The Scrutineer blog
Continuous compliance and vendor risk, made practical
Practical writing on scrutinizing any company, including your own: how to map your controls to the frameworks that matter, collect evidence automatically, flag gaps before an auditor does, and score third-party vendor risk without slowing the business. No fluff, just what helps you stay audit-ready.
Vanta Pricing and Cost for Every Plan
Vanta pricing on AWS starts at $14,000 a year for Essentials, $21,500 for Plus and $23,000 for Professional. The median buyer pays $20,000 a year.
Drata Pricing and What Buyers Actually Pay
Drata pricing on AWS is a $25,000 platform fee plus $7,500 per framework, or $15,000 for 1 to 50 employees. The median buyer pays $25,000 a year.
Secureframe Pricing and What Buyers Actually Pay
Secureframe pricing starts at $15,000 a year on AWS, a $7,500 platform plus a $7,500 first framework, and the median buyer pays $20,000. What moves a quote.
ProcessUnity Pricing and What CyberGRX Costs
ProcessUnity pricing starts at $25,000 a year on its own pages, CyberGRX lists at $17,850 on Vendr, and big enterprises get a quote. What moves your price.
Thoropass Pricing and What the Audit Adds
Thoropass pricing starts at $8,700 a year for the platform plus $5,800 for a SOC 2 audit on AWS, and the median buyer pays $25,000. What moves your quote.
SecurityScorecard Pricing and Cost for TPRM
SecurityScorecard pricing is quote-only. The median buyer pays $23,619 a year, and its AWS listing prices 5 domains at $13,500. What each plan adds.
Bitsight Pricing and Cost, What Buyers Pay
Bitsight pricing is quote-only. Buyers pay a median $23,640 a year across 64 purchases, and the enterprise AWS listing is $138,550. How the meter works.
Hyperproof Pricing and Cost, What Buyers Pay
Hyperproof pricing is quote-only. Buyers pay a median $41,400 a year across 44 purchases, $22,215 to $70,000. What moves the quote and how to cut it.
UpGuard Pricing and Vendor Risk Plan Costs
UpGuard pricing: Vendor Risk Standard is $1,750 a month billed annually for 50 vendors. Every tier, the $79 per-vendor math, and what sits outside the price.
OneTrust Pricing and Cost for GRC and TPRM
OneTrust pricing is quote-only. The median buyer pays about $12,000 a year across 309 Vendr purchases, and GRC plus TPRM costs more. What drives a quote.
Best HIPAA and PCI Compliance Software
Seven HIPAA and PCI compliance platforms compared by origin, plus the control overlap table that shows which framework sets the floor where both apply.
SOX Compliance Software and Best SOX Testing Tools
SOX compliance software and SOX testing tools compared by origin (Workiva, Optro, Diligent, Pathlock, HighRadius, Archer), plus your Section 404 duties.
Best Model Audit Rule software for insurers
Model Audit Rule software compared, plus the three NAIC premium tests, the three compliance clocks and why no auditor ever signs your ICFR assertion.
Best DDQ software and 8 due diligence tools compared
Eight DDQ tools compared on what each is built for, where its answers come from and which publish a price, plus the 57 questions libraries get wrong.
ACH audit services for third-party senders
Four ways a Third-Party Sender can get its annual ACH Rules audit done, what each one produces, and what the 30-day Nacha proof-of-audit clock now demands.
PCI compliance software for service providers
Service providers get one SAQ, not ten, plus 17 requirements merchants never see. What the five categories of PCI tool actually produce, and where each stops.
Best Section 889 compliance software
Three different tools are sold as Section 889 compliance software and only one produces the record the FAR actually enforces. What to buy, and why.
ARC-AMPE compliance cost and timeline
CMS charges nothing for ARC-AMPE. What the MARS-E 2.2 migration really costs, the control baselines by entity type, and what a missed deadline changes.
TX-RAMP certification cost and timeline
Texas DIR charges nothing for TX-RAMP certification. What the work really costs, the control counts by level, and the deadline that changed in 2026.
TPRM software comparison of 9 vendor risk tools
Nine third-party risk platforms compared on where the evidence comes from, what each one bills you for, and exactly where each one stops being useful.
Best HIPAA Risk Assessment Software
Five kinds of tool are sold for the HIPAA risk analysis, and each produces a different document. What each covers, where it stops, and what OCR looks for.
Best Integrated Risk Management Software
Five different products are sold as integrated risk management software, and each produces a different artifact. What each does, and where it stops.
Best AI Vendor Risk Management Software
Five kinds of tool are sold against AI vendor risk, and each is blind to something the others catch. What each produces, and where each one stops.
Best Enterprise Risk Management (ERM) Software
Best ERM software compared by the document each one produces, from enterprise GRC suites to bank ERM tools, with costs and where each stops.
Best Fourth-Party Risk Management Software
There is no clean product category here. Four different kinds of tool are sold against fourth-party risk, each blind to something the others catch, and the cheapest discovery method is already sitting in the SOC 2 reports you collected at onboarding.
GovRAMP Certification Cost and TX-RAMP Pricing
What GovRAMP actually charges at each status on the published fee schedule, what the third party assessor adds on top, why Texas charges nothing at all, and the counterintuitive reason the cheapest looking status is usually the most expensive route.
Best CSA STAR Certification Software
The four categories of tooling sold against CSA STAR, what each one actually produces, why no software can issue a Level 2 listing, and the CCM v4.1 migration deadline that should be driving your buying decision this year.
Best HECVAT Software for Higher Ed Vendors
The four categories of tooling that claim to answer a HECVAT, what each one actually does and where it stops, plus why the Lite versus Full comparison you are reading was retired by HECVAT 4 in 2025.
Best AI Governance Tools and Platforms
The four categories of AI governance tooling compared on what each actually produces, why buying model evaluation when you needed program evidence is the expensive mistake, and which AI rules are genuinely in force for a US company in August 2026.
Best Data Privacy Management Software
Best data privacy management software for US companies, sorted into four tool types with costs, five buying questions and the scope test most teams skip.
SOC 1 Compliance Checklist and What Auditors Test
There is no standard SOC 1 checklist, and that is not a technicality. SOC 2 gives you fixed criteria; SOC 1 makes your own management write the control objectives, and the CPA firm tests what you wrote. Here is what auditors actually test, which layers generalize across every service organization, what a Type 2 costs, and why the bridge letter you were planning on may not be accepted.
FISMA vs FedRAMP and When Each One Applies
They are not competing certifications. FISMA is the law, FedRAMP is the program that makes cloud assessments reusable, and a large share of federal contractors asking the question need neither because the data sits on their own network. Here is the boundary test that decides it, what the 2026 rules renamed, and why reuse matters more than strictness.
What is GLBA Compliance and Who Must Comply
GLBA does not apply to banks alone. It reaches tax preparers, collection agencies, car dealerships that arrange financing and Title IV universities, and which regulator supervises you decides whether MFA and annual penetration testing are mandatory or merely advisable. Here is who is covered, how to tell, and what the rule actually requires.
Computer Software Assurance vs CSV and What Changed
The FDA issued an updated final Computer Software Assurance guidance on February 3, 2026, superseding the September 24, 2025 version and aligning it to the new QMSR. Here is what CSA actually changes against traditional computer system validation, how to decide the assurance effort a system needs, and the 21 CFR Part 11 trap in the middle of it.
GovRAMP vs StateRAMP and What the Rename Changed
StateRAMP became GovRAMP on February 14, 2025. It was a rebrand, not a restructure: existing authorizations, memberships, requirements and pricing all carried across unchanged. Here is what the status ladder actually means, why GovRAMP Ready does not expire the way FedRAMP Ready does, and why the reciprocity between the two programs runs in only one direction.
FFIEC CAT Sunset and What Replaces the CAT
The FFIEC retired the Cybersecurity Assessment Tool on August 31, 2025 and named no successor, stating that it does not endorse any particular tool. Here is what the sunset statement actually said, how the four named alternatives compare for a financial institution, and why the self-assessment expectation survived the tool.
FTC Safeguards Rule Requirements and Exemptions
The FTC Safeguards Rule requires non-bank financial institutions, including auto dealers, tax preparers and mortgage brokers, to run a written information security program with nine specific elements. Here is what each element requires, exactly what the fewer than 5,000 consumers exemption covers, and the breach notification duty in force since May 2024.
ITGC and ITAC Explained (IT General Controls)
ITGC means IT general controls: the four domains auditors test around your systems, covering access to programs and data, change management, program development and computer operations. Here is what sits in each domain, how ITGC differs from ITAC, and the evidence a SOX or SOC 2 auditor actually samples.
AI Governance Framework and ISO 42001 vs NIST RMF
ISO 42001, the NIST AI Risk Management Framework and the EU AI Act compared on what they require, what they produce and who they satisfy, plus where US state AI law actually stands in 2026 and how to pick the framework your buyers are really asking for.
User Access Review Process Steps and Evidence
The user access review process in six steps, the four pieces of evidence auditors actually sample, how often to run reviews under SOC 2, SOX, PCI DSS and ISO 27001, and the five exceptions that get written up most often.
Fourth-Party Risk Management in Practice
Fourth-party risk is the exposure your vendors' vendors create for you. Here is what a fourth party is, the four documents that already name yours, how to build a map that stays current, and the concentration failure mode ordinary vendor tiering misses.
Best Security Questionnaire Automation Software
Security questionnaire automation is two different products that get reviewed as one: tools that answer the questionnaires customers send you, and tools that send questionnaires to your vendors. Here are the platforms US buyers shortlist in each, the reported pricing, and the answer-library trap to avoid.
HITRUST vs SOC 2 Differences, Cost and Which One Buyers Ask For
SOC 2 is a CPA attestation you help scope. HITRUST is a scored certification HITRUST itself issues. Here is what each proves, the reported costs, where the controls overlap, and how to tell which one your customers actually require.
Vendor Tiering Criteria, a 3-Tier Model and Review Cadence
Vendor tiering decides how much diligence each vendor earns. Here are the five criteria that set a tier, a three-tier model to copy, and reassessment cadence.
Best Third-Party Risk Management Software 2026
The TPRM market is really three products: assessment exchanges, security ratings and enterprise risk suites. Here are the ten platforms US buyers shortlist, what each is genuinely best at, the reported pricing, and how to tell which category you need.
FedRAMP 20x vs Rev 5 Requirements, Timeline and the CR26 Classes
FedRAMP 20x is now the default path and Rev 5 closes to new applications in June 2027. Here is the real difference between them, the CR26 timeline, the new Certification Classes A through D, and how to choose.
CMMC Phase 2 Suspended and What Still Applies
The DoD suspended CMMC Phase 2 on July 13, 2026, pausing third-party C3PAO assessments. Phase 1 self-assessments, NIST SP 800-171 Rev 2 and DFARS 252.204-7012 all remain in force. Here is what changed, what did not, and what to do with the gap.
AuditBoard Is Now Optro and the Best Alternatives
AuditBoard was renamed Optro in March 2026 under owner Hg. Here is what actually changed for the platform and its customers, and the lighter alternatives for teams that mainly need SOC 2, ISO 27001 and vendor risk.
What Is SOC 2 Compliance? A Plain-English Guide
What is SOC 2 compliance, how the Trust Services Criteria work, who needs a report, and how to map controls to evidence and stay audit-ready before an accredited auditor issues your attestation.
SOC 2 Type 1 vs Type 2 and Which Report You Need
SOC 2 Type 2 versus Type 1 explained: what each report proves, how the audit period and operating effectiveness differ, and how to decide which one your customers and auditors expect.
SOC 2 Audit Checklist in 12 Steps to Audit-Ready
A practical SOC 2 audit checklist: scope your Trust Services Criteria, map controls, collect evidence, close gaps, run a readiness review, and walk into the audit with everything an auditor will ask for.
ISO 27001 vs SOC 2 and How to Choose (or Run Both)
ISO 27001 vs SOC 2 compared: certification versus attestation, framework structure, overlapping controls, and how to pick the right one or pursue both without duplicating evidence work.
The Vendor Risk Management Process, Step by Step
A repeatable vendor risk management process: intake and tiering, due diligence, security questionnaires, scoring third-party risk, continuous monitoring, and remediation across your vendor lifecycle.
How to Automate Security Questionnaires (Both Sides)
Security questionnaire automation for the answering and the sending side: build an answer library, auto-draft responses from your controls, and review vendor answers faster without losing accuracy.
How Much Does a SOC 2 Audit Cost? (2026 Breakdown)
SOC 2 audit cost in 2026: real auditor fee ranges for Type 1 and Type 2, plus readiness, pen testing, tooling and internal time, and the four decisions that drive your total spend.
SOX Compliance Requirements and the ITGC Checklist
SOX compliance requirements explained for IT and security: Section 302 vs 404(a) and 404(b), who must comply, the ITGC domains auditors test first, and the evidence each one needs.
How Long Does ISO 27001 Certification Take?
ISO 27001 certification takes 3 to 12 months. A phase-by-phase timeline covering scoping, the ISMS operating period, Stage 1 and Stage 2 audits, surveillance, and the 3-year recertification cycle.
GRC Meaning Explained (Governance, Risk and Compliance)
GRC means governance, risk and compliance: the discipline of running policies, risk management and regulatory obligations as one connected program. What GRC is in cyber security, what GRC tools do, and when a spreadsheet stops being enough.
HIPAA Compliance Checklist for IT Teams in 2026
A HIPAA compliance checklist you can actually run: the Security Rule safeguards step by step, the risk analysis, BAAs, training and breach readiness, plus the IT compliance checklist items auditors and OCR investigators ask for first.
Best SOC 2 Compliance Software Compared (2026)
Best SOC 2 compliance software in 2026, compared honestly: Scrutineer, Vanta, Drata, Secureframe, Sprinto and Hyperproof, with reported pricing, strengths, trade-offs and who each platform actually fits.
Best Compliance Management Software for US Teams
Best compliance management software compared by what each platform was actually built for: Optro, Hyperproof, LogicGate, OneTrust, MetricStream, Archer.
Best GRC Software in 2026 Across 8 Platforms
Best GRC software compared honestly for 2026: Scrutineer, OneTrust, Vanta, Drata, Hyperproof, Sprinto, Thoropass and UpGuard, with reported pricing, real strengths and trade-offs, and who each GRC tool actually fits.
PCI Compliance Checklist of 12 PCI DSS Requirements
A PCI compliance checklist built on PCI DSS v4.0.1: all 12 requirements explained, the future-dated controls now enforceable, how to pick your SAQ and merchant level, and the evidence a QSA will ask you for.
GDPR Compliance Checklist for US Companies (2026)
A GDPR compliance checklist written for US companies: when GDPR actually applies to a business with no EU office, the Article 27 representative, lawful basis, DSARs, 72-hour breach notice, transfers after the Data Privacy Framework, and the evidence to keep.
How to Conduct a Cybersecurity Risk Assessment (Step by Step)
How to conduct a cybersecurity risk assessment step by step: scope, inventory assets, identify threats, score by likelihood and impact, rank the results, assign treatments, and reassess continuously. Built on the NIST SP 800-30 methodology.
Compliance Automation Software Pricing for 12 Platforms
Compliance automation software pricing in 2026: reported annual costs for Vanta, Drata, Secureframe, Sprinto, Hyperproof, OneTrust, Panorays, Whistic and more, re-verified in July 2026, plus the separate audit fee.
ISO 27001 Annex A Controls List With All 93 Controls
The complete ISO 27001:2022 Annex A controls list: all 93 controls by number and name across the four themes, the 11 controls new in 2022, how the Statement of Applicability decides which apply, and the evidence auditors ask for.
Ready to put it to work? See how scrutiny works, explore the readiness report, or compare plans.
Reading is good. A live, monitored posture is better.
Connect your stack and watch Scrutineer map your controls to SOC 2, ISO 27001, HIPAA, GDPR and PCI, collect evidence automatically, flag gaps, and score every vendor you trust against a clear readiness report and prioritized gap list. AI scrutinizes, you decide. An accredited auditor still issues the attestation.
Automated evidence · Per-control statuses · Prioritized gap list