Policy + Compliance

Understand the rules your business has to follow, and how to meet them.

Compliance comes down to three things: rules someone wrote, people who check that you follow them, and the proof you keep. This site explains each standard, regulation and certification in plain words. What it is, whether it applies to you, what you have to write down, who checks it, and who can help. Every page names its sources.

Share
Sponsored
Policy  Acknowledgment  Proof
Acknowledgedv3.2 14:02by name, on record
The Proof is Yourswith AllyMatter
Prove It the Modern WayEvery policy this site tells you to write, acknowledged by name
01
Approve it, lock the version
Non-author approval, obsolete copies blocked
02
Every name on record
Version-bound, re-collected on change, survives departure
03
Walk in with the trail
From $29/mo, 20 editors, unlimited staff (published)

Start here

The standards people ask about most.

Eight names that come up in almost every contract, audit or customer questionnaire. Each explainer says what the standard is, who has to follow it, what you must write down, and who checks it.

Every standard →
StandardSOC 2

A report from a CPA firm on how a company protects customer data. Customers ask for it before they sign; there is no certificate, only the report.

Checked by: A licensed CPA firm (independent certified public accountants) perform
StandardISO 27001

The international standard for running information security as a managed system. An accredited registrar certifies it; consultants help you build it.

Checked by: An accredited certification body (registrar) operating under ISO/IEC 1
StandardHIPAA

US rules for protecting patient health information. There is no certification; the Office for Civil Rights checks your policies and records after a complaint or breach.

Checked by: Government enforcement only. OCR investigates complaints and breach re
StandardISO 9001

The quality management standard most manufacturers and service firms are asked for by customers. A registrar audits it and issues a certificate every three years.

Checked by: Accredited certification body (registrar) accredited to ISO/IEC 17021-
StandardPCI DSS

The card brands' security rules for anyone who takes card payments. Small merchants self-assess; larger ones use a qualified assessor.

Checked by: A PCI SSC qualified Qualified Security Assessor (QSA) company with cer
StandardCMMC/NIST 800-171

The Department of Defense's cybersecurity requirement for contractors that handle controlled information. Assessed by accredited third parties from late 2026.

Checked by: Level 1 and Level 2 (self): the organization's own assessment with sen
StandardOSHA written programs

The safety plans US employers must keep in writing, such as hazard communication and emergency action. Inspectors ask for the document and the training records.

Checked by: OSHA compliance safety and health officers, or State Plan inspectors (
StandardGDPR

The European Union's data protection law. It applies to any business that handles EU residents' data, wherever the business sits.

Checked by: No mandatory assessor. Supervisory authorities (for example CNIL, the

Need a hand implementing it?

Find a Consultant Who Does This Work

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

From the publisher

Keep Your Written Policies in One Place

Whatever you are working toward, AllyMatter gets your policies approved, keeps every version and records who has read each one.

See how AllyMatter works From $29/mo, 20 editors, unlimited staff

Questions

Cost, independence, and how to choose.

Why does a category with 16 tools publish only 3 prices?

Dedicated policy managers and GRC suites sell through quotes so the price can follow the deal size. The pricing ledger tracks each vendor’s pricing page monthly and records the date it last showed a number, or returned an error.

Does an acknowledgment count as a signature?

Not automatically. An acknowledgment record ties a named person to a document version at a time. Some obligations, such as FMCSA 382.601, ask for a signed receipt. Profiles state which of the two a tool actually captures.

Can my consultant also certify us?

No, for accredited certifications. See the two-contracts table above. Directory profiles for assessors carry an independence line for this reason.

Who owns this site, and does it affect the picks?

AllyMatter, one of the listed tools. Its listing is labeled every time it appears, it is excluded from picks, and the matching form ignores who owns what. On pages for frameworks it supports, the one labeled Sponsored slot carries its own ad, placed by the publisher at no charge. It appears nowhere else. The full method is on the methodology page.

How does a firm get verified?

A human here checks the record against the firm’s own site and public filings, dates the check, and repeats it within 90 days. Firms can confirm their own listing and supply the fields we could not check.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.