controlled Unclassified Information: The Complete CUI Guide (2026)](https://governancedocs.com/controlled-unclassified-information/): Controlled unclassified information from 32 CFR 2002: what is and isn't CUI, Basic vs Specified, the marking rules, safe... - [COSO ERM Principles: All 20 Explained in 5 Components (2026)](https://governancedocs.com/coso-erm-principles/): The 20 COSO ERM principles from the 2017 framework by component, what each asks you to show, how they differ from the 17... - [Crypto Travel Rule: The Complete EU Guide With No Threshold (2026)](https://governancedocs.com/crypto-travel-rule/): The EU crypto travel rule (Reg 2023/1113): the Article 14 data set, CASP duties by role, self-hosted wallets above €1,00... - [CSA STAR Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/csa-star-certification-cost/): CSA STAR certification cost by level: Level 1 free, Valid-AI-ted $595, Level 2 = ISO 27001 or SOC 2 base plus a CCM incr... - [CSCF v2026: What Changed in the 32 SWIFT Controls (Complete Guide)](https://governancedocs.com/cscf-v2026/): CSCF v2026 explained: 2.4 now mandatory, customer connectors in scope of 14 controls, the B-to-A4 reclassification, all... - [Cyber Essentials Renewal: The Complete 12-Month Cycle (2026)](https://governancedocs.com/cyber-essentials-renewal/): Cyber Essentials renewal: 12-month validity, a full reassessment each year at £320–600, the April question-set change, P... - [Cyber Essentials Requirements: The 5 Controls Explained (2026)](https://governancedocs.com/cyber-essentials-requirements/): Cyber Essentials requirements v3.3: the 5 controls with numbers — 14-day patching, MFA on cloud, 12-character passwords,... - [Cyber Essentials Scope: 12 Essential In-or-Out Rules (2026)](https://governancedocs.com/cyber-essentials-scope/): Cyber Essentials scope under v3.3: whole organisation vs sub-set, 12 device rules, the role-based BYOD table, cloud neve... - [Cyber Risk Quantification: A Clear Guide to FAIR Indicators](https://governancedocs.com/cyber-risk-quantification/): Cyber risk quantification with FAIR: the factors from threat event frequency to loss magnitude, the 5 indicators it prod... - [Cybersecurity KRIs vs KPIs: 5 Clear Rules for Board Reporting](https://governancedocs.com/cybersecurity-kri-vs-kpi/): Every security team is asked the same question by its board sooner or later: are we getting safer? Answering it means re... - [Data Catalog vs Data Dictionary: 5 Clear Differences (2026)](https://governancedocs.com/data-catalog-vs-data-dictionary/): Data catalog vs data dictionary on 5 differences — question, unit, meaning, context, currency — where the glossary sits,... - [Data Cybersecurity Controls: A Clear Guide to NCA DCC-1:2022](https://governancedocs.com/data-cybersecurity-controls/): The NCA Data Cybersecurity Controls (DCC-1:2022): 3 domains, 11 subdomains, 47 sub-controls scaled to 4 classification l... - [Data Governance Framework: The 5 Essential Layers Explained (2026)](https://governancedocs.com/data-governance-framework/): A data governance framework in 5 layers — strategy and policy, operating model, standards and processes, assets and meta... - [Data Governance Maturity Model: The 5 Levels Explained (2026)](https://governancedocs.com/data-governance-maturity-model/): The data governance maturity model: 5 levels (performed to optimized), 7 dimensions, how to run an evidence-based assess... - [Data Lineage: The 3 Essential Types and How to Capture Them (2026)](https://governancedocs.com/data-lineage/): Data lineage explained: business, technical and operational lineage, granularity and direction, 4 capture methods, the r... - [DPDP Breach Notification: The 72-Hour Rule 7 Guide (2026)](https://governancedocs.com/dpdp-breach-notification/): DPDP breach notification under Rule 7: each affected data principal without delay, the Board within 72 hours with 6 item... - [DPDP Penalties: The 7 Bands up to ₹250 Crore Explained (2026)](https://governancedocs.com/dpdp-penalties/): DPDP penalties: all 7 Schedule bands (₹250cr security, ₹200cr breach notice and children, ₹150cr SDF, ₹50cr other), the... - [DPDP vs GDPR: 12 Clear Differences Explained (2026)](https://governancedocs.com/dpdp-vs-gdpr/): DPDP vs GDPR on 12 points: scope, lawful bases, children under 18, breach notice with no threshold, ₹250 crore vs 4% fin... - [FedRAMP Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/fedramp-certification-cost/): FedRAMP certification cost in 2026: 6 components with labelled ranges, a $150k–$300k Moderate assessment, and how path a... - [FedRAMP Continuous Monitoring in 2026: A Clear Guide to 6 Rulesets](https://governancedocs.com/fedramp-continuous-monitoring/): FedRAMP continuous monitoring is now Ongoing Certification: 6 rulesets, 76 rules, a quarterly report, and vulnerability... - [Financial Services Compliance: 3 Essential Regimes](https://governancedocs.com/financial-services-compliance/): There is no single rulebook for finance. Financial services compliance is a patchwork determined by what you do and wher... - [Fraud Risk Assessment: A Complete Guide to the COSO 5 Principles](https://governancedocs.com/fraud-risk-assessment/): Fraud risk assessment under the COSO/ACFE Guide 2nd edition: the 5 principles, a scheme-by-scheme method with a worked r... - [FTC Safeguards Rule Breach Notification: The 30-Day WISP Rule](https://governancedocs.com/ftc-safeguards-rule-breach-notification/): FTC Safeguards Rule breach notification under 314.4(j): the notification-event definition, deemed discovery, 500 consume... - [FTC Safeguards Rule Penalties: The Complete WISP Enforcement Guide](https://governancedocs.com/ftc-safeguards-rule-penalties/): FTC Safeguards Rule penalties: no fine in the Rule, section 5 orders with 20-year obligations, $53,088 per violation for... - [GovRAMP Cost in 2026: The Complete Breakdown by Tier and Stage](https://governancedocs.com/govramp-cost/): GovRAMP cost from the published schedule: $500–$1,500 membership plus PMO fees from $1,000 (Snapshot) to $19,500 (Author... - [GovRAMP Fast Track: 5 Essential Steps to Reuse a FedRAMP Package](https://governancedocs.com/govramp-fast-track/): GovRAMP Fast Track: reuse FedRAMP SARs, RARs and 90 days of ConMon for GovRAMP verification in 5 steps, the same fees as... - [GovRAMP Security Snapshot: The 40-Control Score Explained (2026)](https://governancedocs.com/govramp-security-snapshot/): GovRAMP Security Snapshot: a 40-control NIST 800-53 score out of 100, Single vs Progressing, $1,000–$2,500 or $750–$1,60... - [GovRAMP vs FedRAMP: 7 Clear Differences Explained for 2026](https://governancedocs.com/govramp-vs-fedramp/): GovRAMP vs FedRAMP: state and local vs federal buyers, a progressive ladder vs one gate, SSP/POA&M vs JSON artifacts, pu... - [HITRUST Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/hitrust-certification-cost/): HITRUST certification cost for e1, i1 and r2: HITRUST/MyCSF fees, External Assessor fees, remediation and staff time, th... - [HITRUST External Assessor: 8 Clear Questions Before Choosing](https://governancedocs.com/hitrust-external-assessor/): HITRUST External Assessor: the only firms authorised to validate, vs Readiness Licensees, HITRUST's vetting and disclaim... - [HITRUST Interim Assessment: The Clear Guide to Year 2 (2026)](https://governancedocs.com/hitrust-interim-assessment/): HITRUST interim assessment: the year-one checkpoint of a 2-year r2, what it confirms, the evidence it needs, the i1 rapi... - [HITRUST vs HIPAA: 5 Essential Differences and When to Certify](https://governancedocs.com/hitrust-vs-hipaa/): Healthcare vendors get asked for HIPAA compliance constantly, and increasingly for HITRUST certification as well. The tw... - [HITRUST vs SOC 2: 7 Clear Differences Explained for 2026](https://governancedocs.com/hitrust-vs-soc-2/): HITRUST vs SOC 2: prescribed, maturity-scored certification with central QA vs a CPA attestation on self-defined control... - [ICSR: The Complete Guide to Internal Control over Sustainability](https://governancedocs.com/icsr/): ICSR explained: COSO's March 2023 guidance applying the 17 principles to ESG data — why sustainability data breaks finan... - [ILAAP: The 7 Essential ECB Principles and 6 Building Blocks](https://governancedocs.com/ilaap/): ILAAP under Article 86 CRD and the ECB's 2018 guide: 7 principles, 6 building blocks, normative and economic perspective... - [ISO 27017: Cloud Security Controls and What the 2026 Edition Changes](https://governancedocs.com/iso-27017/): ISO 27017 is not a certification. Here is what the standard actually contains, how it differs from ISO 27018, how it is... - [ISO 27701 Implementation: A Proven 8-Step Plan for 2026](https://governancedocs.com/iso-27701-implementation/): ISO 27701 implementation in 8 steps from either start — extending ISO 27001 or standalone — with deliverables, traps, ti... - [ISO 27701 Mandatory Documents: The Complete 2026 Checklist](https://governancedocs.com/iso-27701-mandatory-documents/): ISO 27701 mandatory documents: the clause 4–10 documented information, the records the A.1, A.2 and A.3 controls require... - [ISO 27701 vs GDPR: 10 Clear Differences and the Mapping (2026)](https://governancedocs.com/iso-27701-vs-gdpr/): ISO 27701 vs GDPR: a certifiable PIMS standard vs a binding law — 10 points compared, 12 GDPR articles mapped to Annex A... - [ISO 55001 vs ISO 41001 vs ISO 50001: Which One Do You Need?](https://governancedocs.com/iso-55001-41001-50001/): ISO 55001, ISO 41001 and ISO 50001 manage different things about the same estate. What each one actually covers, where t... - [IT Governance Framework: 3 Essential Layers Explained](https://governancedocs.com/it-governance-framework/): Teams adopting COBIT, ISO 31000 and the CIS Controls often assume they are choosing between them. They are not. Each occ... - [KYC-SA: A Complete Guide to the SWIFT Attestation App (2026)](https://governancedocs.com/kyc-sa/): KYC-SA explained: what the SWIFT attestation app is, what is submitted 1 Jul–31 Dec, how the independent assessment is r... - [LCR vs NSFR: 7 Clear Differences Between the Basel Ratios](https://governancedocs.com/lcr-vs-nsfr/): LCR vs NSFR: 30-day stress buffer vs one-year funding structure, HQLA and run-off factors vs ASF and RSF, why a bank can... - [Management Review Controls: 6 Essential Precision Factors (2026)](https://governancedocs.com/management-review-controls/): Management review controls per PCAOB Practice Alert 11: the 6 precision factors, the 4 questions an auditor tests, the e... - [Master Data Management vs Data Governance: 5 Essential Differences](https://governancedocs.com/master-data-management-vs-data-governance/): Master data management vs data governance: MDM executes the golden record, governance decides definitions and rules — 5... - [Material Weakness vs Significant Deficiency: The Definitive Guide](https://governancedocs.com/material-weakness/): Material weakness vs significant deficiency vs deficiency under PCAOB AS 2201: definitions, the 2-factor test, 4 indicat... - [MiCA Compliance Checklist: 60 Essential Items by Title (2026)](https://governancedocs.com/mica-compliance-checklist/): MiCA compliance checklist by Title: white papers, ART and EMT issuers, CASP authorisation and conduct, per-service rules... - [MiCA Compliance Cost in 2026: The Complete Breakdown](https://governancedocs.com/mica-compliance-cost/): MiCA compliance cost: Article 67 capital (€50k/€125k/€150k or ¼ overheads), authorisation €50k–500k, ongoing €170k–2.3m... - [MiCA Market Abuse: The 3 Prohibitions and Article 92 Explained](https://governancedocs.com/mica-market-abuse/): MiCA market abuse (Title VI): scope, inside information disclosure, the 3 prohibitions, Article 92 surveillance and STOR... - [MTTD vs MTTR: A Clear Guide to the 4 Cyber Response Indicators](https://governancedocs.com/mttd-vs-mttr/): MTTD vs MTTR explained as 4 clocks on one incident timeline — detect, acknowledge, contain, recover — with formulas, the... - [MyCSF: The Complete Guide to the HITRUST Assessment Platform](https://governancedocs.com/mycsf/): MyCSF: HITRUST's platform for scoping, tailoring, evidence, inheritance of up to 85% of controls, assessor validation, Q... - [NCA ECC Self-Assessment: A Clear Guide to the Compliance Tool](https://governancedocs.com/nca-ecc-self-assessment/): The NCA ECC self-assessment explained: the ECC-2:2024 Assessment and Compliance Tool, the Haseen platform, 4 status valu... - [NCA ECC: A Cybersecurity Compliance Guide for Saudi Firms](https://governancedocs.com/nca-ecc-cybersecurity-compliance/): For Saudi firms navigating the digital age, NCA ECC cybersecurity compliance is more than a requirement—its a vital shie... - [NIST 800-171 Compliance Cost: A Realistic 2026 Breakdown](https://governancedocs.com/nist-800-171-compliance-cost/): NIST 800-171 compliance cost: DoD's assessment estimates ($37,196 self, $104,670 certified) plus our implementation esti... - [NIST 800-171 Rev 3 vs Rev 2: 97 Requirements Explained (2026)](https://governancedocs.com/nist-800-171-rev-3/): NIST 800-171 Rev 3 vs Rev 2: 110 requirements in 14 families became 97 in 17, with 88 ODPs and 3 new families — and why... - [NIST 800-171 vs 800-53: 8 Clear Differences Explained (2026)](https://governancedocs.com/nist-800-171-vs-800-53/): NIST 800-171 vs 800-53 on 8 points: purpose, scope, size, baselines, ODPs, assessment, and the tailoring that cuts 287 m... - [NIST 800-171A: A Clear Guide to Assessment Objectives (2026)](https://governancedocs.com/nist-800-171a/): NIST 800-171A explained: how a requirement becomes assessment objectives, the examine/interview/test methods, how 320 ob... - [NIST 800-53 Overlays: The 7 Categories Explained (2026)](https://governancedocs.com/nist-800-53-overlays/): NIST 800-53 overlays: the 800-53B definition, the 7 categories, baseline vs overlay vs tailoring, published overlays (SP... - [NIST 800-53 Privacy Controls: The 8 PT Controls Explained (2026)](https://governancedocs.com/nist-800-53-privacy-controls/): NIST 800-53 privacy controls: the PT family's 8 controls and 13 enhancements, the privacy baseline, privacy controls in... - [NIST 800-53 Rev 5 vs Rev 4: The 7 Clear Changes (2026)](https://governancedocs.com/nist-800-53-rev5-vs-rev4/): NIST 800-53 Rev 5 vs Rev 4: the 7 changes NIST lists, the new PT and SR families, what was withdrawn, where Rev 4 still... - [NIST 800-53A: The Clear Guide to Assessment Procedures](https://governancedocs.com/nist-800-53a/): NIST 800-53A Rev 5 explained: determination statements, the 3 methods (examine, interview, test), 4 object types, depth... - [NIST Cybersecurity Framework: A Guide to Getting Started](https://governancedocs.com/nist-cybersecurity-framework/): The NIST cybersecurity framework is your go-to roadmap for making smart, effective cybersecurity investments that protec... - [NIST SP 800-30 Risk Assessment: The 4 Essential Steps](https://governancedocs.com/nist-sp-800-30-risk-assessment/): A NIST SP 800-30 risk assessment is how you work out which risks actually matter to your organisation. The NIST Cybersec... - [NIST SP 800-55: A Clear Guide to Security Measurement Indicators](https://governancedocs.com/nist-sp-800-55/): NIST SP 800-55 (December 2024, two volumes): the 4 measure types, the 10 documentation fields, what makes a measure trus... - [PCI DSS Merchant Levels: A Clear Guide to All 4 in 2026](https://governancedocs.com/pci-dss-merchant-levels/): PCI DSS merchant levels explained: the 4 Visa and Mastercard tiers by transaction volume, ROC vs SAQ validation, and the... - [PCI DSS SAQ Types: The Complete 2026 Guide to Choosing Yours](https://governancedocs.com/pci-dss-saq/): There are nine PCI DSS SAQ types in v4.0.1. This 2026 guide compares all of them, explains the January 2025 SAQ A change... - [PCI DSS v4.0.1: A Clear Guide to the 2026 Version](https://governancedocs.com/pci-dss-v40-compliance/): PCI DSS v4.0.1 is the only active version since v4.0 retired. The 5 dates that matter, what the limited revision changed... - [PCI DSS vs ISO 27001: A Clear Guide to the 5 Differences](https://governancedocs.com/pci-dss-vs-iso-27001/): PCI DSS vs ISO 27001 on 5 differences — scope, enforcement, prescription, assessment cadence, output — with all 12 PCI r... - [Pillar 3 Disclosure: The Essential Basel DIS Templates Guide](https://governancedocs.com/pillar-3-disclosure/): Pillar 3 disclosure under the Basel DIS standard: scope and principles, template families from KM1 to LIQ2, frequency, t... - [Privacy by Design: 7 Principles, GDPR Article 25 and ISO 27701](https://governancedocs.com/privacy-by-design/): Privacy by design explained: Cavoukian's 7 principles, what GDPR Article 25 requires and how the EDPB reads it, the ISO... - [QHSE Management System: 4 Essential Standards Combined](https://governancedocs.com/qhse-management-system/): Most organisations arrive at quality, health and safety, and environment separately — three managers, three manuals, thr... - [Qualified Individual: The Complete WISP and Safeguards Rule Guide](https://governancedocs.com/qualified-individual/): The Qualified Individual under 16 CFR 314.4(a): what the Rule requires, what qualified means, 3 ways to fill the role, o... - [SAMA Business Continuity Management Framework: 9 Principles (2026)](https://governancedocs.com/sama-business-continuity-framework/): The SAMA Business Continuity Management Framework (2017): 9 principles, the control considerations that decide findings,... - [SAMA Cloud Computing Requirements: The Complete 3.4.3 Guide (2026)](https://governancedocs.com/sama-cloud-computing/): SAMA cloud computing requirements in CSF 3.4.3: SAMA approval before use or contract, data in Saudi Arabia unless approv... - [SAMA CSF Domains: All 4 and Their 32 Subdomains Explained (2026)](https://governancedocs.com/sama-csf-domains/): The 4 SAMA CSF domains and all 32 subdomains as the Framework names them — governance, risk and compliance, operations,... - [SAMA Cyber Threat Intelligence Principles: A Clear 19-Point Guide](https://governancedocs.com/sama-cyber-threat-intelligence/): The SAMA Cyber Threat Intelligence Principles (2022): 19 principles in 4 domains — core, strategic, operational, technic... - [SAMA IT Governance Framework: All 35 Subdomains Explained (2026)](https://governancedocs.com/sama-it-governance-framework/): The SAMA IT Governance Framework (Circular 43028139, 2021): 4 domains, 35 subdomains, the 0–5 maturity model, how it int... - [Saudi PDPL Breach Notification: The Complete 72-Hour SDAIA Guide](https://governancedocs.com/saudi-pdpl-breach-notification/): Saudi PDPL breach notification: 72 hours to SDAIA through the platform with 5 items, data subjects without undue delay,... - [Saudi PDPL Penalties: The 2 Tiers up to SAR 5 Million Explained](https://governancedocs.com/saudi-pdpl-penalties/): Saudi PDPL penalties: Article 35 criminal tier (2 years, SAR 3m) for sensitive-data disclosure, Article 36 fines up to S... - [Significant Data Fiduciary: 6 Essential Extra Duties (2026)](https://governancedocs.com/significant-data-fiduciary/): Significant Data Fiduciary under DPDP s.10 and Rule 13: India-based DPO, independent auditor, annual DPIA and audit, alg... - [SOX 302 vs 404: The 2 Certifications and 5 Clear Differences](https://governancedocs.com/sox-302-vs-404/): SOX 302 vs 404: quarterly CEO/CFO certifications vs the annual ICFR assessment and attestation, section 906, who signs w... - [SOX Compliance Cost in 2026: The Complete Breakdown](https://governancedocs.com/sox-compliance-cost/): SOX compliance cost by profile: 404(a)-only $200k–500k, accelerated filer $750k–2m, large accelerated $2.8–9m+ in year o... - [SOX Compliance: 5 Essential Steps to ICFR Readiness](https://governancedocs.com/sox-compliance/): Sarbanes-Oxley made internal control a named personal responsibility: under Sections 302 and 404, executives sign to say... - [SOX Control Testing: The Clear Guide to Sample Sizes (2026)](https://governancedocs.com/sox-control-testing/): SOX control testing under AS 2201: the principles, conventional sample sizes by frequency (annual 1 to daily 20–40), des... - [SOX ITGC: The 4 Essential IT General Control Domains (2026)](https://governancedocs.com/sox-itgc/): SOX ITGC explained: the 4 domains (access, change, development, operations), how they support application controls and I... - [SOX Scoping and Materiality: A Clear Top-Down Guide (2026)](https://governancedocs.com/sox-scoping/): SOX scoping and materiality under AS 2201: the top-down sequence, overall and performance materiality, qualitative facto... - [STAR Level 1: The Clear Guide to the CSA Self-Assessment (2026)](https://governancedocs.com/star-level-1/): STAR Level 1: the free CSA self-assessment behind ~2,479 of 2,765 registry listings, the CAIQ v4.1 submission version, C... - [STAR Registry: The Clear Guide to CSA’s 2,765 Listings (2026)](https://governancedocs.com/star-registry/): STAR Registry: ~2,765 CSA listings on 19 Sept 2026 — CAIQ, CAIQ Lite, Valid-AI-ted, Certification, Attestation, C-STAR,... - [Supply Chain Security: 2 Essential Assurance Routes](https://governancedocs.com/supply-chain-security/): Ask two companies how they prove supply chain security and you will get two unrelated answers. One will describe physica... - [SWIFT CSP Assessment Cost: A Realistic 2026 Estimate by Type](https://governancedocs.com/swift-csp-assessment-cost/): SWIFT CSP assessment cost by architecture type: assessor days × $1,200–2,500/day, from $1,800 (type B) to $25,000 (A1),... - [SWIFT CSP Attestation: 5 Essential Steps to Comply](https://governancedocs.com/swift-csp-attestation/): If your institution is on the SWIFT network, security is not a matter of internal policy. SWIFT CSP attestation is an an... - [SWIFT Mandatory Controls vs Advisory: All 32 Explained (2026)](https://governancedocs.com/swift-mandatory-controls/): SWIFT mandatory controls vs advisory in CSCF v2026: the 26 mandatory and 6 advisory controls, the A suffix, status vs ap... - [SWIFT Secure Zone: 6 Essential Design Rules for Control 1.1 (2026)](https://governancedocs.com/swift-secure-zone/): How to design the SWIFT secure zone under CSCF control 1.1: what goes inside by architecture type, 4 boundary controls,... - [TISAX Assessment Levels: AL 1, 2 and 3 Explained (2026 Guide)](https://governancedocs.com/tisax-assessment-levels/): TISAX assessment levels explained: what AL 1, AL 2, AL 2.5 and AL 3 involve, which of the 12 objectives need each, how t... - [TISAX Labels: All 12 Assessment Objectives Explained (2026 Guide)](https://governancedocs.com/tisax-labels/): TISAX labels explained: the 12 assessment objectives, the info-security label hierarchy, the prototype and data protecti... - [TISAX Prototype Protection: 20 ISA2027 Controls Explained (2026)](https://governancedocs.com/tisax-prototype-protection/): TISAX prototype protection under ISA2027: the 20 controls in 8.1 and 8.2, the 4 objectives that trigger them, what chang... - [TISAX Self-Assessment: 6 Proven Steps to a Clean Audit (2026)](https://governancedocs.com/tisax-self-assessment/): How to run a TISAX self-assessment: the 6 ISA maturity levels 0–5, the target level 3, how the result score with cutback... - [Valid-AI-ted: The AI-Scored STAR Level 1 Explained (2026 Guide)](https://governancedocs.com/valid-ai-ted/): Valid-AI-ted: CSA's AI-scored STAR Level 1 — $595 for up to 10 attempts, free to members, feedback and a badge — plus th... - [VDA ISA2027: What Changed and What It Means for Your TISAX Assessment](https://governancedocs.com/tisax-isa2027/): VDA ISA2027 replaces ISA 6 for every TISAX assessment ordered from 1 January 2027. What changed in the catalogue, the re... - [Verifiable Parental Consent: The Complete DPDP Rule 10 Guide](https://governancedocs.com/verifiable-parental-consent/): Verifiable parental consent under DPDP Rule 10: child = under 18, the 3 identity sources, 4 illustration cases, the exem... - [Vulnerability Management Metrics: 5 Critical Indicators for 2026](https://governancedocs.com/vulnerability-management-metrics/): The 5 vulnerability management metrics that matter — exposure, MTTR by severity, SLA adherence, backlog age, scan covera... - [Which States Use GovRAMP? The Complete 2026 List of 33 States](https://governancedocs.com/govramp-states/): Which states use GovRAMP: 72 participating organisations in 33 states, 30 with a state-level participant, join years fro... - [Who Needs BSI C5? Healthcare, Federal Government and 3 More (2026)](https://governancedocs.com/who-needs-bsi-c5/): Who needs BSI C5: the 5 customer groups — healthcare under § 393 SGB V (type 2 since July 2025), federal agencies, regul... ### General Guides (136) - [21 CFR Part 820: The Complete 2026 Section-by-Section Guide](https://governancedocs.com/21-cfr-part-820/): 21 CFR Part 820 section by section after the QMSR: what 820.1, 820.3, 820.7, 820.10, 820.35 and 820.45 require, and whic... - [AML Compliance Cost Under AMLR: A Practical 2027 Method](https://governancedocs.com/aml-compliance-cost/): AML compliance cost under AMLR: the provisions that drive it, where budgets break, and a worked method to size the build... - [AML Compliance Officer Under AMLR: The Essential 2027 Guide](https://governancedocs.com/aml-compliance-officer-amlr/): AMLR Article 11 requires two appointments, not one. What the AML compliance officer does, what the compliance manager do... - [AMLA Direct Supervision: Who Is Actually Selected in 2027](https://governancedocs.com/amla-direct-supervision/): AMLA direct supervision reaches about 40 cross-border financial groups, not the whole market. The three gates, the timet... - [AMLR 2027: The Complete Timeline to 10 July 2027](https://governancedocs.com/amlr-2027/): AMLR applies from 10 July 2027. The complete timeline: application dates, the 2029 football carve-out, AMLA supervision,... - [AMLR vs AMLD: What Actually Changes in 2027](https://governancedocs.com/amlr-vs-amld/): AMLR vs AMLD compared provision by provision: the two compliance roles, the 60-day SDD limit, retention that became dele... - [AS9100 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/as9100-certification-cost/): AS9100 certification cost explained: AS9104/1 Table 8 audit days, the mandatory 20% uplift, the $700 IAQG OASIS fee, and... - [Beneficial Owner 25 Percent: The Complete AMLR Calculation](https://governancedocs.com/beneficial-owner-25-percent/): The beneficial ownership threshold under AMLR Article 52: multiply along each chain, add across chains, and the separate... - [BES Cyber System Categorization: A Complete CIP-002 Guide](https://governancedocs.com/bes-cyber-system-categorization/): BES Cyber System categorization under CIP-002: the high, medium and low criteria, the process auditors test, and the 15-... - [CDD vs EDD: The Complete AMLR Comparison for 2027](https://governancedocs.com/cdd-vs-edd/): CDD vs EDD under AMLR: the eight mandatory enhanced triggers, the seven Article 34(4) measures, the 60-day SDD limit and... - [CIP-013 Supply Chain: The Complete 2026 Guide](https://governancedocs.com/cip-013-supply-chain/): CIP-013 supply chain risk management: the planning stage everyone skips, the six procurement elements, and what to do wh... - [CIP-014 Physical Security: The Complete 2026 Guide](https://governancedocs.com/cip-014-physical-security/): CIP-014 physical security explained: the two separate unaffiliated third-party gates at R2 and R6, the six R5 functions,... - [CIP-015: Internal Network Security Monitoring in 2026](https://governancedocs.com/cip-015-insm/): CIP-015 internal network security monitoring is not enforceable until 1 October 2028, not September 2025. What the stand... - [CMMC Level 2 Certification Cost: The Complete 2026 Breakdown](https://governancedocs.com/cmmc-level-2-certification-cost/): CMMC Level 2 certification cost runs about $104,670 over three years in DoD's own rule. Here's what to budget in 2026 wi... - [CMMC vs NIST 800-171: The Complete 2026 Guide for Defense Contractors](https://governancedocs.com/cmmc-vs-nist-800-171/): CMMC vs NIST 800-171 explained for 2026. The Department of War suspended CMMC Phase II on July 13, 2026, but all 110 NIS... - [Cyber Essentials Cost 2026: The Complete UK Price Guide](https://governancedocs.com/cyber-essentials-cost/): Cyber Essentials cost in 2026 runs £320 to £600 plus VAT by headcount, with Plus quoted separately from around £1,200. T... - [DORA Compliance Cost in 2026: The Complete Breakdown](https://governancedocs.com/dora-compliance-cost/): DORA compliance cost in 2026: why 64% of institutions budget €2–5 million, what a €250,000–€500,000 TLPT covers, and the... - [DPDP Act vs GDPR: The Complete 2026 Guide to 9 Differences](https://governancedocs.com/dpdp-act-vs-gdpr/): DPDP Act vs GDPR compared on 9 points: consent, a ₹250 crore fine cap vs 4% of turnover, children under 18, breach clock... - [Dual Control and Split Knowledge: The Difference That Fails Audits](https://governancedocs.com/dual-control-and-split-knowledge/): Dual control and split knowledge are two separate controls, not one. What each requires, the arrangements that look comp... - [FDA Complaint Records: The Complete 820.35 Guide for 2026](https://governancedocs.com/fda-complaint-records/): 820.35(a) names seven data elements for FDA complaint records, plus the justification record required when you decline t... - [FDA Device Labeling Controls: The Complete 820.45 Guide](https://governancedocs.com/fda-device-labeling-controls/): Section 820.45 is the most prescriptive part of the QMSR: five accuracy checks, a documented labeling release, and the m... - [FDA QMSR: The Complete 2026 Guide to 21 CFR Part 820](https://governancedocs.com/fda-qmsr/): The FDA QMSR took effect 2 February 2026. What changed in 21 CFR Part 820, what an ISO 13485 certificate does not eviden... - [Food Fraud and Food Defense: Why They Are Not the Same](https://governancedocs.com/food-fraud-and-food-defense/): Food fraud and food defense are separate FSSC 22000 requirements with different motives, assessments and plans. How to b... - [Food Safety Culture: The FSSC 22000 Requirement Explained](https://governancedocs.com/food-safety-culture/): Food safety culture as an auditable FSSC 22000 requirement: the four required elements, objectives with targets, and how... - [FSSC 22000 Additional Requirements: All 18 Groups Explained](https://governancedocs.com/fssc-22000-additional-requirements/): All 18 FSSC 22000 additional requirements groups and 66 lettered requirements, what each demands, and which food chain c... - [FSSC 22000 Certification Cost in 2026: Complete Breakdown](https://governancedocs.com/fssc-22000-certification-cost/): FSSC 22000 certification cost explained: how ISO 22003-1 and Scheme Part 3 fix your auditor days, the €330 Foundation fe... - [FSSC 22000 Certification in 2026: The Complete Guide](https://governancedocs.com/fssc-22000-certification/): FSSC 22000 certification explained: the three normative layers, the 18 Additional Requirement groups, how the audit work... - [FSSC 22000 Food Chain Categories: The Complete Breakdown](https://governancedocs.com/fssc-22000-food-chain-categories/): All 13 FSSC 22000 food chain categories, the prerequisite standard each carries, and how your category decides which Add... - [FSSC 22000 Version 7: Every Transition Date Explained](https://governancedocs.com/fssc-22000-version-7/): FSSC 22000 Version 7 transition dates, what changed, the ISO 22002 renumbering trap and a working order for the upgrade... - [FSSC 22000 vs ISO 22000: Which One Do You Need?](https://governancedocs.com/fssc-22000-vs-iso-22000/): FSSC 22000 vs ISO 22000 compared layer by layer: what the scheme adds, what it costs to run, and when ISO 22000 alone is... - [FTC Safeguards Rule for Tax Preparers: The 10 Requirements](https://governancedocs.com/ftc-safeguards-rule-for-tax-preparers/): The FTC Safeguards Rule for tax preparers sets ten obligations at 16 CFR 314.4. What each requires, what changed in May... - [GENIUS Act AML Requirements: The 6 Essential BSA Elements](https://governancedocs.com/genius-act-aml-requirements/): GENIUS Act AML requirements: section 4(a)(5) makes an issuer a BSA financial institution and names six elements, plus th... - [GENIUS Act Compliance Cost: A Practical 2027 Method](https://governancedocs.com/genius-act-compliance-cost/): GENIUS Act compliance cost has no published benchmark. A 7-step method to size it from the statute and your own book: ca... - [GENIUS Act Compliance Requirements: The Essential Section 4 Guide](https://governancedocs.com/genius-act-compliance-requirements/): GENIUS Act compliance requirements in one place: the 14 paragraphs of section 4(a) that bind a stablecoin issuer, from r... - [GENIUS Act Effective Date: The Complete 2027 Timeline](https://governancedocs.com/genius-act-effective-date/): GENIUS Act effective date is 18 January 2027 under section 20. The full timeline: the missed rulemaking deadline, the sa... - [GENIUS Act Reserve Requirements: The 8 Eligible Assets Explained](https://governancedocs.com/genius-act-reserve-requirements/): GENIUS Act reserve requirements: at least 1 to 1 in eight eligible asset classes, no rehypothecation, a monthly report a... - [GENIUS Act vs MiCA: The Essential Stablecoin Regime Comparison](https://governancedocs.com/genius-act-vs-mica/): GENIUS Act vs MiCA: who may issue, what backs the token, what the holder is promised, the usage cap, and the lawful-orde... - [HIPAA Compliance Cost in 2026: The Complete Breakdown](https://governancedocs.com/hipaa-compliance-cost/): HIPAA compliance cost in 2026 runs $3,000 to $35,000 in year one for most small organizations. A full line-item breakdow... - [HITRUST vs ISO 27001: 7 Essential Differences Explained (2026)](https://governancedocs.com/hitrust-vs-iso-27001/): HITRUST vs ISO 27001 compared on issuer, controls (43/182/tailored vs 93), scoring, validity (1–2 vs 3 years), cost and... - [IATF 16949 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iatf-16949-certification-cost/): IATF 16949 certification cost explained: the IATF Rules 6th Edition audit-day table, a $1,500/day registrar benchmark, a... - [IEC 62304 Documentation Requirements: Every Deliverable by Class (Clear 2026 Guide)](https://governancedocs.com/iec-62304-documentation-requirements/): IEC 62304 documentation requirements in one table: every deliverable the standard names, the class at which each is requ... - [IEC 62304 Edition 2: Release Date, What Changes and What To Do Now (Clear 2026 Update)](https://governancedocs.com/iec-62304-edition-2/): IEC 62304 Edition 2 status, September 2026: committee-draft stage, publication not before 2028, what the draft changes,... - [IEC 62304 FDA Guidance: Documentation Levels vs Safety Classes, Mapped (Clear 2026 Guide)](https://governancedocs.com/iec-62304-fda-guidance/): IEC 62304 FDA guidance explained: why Documentation Level is not software safety class, how each element of the June 202... - [IEC 62304 Legacy Software: The Clause 4.4 Route Explained Step by Step (Clear 2026 Guide)](https://governancedocs.com/iec-62304-legacy-software/): IEC 62304 legacy software under clause 4.4: who qualifies, the four-step route, the gap analysis scoped to 5.2, 5.3, 5.7... - [IEC 62304 Risk Management: How Clause 7 Fits ISO 14971:2019 (Clear 2026 Guide)](https://governancedocs.com/iec-62304-risk-management/): IEC 62304 risk management explained: clause 7 as the software slice of ISO 14971:2019, the five cause categories, the fo... - [IEC 62304 Software Safety Classification: Class A, B and C Explained (2026 Guide)](https://governancedocs.com/iec-62304-software-safety-classification/): IEC 62304 software safety classification explained: how Class A, B and C are decided, the Class C default, segregation,... - [IEC 62304 SOUP: What Counts and What You Owe at Every Class (Clear 2026 Guide)](https://governancedocs.com/iec-62304-soup/): IEC 62304 SOUP explained: what counts as software of unknown provenance, the identification and maintenance duties every... - [IEC 62304 vs IEC 82304-1: Which Standard Does SaMD Need? (Complete 2026 Comparison)](https://governancedocs.com/iec-62304-vs-iec-82304-1/): IEC 62304 vs IEC 82304-1 for software-only medical devices: one governs the software life cycle, the other the product a... - [IEC 62304 vs ISO 13485: How the Two Standards Fit Together (Clause-by-Clause, 2026)](https://governancedocs.com/iec-62304-vs-iso-13485/): IEC 62304 vs ISO 13485: one is the QMS, the other the software life cycle inside it. Clause-by-clause mapping to the 201... - [IEC 62443 Certification Cost in 2026: The Complete Guide](https://governancedocs.com/iec-62443-certification-cost/): IEC 62443 certification cost in 2026: ISASecure fees from $1,200 a year, assessment ranges of €15,000–€50,000 by role, a... - [IEC 62443 Certification: The Complete 2026 Guide](https://governancedocs.com/iec-62443-certification/): IEC 62443 certification explained: what is certified by role, how assessment requirements are selected, and what 4 thing... - [IEC 62443 Maturity Levels: The Complete 2026 Guide](https://governancedocs.com/iec-62443-maturity-levels/): IEC 62443 maturity levels explained: ML 1 to ML 4, why clause 4.2 makes documentation the substance of ML 2, and how to... - [IEC 62443 Parts Explained: The Complete 2026 Guide](https://governancedocs.com/iec-62443-parts-explained/): Which IEC 62443 parts do you actually need? 2-1, 3-2, 3-3, 4-1, 4-2 and 2-4 sorted by role, with current editions and 4... - [IEC 62443 Security Levels: The Complete 2026 Guide](https://governancedocs.com/iec-62443-security-levels/): IEC 62443 security levels explained: SL-T vs SL-C vs SL-A, how to assign a target level from risk, and how to verify a s... - [IEC 62443 vs ISO 27001: The Complete 2026 Comparison](https://governancedocs.com/iec-62443-vs-iso-27001/): IEC 62443 vs ISO 27001 compared: what Edition 2.0 changed in 2024, which requirements your ISMS already covers, and the... - [IEC 62443 Zones and Conduits: The Complete 2026 Guide](https://governancedocs.com/iec-62443-zones-and-conduits/): How to define IEC 62443 zones and conduits: the 8-step sequence, the 3 mandatory separations, and 8 questions that expos... - [IMS Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/ims-certification-cost/): IMS certification cost runs about $14,400-$30,000 in registrar fees for a 40-person company in 2026. How IAF MD 11 caps... - [Is ISO 27001 Worth It? The Complete 2026 ROI Breakdown](https://governancedocs.com/is-iso-27001-worth-it/): Is ISO 27001 worth it in 2026? A straight cost-versus-return breakdown: typical $8,000-$60,000 first-year spend, what ce... - [ISO 13485 Certification Cost: A Clear 2026 Breakdown](https://governancedocs.com/iso-13485-certification-cost/): ISO 13485 certification cost, broken down: the normative IAF audit-day table that sets your fee, indicative $1,100-$1,80... - [ISO 13485 Certification Timeline: The Complete 2026 Guide](https://governancedocs.com/iso-13485-certification-timeline/): ISO 13485 certification timeline explained: 6–18 months from kickoff to certificate, phase by phase, with the audit-day... - [ISO 14001 Certification Cost: A Complete 2026 Breakdown](https://governancedocs.com/iso-14001-certification-cost/): ISO 14001 certification cost runs about $4,000-$16,000 for a small company in 2026. Full breakdown of audit fees, hidden... - [ISO 14001 Certification Timeline: The Complete 2026 Guide](https://governancedocs.com/iso-14001-certification-timeline/): ISO 14001 certification timeline in 2026: 6–12 months kickoff to certificate, phase by phase, with audit-day tables and... - [ISO 17025 Accreditation Cost: The Complete 2026 Breakdown](https://governancedocs.com/iso-17025-accreditation-cost/): ISO 17025 accreditation cost in 2026: UKAS’s published £9,815 initial assessment, NVLAP’s $5,750 annual fee, and the $14... - [ISO 20000 Certification Cost: The Complete 2026 Breakdown](https://governancedocs.com/iso-20000-certification-cost/): ISO 20000 certification cost in 2026: how registrars set 3.5 to 15 audit days from ISO/IEC 20000-6, what $1,200 to $2,50... - [ISO 22002 Prerequisite Programmes: The 2025 Reissue Explained](https://governancedocs.com/iso-22002-prerequisite-programmes/): ISO 22002 prerequisite programmes were restructured and renumbered in 2025. Which part applies to your category, and the... - [ISO 22301 Certification Cost: A Complete 2026 Breakdown](https://governancedocs.com/iso-22301-certification-cost/): ISO 22301 certification cost runs about $2,500-$13,000 for a small or mid-sized company in 2026. Audit-day math, hidden... - [ISO 27001 Access Control Policy: The Complete 2026 Guide](https://governancedocs.com/iso-27001-access-control-policy/): What an ISO 27001 access control policy must contain in 2026 — the nine Annex A controls it carries, a ten-section outli... - [ISO 27001 Consultant Costs in 2026: The Complete Decision Guide](https://governancedocs.com/iso-27001-consultant/): What an ISO 27001 consultant does, what day rates look like in 2026, the impartiality rule that stops your adviser certi... - [ISO 27001 for Startups: The Complete 2026 Guide to Cost, Timeline and Payback](https://governancedocs.com/iso-27001-for-startups/): What ISO 27001 certification really costs a startup in 2026, how long it takes, the documents you must produce, and when... - [ISO 27001 Incident Response Plan: The Complete 2026 Guide](https://governancedocs.com/iso-27001-incident-response-plan/): What an ISO 27001 incident response plan must contain, the Annex A 5.24 to 5.28 controls behind it, a seven-step build,... - [ISO 27001 Nonconformity: The Complete 2026 Guide to Major vs Minor Findings](https://governancedocs.com/iso-27001-nonconformity/): How ISO 27001 nonconformity findings are classified as major or minor, the deadlines that follow, the six most common fi... - [ISO 27001 Recertification Audit: The Complete 2026 Guide](https://governancedocs.com/iso-27001-recertification-audit/): What happens at the year-three ISO 27001 recertification audit: the ISO/IEC 17021-1 timing rules, what auditors sample,... - [ISO 27001 Scope: The Complete 2026 Guide to Defining Your ISMS](https://governancedocs.com/iso-27001-scope/): Your ISO 27001 scope decides your audit days, your workload and what your certificate says. Clause 4.3 rules, three scop... - [ISO 27001 vs GDPR: The Complete 2026 Compliance Guide](https://governancedocs.com/iso-27001-vs-gdpr/): ISO 27001 vs GDPR: certification proves you secure data, but GDPR asks whether you should hold it at all. The overlaps,... - [ISO 27001 vs HIPAA: 7 Essential Differences Explained (2026)](https://governancedocs.com/iso-27001-vs-hipaa/): ISO 27001 vs HIPAA compared: law vs standard, 93 Annex A controls vs Security Rule safeguards, audits, breach rules, cos... - [ISO 27001 vs ISO 27002: The Complete 2026 Guide to Which One You Need](https://governancedocs.com/iso-27001-vs-iso-27002/): ISO 27001 vs ISO 27002 explained: one is a 19-page certifiable requirements standard, the other 152 pages of implementat... - [ISO 27001 vs ISO 27701: The Complete 2026 Decision Guide](https://governancedocs.com/iso-27001-vs-iso-27701/): ISO 27001 vs ISO 27701: since the 2025 edition a privacy system can be certified alone. Which you need, what overlaps, a... - [ISO 27001 vs TISAX: The Complete 2026 Supplier Guide](https://governancedocs.com/iso-27001-vs-tisax/): ISO 27001 vs TISAX compared for automotive suppliers: certificate versus ENX label, maturity level 3 scoring, AL2 vs AL3... - [ISO 27701 Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/iso-27701-certification-cost/): ISO 27701 certification cost in 2026: $6,000–$20,000 in year one as an ISO 27001 add-on, $10,000–$35,000 standalone, and... - [ISO 45001 Certification Cost: A Complete 2026 Breakdown](https://governancedocs.com/iso-45001-certification-cost/): ISO 45001 certification cost runs about $3,000-$14,000 for a small company in 2026. Audit-day math from IAF MD 22, hidde... - [ISO 45001 Certification Timeline: The Complete 2026 Guide](https://governancedocs.com/iso-45001-certification-timeline/): ISO 45001 certification timeline in 2026: 6–12 months from kickoff to certificate, phase by phase, with the OH&S audit-d... - [ISO 9001 Certification Timeline: The Complete 2026 Guide](https://governancedocs.com/iso-9001-certification-timeline/): ISO 9001 certification timeline in 2026: 4–12 months from kickoff to certificate, stage by stage, with audit-day tables... - [ISO 9001 Risks and Opportunities: The Definitive 2026 Guide](https://governancedocs.com/iso-9001-risks-and-opportunities/): ISO 9001 risks and opportunities in the 2026 edition: 6.1.2 for risks, 6.1.3 for opportunities, separate effectiveness r... - [ISO 9001:2026 Changes: The Complete 2015 vs 2026 Comparison](https://governancedocs.com/iso-9001-2026-changes/): ISO 9001:2026 changes explained clause by clause: 65 requirements — 46 unchanged, 16 revised, 2 new, 1 renumbered — and... - [ISO 9001:2026 Transition Checklist: 10 Essential Steps](https://governancedocs.com/iso-9001-2026-transition-checklist/): ISO 9001:2026 transition checklist: 10 steps from buying the text to the management review that records the transition,... - [NERC CIP Audit: The Complete 2026 Preparation Guide](https://governancedocs.com/nerc-cip-audit/): NERC CIP audit preparation: writing the RSAW narrative, computing your own intervals, the three checks worth running fir... - [NERC CIP Compliance: The Complete 2026 Guide](https://governancedocs.com/nerc-cip-compliance/): NERC CIP compliance explained: how RSAW audits work, the three evidence rules, the compliance calendar, and where progra... - [NERC CIP Low Impact: The Complete 2026 Guide](https://governancedocs.com/nerc-cip-low-impact/): NERC CIP low impact explained: the seven CIP-003 Attachment 1 topics, the vendor remote access control added in April 20... - [NERC CIP Patch Management: The Complete 2026 Guide](https://governancedocs.com/nerc-cip-patch-management/): NERC CIP patch management under CIP-007 R2: the two separate 35-calendar-day clocks, named patch sources, and mitigation... - [NERC CIP Standards: The Complete 2026 Guide to All 13](https://governancedocs.com/nerc-cip-standards/): NERC CIP standards explained: all 13 enforceable standards, 46 requirements, the 2028 cutover, and why CIP-015 is not ye... - [NERC CIP vs IEC 62443: A Clear 2026 Comparison](https://governancedocs.com/nerc-cip-vs-iec-62443/): NERC CIP vs IEC 62443 compared: mandatory versus voluntary, impact ratings versus zones and conduits, and how to run bot... - [NIS2 Compliance Cost in 2026: The Complete Breakdown](https://governancedocs.com/nis2-compliance-cost/): NIS2 compliance cost in 2026 runs €25,000 to €120,000 in year one for most important entities, more for essential ones.... - [NIS2 IEC 62443 Mapping: The Complete 2026 Guide](https://governancedocs.com/nis2-iec-62443/): A NIS2 IEC 62443 mapping of all ten Article 21(2) measures, plus the Article 23 reporting clock and what the mapping doe... - [NIST CSF 2.0 vs 1.1: The 79 Subcategories That Changed](https://governancedocs.com/nist-csf-2-0-vs-1-1/): CSF 2.0 withdrew 79 Subcategories and removed 12 Categories. The full mapping, the 16 outcomes with no predecessor, and... - [NIST CSF Audit Checklist: 6 Fields Every Line Needs](https://governancedocs.com/nist-csf-audit-checklist/): There is no CSF certification audit. What an internal NIST CSF audit checklist is for, the six fields each line needs, a... - [NIST CSF Maturity Levels: A Clear 5-Point Scale That Works](https://governancedocs.com/nist-csf-maturity-levels/): CSF 2.0 has no maturity model. Here is a defensible 5-point scale for scoring all 106 outcomes, why Tiers are not maturi... - [NIST CSF Policy Templates: What All 106 Outcomes Need](https://governancedocs.com/nist-csf-policy-templates/): What NIST CSF policy templates must cover across the six Functions, the documents most programmes are missing, and how t... - [NIST CSF Tiers: A Clear Guide to the 4 Implementation Tiers](https://governancedocs.com/nist-csf-tiers/): The 4 NIST CSF Tiers explained, including the two axes CSWP 29 scores them on and why Tier 4 is not the goal. No certifi... - [NIST CSF to 800-53 Mapping: A Clear Guide to All 106](https://governancedocs.com/nist-csf-800-53-mapping/): NIST maps all 106 CSF 2.0 outcomes to SP 800-53 Rev 5 with 740 control references. How to use the mapping properly, and... - [NIST Privacy Framework 1.1 vs 1.0: Every Change Mapped](https://governancedocs.com/nist-privacy-framework-1-1-vs-1-0/): NIST Privacy Framework 1.1 vs 1.0: four Categories retired, six added and all 34 Subcategory identifiers that moved, in... - [NIST Privacy Framework Data Map: How to Build One (ID.IM-P8)](https://governancedocs.com/nist-privacy-framework-data-map/): A NIST Privacy Framework data map shows every data action, store and party. What to include, how much detail, and the tw... - [NIST Privacy Framework Implementation Tiers: Not a Maturity Model](https://governancedocs.com/nist-privacy-framework-implementation-tiers/): NIST Privacy Framework Implementation Tiers: Partial, Risk Informed, Repeatable and Adaptive — and why Tier 4 is not the... - [NIST Privacy Framework Profiles: Current vs Target in 2026](https://governancedocs.com/nist-privacy-framework-profiles/): A NIST Privacy Framework Profile records what you achieve and what you need. How to build an honest Current Profile and... - [NIST Privacy Framework vs GDPR: How They Fit Together](https://governancedocs.com/nist-privacy-framework-vs-gdpr/): NIST Privacy Framework vs GDPR: one is a voluntary risk model, one is law. Where they overlap, where each goes further,... - [NIST Privacy Framework vs ISO 27701: Which One in 2026?](https://governancedocs.com/nist-privacy-framework-vs-iso-27701/): NIST Privacy Framework vs ISO 27701: a free risk model against a certifiable management system. Which to start with, and... - [NIST Privacy Framework: The Complete 2026 Guide](https://governancedocs.com/nist-privacy-framework/): The NIST Privacy Framework explained: the Core, Profiles and Implementation Tiers, all 102 Subcategories, and why versio... - [Notified Body Fees Under the MDR: A Clear 2026 Breakdown](https://governancedocs.com/notified-body-fees/): Notified body fees under the MDR from the 2026 price lists: €2,290–€3,000 audit days, €4,032 technical file days, and wh... - [OT Patch Management: The Complete 2026 Guide for IEC 62443](https://governancedocs.com/ot-patch-management/): OT patch management under IEC 62443: verify authenticity, test for compatibility, set urgency from real exposure, and re... - [OT Secure Remote Access: The Complete 2026 IEC 62443 Guide](https://governancedocs.com/ot-secure-remote-access/): OT secure remote access under IEC 62443: jump host architecture, individual identities and MFA, vendor access rules, ses... - [Payment Stablecoin: The Essential GENIUS Act Definition Explained](https://governancedocs.com/payment-stablecoin-definition/): A payment stablecoin under GENIUS Act section 2(22): the two limbs, the three exclusions, why a tokenised deposit is not... - [PCI DSS Compliance Cost: A Clear 2026 Price Breakdown](https://governancedocs.com/pci-dss-compliance-cost/): PCI DSS compliance cost in 2026 runs from about $500 a year on SAQ A to over $200,000 for a Level 1 ROC. Here is the ful... - [PCI PIN Key Blocks: The 3 Phases and What Phase 3 Did Not Require](https://governancedocs.com/pci-pin-key-blocks/): PCI PIN key blocks explained: the three phases, why Phase 3 never required existing POI deployments to convert, and how... - [PCI PIN Key Injection Facility: Normative Annex B Explained](https://governancedocs.com/pci-pin-key-injection-facility/): Key injection facility requirements under PCI PIN Annex B: the secure room, the clear-text injection dates and their rea... - [PCI PIN Remote Key Distribution: Normative Annex A Explained](https://governancedocs.com/pci-pin-remote-key-distribution/): Remote key distribution under PCI PIN Annex A: the two sub-annexes, the design assurance requirement, the three barrier... - [PCI PIN Scope: Which of the 145 Requirements Apply to You](https://governancedocs.com/pci-pin-scope/): PCI PIN scope explained: the four requirement columns, why 96 + 85 + 105 + 94 does not equal your total, and the four qu... - [PCI PIN Security Requirements: A Complete Guide to v3.1 in 2026](https://governancedocs.com/pci-pin-security-requirements/): PCI PIN Security Requirements v3.1 explained: 7 control objectives, 33 requirements, 145 sub-requirements, the four scop... - [PCI PIN vs PCI DSS: Which One Applies to You in 2026](https://governancedocs.com/pci-pin-vs-pci-dss/): PCI PIN vs PCI DSS explained: different assessors, no self-assessment route for PIN, a two-year cycle, and scope set by... - [Permitted Payment Stablecoin Issuer: The 3 Essential Types](https://governancedocs.com/permitted-payment-stablecoin-issuer/): A permitted payment stablecoin issuer is one of three types under GENIUS Act section 2(23). The regulator for each, the... - [Privacy Risk vs Cybersecurity Risk: The Critical 2026 Difference](https://governancedocs.com/privacy-risk-vs-cybersecurity-risk/): Privacy risk vs cybersecurity risk: why a privacy problem can arise from processing that is authorised, accurate and per... - [Problematic Data Actions: The Privacy Risk Security Misses](https://governancedocs.com/problematic-data-actions/): A problematic data action can arise from processing that is authorised, accurate and secure. The ten questions that find... - [QMSR Inspection: The Complete 2026 Guide to CP 7382.850](https://governancedocs.com/qmsr-inspection/): QSIT is gone. A QMSR inspection runs on Compliance Program 7382.850: six QMS Areas, 54 elements, four OAFRs, and records... - [QMSR Internal Audit: Why FDA Can Now Read Your Reports](https://governancedocs.com/qmsr-internal-audit/): Section 820.180(c) shielded internal audit, supplier audit and management review reports from FDA review. The QMSR withd... - [QMSR vs ISO 13485: The Complete 2026 Gap Analysis](https://governancedocs.com/qmsr-vs-iso-13485/): QMSR vs ISO 13485: the standard is incorporated into 21 CFR Part 820, so the real question is the delta. Fourteen requir... - [QSR to QMSR Transition: The Complete 2026 Mapping Guide](https://governancedocs.com/qsr-to-qmsr-transition/): All 31 old QSR sections mapped to where each requirement now lives under the QMSR, the one section with no successor, an... - [Qualified PIN Assessor: What a PCI PIN Assessment Involves](https://governancedocs.com/qualified-pin-assessor/): Qualified PIN Assessor explained: no self-assessment route, observation-led testing, the two-year listing clock that sta... - [Quality Culture and Ethical Behaviour: ISO 9001:2026 Essentials](https://governancedocs.com/quality-culture-ethical-behaviour/): Quality culture and ethical behaviour are new in ISO 9001:2026 (clauses 5.1.1, 7.1.4, 7.3): what the standard says, what... - [SOC 2 vs HIPAA: The Complete 2026 Compliance Guide](https://governancedocs.com/soc-2-vs-hipaa/): SOC 2 vs HIPAA compared: HIPAA is US federal law, SOC 2 is an AICPA attestation. See what each covers, where they overla... - [Suspicious Transaction Report Deadline: The Complete AMLR Guide](https://governancedocs.com/suspicious-transaction-report-deadline/): A suspicious transaction report under AMLR has no fixed filing period. The clocks that do run, the two reportable catego... - [The NIST CSF GOVERN Function: All 31 Outcomes Explained](https://governancedocs.com/nist-csf-govern-function/): The GOVERN function is 31 of the 106 CSF 2.0 outcomes across six Categories, ten of them supply chain. What it asks for,... - [The Purdue Model in 2026: A Complete OT Security Guide](https://governancedocs.com/purdue-model-ot-security/): The Purdue model explained for OT security: all 7 levels, why a level is not a zone, 7 departures real plants make, and... - [TISAX Certification Cost in 2026: The Complete Breakdown](https://governancedocs.com/tisax-certification-cost/): TISAX certification cost in 2026: the €405 ENX fee, AL2 vs AL3 audit provider fees, preparation ranges, hidden follow-up... - [User Access Review: A Complete 2026 Guide for ISO 27001 and SOC 2](https://governancedocs.com/user-access-review/): A user access review is the control auditors test hardest. Here is the seven-step process, the ISO 27001 A.5.18, SOC 2 C... - [Vendor Security Questionnaire: The Complete 2026 Response Playbook](https://governancedocs.com/vendor-security-questionnaire/): A vendor security questionnaire slows deals only when you improvise. Here are the four formats, the ten recurring contro... - [Who Does the FTC Safeguards Rule Apply To? The Complete 2026 Guide](https://governancedocs.com/who-does-the-ftc-safeguards-rule-apply-to/): The FTC Safeguards Rule covers 13 types of non-bank financial institution, not just banks. Here is the two-part coverage... - [WISP for Sole Practitioners: 4 Elements You Can Safely Skip](https://governancedocs.com/wisp-for-sole-practitioner/): A WISP for sole practitioners is smaller, but not for the reason most assume. What 16 CFR 314.6 disapplies below 5,000 c... - [Written Information Security Plan Template: The 10 Elements](https://governancedocs.com/written-information-security-plan-template/): A written information security plan template is only the shape. Here is what a WISP must contain under 16 CFR Part 314,... ## Policies and Terms - [Terms and Conditions](https://governancedocs.com/terms-and-conditions/): Clause 3 is the product licence. A toolkit is licensed to a single organization. - [Privacy Policy](https://governancedocs.com/privacy-policy/) - [Refund and Return Policy](https://governancedocs.com/refund-and-return-policy/): 30 days from purchase. - [Delivery Policy](https://governancedocs.com/delivery-policy/): Instant download after checkout. ## Contact Governance Docs LLC, 1209 Mountain Road PL NE, Ste R, Albuquerque, NM 87110, United States - https://governancedocs.com/contact-governance-docs/