⚠️ Important: All content, templates, tools, and information on this site are provided for informational purposes only and do not constitute legal advice, audit advice, or professional compliance advice. Use of any template does not guarantee regulatory compliance or audit certification. Read full disclaimer ↓

Compliance Documentation Kits

Audit-ready
compliance docs
in hours.

Professional GDPR, HIPAA, SOC 2, CMMC, DORA and NYDFS kits. Fillable PDF templates, gap assessment tools, and evidence trackers. Built by a compliance professional who has shipped HIPAA-compliant SaaS.

S
M
A
J

Trusted by SaaS founders, CTOs, and vCISOs
going through their first GDPR, HIPAA, CMMC, DORA, SOC 2 or NYDFS audit

SOC 2 Readiness Dashboard
OVERALL SCORE
68 / 100
Moderate Risk
CC6 — Access Control45%
CC8 — Change Mgmt72%
A1 — Availability88%
Information Security Policy
Change Management Policy
Quarterly Access Reviews
~
Vendor Risk Assessments
DR Plan Tested
🛡️ GDPR + UK GDPR + CCPA
All SOC 2 Trust Service Criteria
🏥 HIPAA 45 CFR Part 164
🏛️ NYDFS 23 NYCRR 500
🇺🇸 CMMC / NIST 800-171
🇪🇺 DORA / ICT Risk
Instant download
📋 Fillable PDFs
🔧 Free gap assessment tools
Products

Pick your compliance kit

Every kit includes fillable PDF templates mapped to the relevant standard — and a free interactive tool to assess your gaps before you start.

🇪🇺
GDPR Compliance

GDPR Compliance Kit

For any business with EU, UK, or California users. Six professionally drafted fillable PDFs covering every GDPR requirement, plus a free gap assessment tool.

Starter Kit
Privacy Policy + Cookie Policy
$39
Full GDPR Kit ★
16 templates + Gap Assessment Tool
$99
SaaS Bundle
Full Kit + Data Retention + Employee Policy
$179
Full Kit includes:
  • Privacy Policy (GDPR + CCPA + UK GDPR)
  • Cookie Policy Template
  • Data Processing Agreement (Art. 28)
  • Subject Access Request Workflow (Art. 15)
  • Data Breach Notification — 72hr (Art. 33/34)
  • 50-Point GDPR Compliance Checklist
  • DPIA Template (Art. 35)
  • Data Inventory & ROPA (Art. 30)
  • Data Mapping Template (Art. 30/32)
  • Privacy by Design & Default Policy (Art. 25)
  • Lawful Basis Assessment (Art. 6/9)
  • Data Subject Rights Procedures (Art. 15–22)
  • Security of Processing — TOMs (Art. 32)
  • Data Retention Policy (Art. 5(1)(e))
  • Consent Management Framework (Art. 7/8)
  • Privacy Notices — 6 types (Art. 13/14)
  • Free Gap Assessment Tool
🏥
HIPAA Compliance

HIPAA Compliance Kit

For medical practices, digital health startups, and business associates. Fourteen templates covering every safeguard category, including the Security Risk Assessment OCR checks first.

Starter Kit
Notice of Privacy Practices + BAA
$29
Full HIPAA Kit ★
14 templates + Risk Assessment Tool
$79
Business Associate Bundle
Full Kit + Vendor Tracking + Due Diligence
$129
Full Kit includes:
  • Notice of Privacy Practices (§164.520)
  • Business Associate Agreement (§164.502(e))
  • Security Risk Assessment (§164.308(a)(1)(ii)(A))
  • Risk Management Plan (§164.308(a)(1)(ii)(B))
  • Breach Notification Procedure — 60-day (§164.400–414)
  • Workforce Training & Sanctions Policy (§164.308(a)(5))
  • Access Control Policy (§164.312(a))
  • Audit Controls & Activity Review Policy (§164.312(b))
  • Device & Media Controls Policy (§164.310(d))
  • Minimum Necessary Standard Procedures (§164.502(b))
  • Workstation & Physical Security Policy (§164.310(b)/(c))
  • Incident Response Plan (§164.308(a)(6))
  • Patient Rights Request Procedures (§164.524/526/528)
  • 50-Point HIPAA Compliance Checklist
  • Free Risk Assessment & Gap Tool
🏛️
NYDFS Cybersecurity

NYDFS 23 NYCRR 500 Kit

For banks, insurers, and other covered entities regulated by the NY Department of Financial Services. Documentation mapped to every Part 500 requirement, plus a live gap assessment tool.

Essentials
Policy + Risk Assessment + Cert. Checklist — PDF + Word
$39
Complete Compliance Kit ★
14 documents + Gap Assessment Tool
$99
Enterprise / Multi-Entity
Complete Kit + 5 enterprise documents + unlimited entities
$179
Complete Kit includes (14 documents):
  • Cybersecurity Policy Template (§500.03)
  • Risk Assessment Workbook (§500.09)
  • Incident Response Plan Template (§500.16)
  • Annual Certification Checklist (§500.17(b))
  • Vendor / TPSP Risk Questionnaire (§500.11)
  • CISO Board Reporting Template (§500.04)
  • 9 more policies: MFA, encryption, access control, data retention, pen testing, training & audit trail
  • Every document as fillable PDF + editable Word
  • Free interactive Gap Assessment Tool — all 23 sections + Class A determination
Enterprise tier also adds (5 documents):
  • Multi-Entity Risk Assessment Matrix
  • Group / Affiliate Policy Template Set + Class A Designation Worksheet
  • Consolidated Incident Response Plan with entity-specific annexes
  • Certification Tracker for multi-entity annual filings
  • Vendor / TPSP Risk Tracker with shared-vendor concentration view
  • Unlimited-entity license — built for holding companies, affiliate groups & MSPs
🇺🇸
CMMC Compliance

CMMC Compliance Kit (Level 1 & 2)

For DoD contractors and subcontractors handling FCI or CUI under DFARS 252.204-7021. Documentation mapped to all 110 NIST SP 800-171 requirements, plus a live gap assessment tool.

Essentials (Level 1)
SSP + Policy + Annual Affirmation Checklist
$59
Complete Kit (Level 2) ★
18 documents + Free Gap Assessment Tool
$179
Enterprise (Level 2, C3PAO-Ready)
Complete Kit + Evidence Matrix + Mock Assessment + Flow-Down
$279
Complete Kit includes (18 documents):
  • System Security Plan — all 110 NIST SP 800-171 requirements
  • 14 policies — one per control family, cross-referenced to the SSP
  • POA&M Tracker — auto-filling Excel workbook with dashboard
  • CUI Scoping & Boundary Guide — DoD's 5-asset-category framework
  • Every requirement cross-referenced to its exact NIST control number
  • Free interactive Gap Assessment Tool — real weighted SPRS-style scoring
Enterprise tier also adds:
  • Subcontractor Flow-Down Package — clause language + attestation form
  • Mock Assessment Walkthrough Guide — the C3PAO process, phase by phase
  • C3PAO Evidence-Collection Matrix — all 110 requirements + readiness dashboard
  • Built for organizations preparing for a real third-party assessment
🇪🇺
DORA Compliance

DORA Compliance Kit

For EU banks, insurers, investment firms, payment institutions, and other financial entities under Regulation (EU) 2022/2554. Documentation mapped article-by-article to RTS 2024/1774, plus a live gap assessment tool.

Essentials (Simplified Regime)
Simplified Framework + Review Report
$69
Complete Kit (Full Framework) ★
13 documents + Free Gap Assessment Tool
$199
Enterprise (TLPT-Ready)
Complete Kit + TLPT Guide + CTPP Toolkit + Self-Host Tool
$299
Complete Kit includes (13 documents):
  • ICT Risk Management Framework — all 11 operational areas, Articles 5-14
  • 9 policies — one per RTS 2024/1774 chapter, cross-referenced to the framework
  • Incident Classification & Reporting Tracker — auto-calculates the 4hr/72hr/1-month deadlines
  • Register of Information — working register with concentration-risk dashboard
  • Every section cross-referenced to its exact RTS article number
  • Free interactive Gap Assessment Tool — tracks completion against the real article structure
Enterprise tier also adds:
  • TLPT Readiness Guide — phases, roles, budgets, and a month-by-month checklist
  • CTPP & Concentration Risk Toolkit — provider concentration-risk worksheet + exit planning
  • Gap Assessment Tool — full source code, ready to self-host internally
  • Built for entities designated as significant or managing critical-provider relationships
Free Tools

Know your gaps before you buy

Run a free assessment to see exactly where your compliance posture stands — and which documents you actually need.

🛡️

GDPR Gap Assessment

39 questions across 7 GDPR categories. Live compliance score, gap analysis by risk level, and recommendations for which templates to prioritize.

Launch Tool →
📋

SOC 2 Readiness Checklist

60 controls mapped to all Trust Service Criteria. Score your readiness across CC1–CC9 and A1. Priority action plan sorted by risk level.

Launch Tool →
📎

SOC 2 Evidence Tracker

For every SOC 2 control: what evidence to collect, which tools generate it, and how often. The guidance your auditor won't give you upfront.

Launch Tool →
🏥

HIPAA Risk Assessment

30 questions across 5 safeguard categories. Live compliance score and a priority action plan mapping every gap to the exact template that fixes it.

Launch Tool →
🏛️

NYDFS Gap Assessment

Scored across all 23 NYCRR 500 requirement sections, plus a Class A Company determination. See exactly where your documentation stands before your next annual certification.

Launch Tool →
🇺🇸

CMMC Gap Assessment

Score all 110 NIST SP 800-171 requirements using the DoD's real weighted methodology — not just a percent-complete bar. See exactly how far you are from a passing score.

Launch Tool →
🇪🇺

DORA Gap Assessment

Track completion against RTS 2024/1774's actual article structure for both the Full Framework and the Simplified Regime — switch between them and see exactly what's left.

Launch Tool →
Why Us

How we compare

Most compliance kits are bare Word documents with no context. Here's what makes these different.

Feature ComplianceKitPro Typical Etsy Kits Compliance SaaS ($15K+/yr)
TSC / GDPR Article mapped per template All 16 templates, all Articles Not included
Interactive gap assessment tool Free, browser-based
Evidence Collection Tracker Included in Bundle
Built by a compliance professional HIPAA SaaS background Template sellers
Fillable PDFs with hint text Some ✓ Varies
Price $29 – $299 $5 – $30 $10,000 – $30,000 / yr
About

Built by someone who has done this for real

I'm a software founder who has shipped HIPAA, SOC2, GDPR, NYSDFS-compliant SaaS products from the ground up. Along the way I navigated data privacy compliance across healthcare, fintech, and enterprise SaaS.

After helping dozens of teams navigate complex compliance requirements, I kept seeing the same problem: founders and CTOs were spending weeks researching policies and thousands of dollars on consultants for documentation that should take hours. I built these kits to fix that.

Every template is based on real audit experience, mapped to the actual standard it satisfies, and written so your team can complete it without a law degree.

Browse All Kits Try Free Tools
// Credentials
🏗️
HIPAA-Compliant SaaS Founder
Designed and shipped products meeting HIPAA technical safeguard requirements
⚖️
GDPR Implementation Experience
Implemented GDPR programs for B2C and B2B SaaS products with EU users
🔐
SOC 2 Audit Process
Navigated SOC 2 Type II audit preparation including evidence collection and auditor review
📋
Policy Documentation at Scale
Built compliance documentation programs used across multiple product lines
🏛️
Enterprise Security & Data Governance
Director-level experience across HIPAA, NIST 800-171 (CMMC Level 2), ISO 27001, HITRUST, and PCI DSS frameworks in regulated industries
Blog

Compliance guides

All Posts →

GDPR Checklist for SaaS Startups in 2026

The 12 things your startup needs to have documented before an enterprise customer asks for your privacy posture.

Read article →

What Evidence Does a SOC 2 Auditor Actually Sample?

Most teams are surprised by how specific auditor requests are. Here's exactly what they pull — and how to be ready.

Read article →

GDPR vs SOC 2: Which Does Your Startup Need First?

The answer depends on where your customers are and who's asking. A practical decision framework for early-stage teams.

Read article →
Get started today

Stop stalling on compliance.
Start in the next hour.

Instant download. Fillable PDFs. Free gap assessment tools. Everything you need to get audit-ready without a consultant.

⚖️ Legal Disclaimer

Last updated: June 2026  ·  ComplianceKitPro  ·  compliancekitpro.com

1. Not Legal Advice

All templates, checklists, tools, blog posts, guides, and other content provided by ComplianceKitPro ("we", "us", or "our") are for general informational purposes only. Nothing on this website or included in any downloadable product constitutes legal advice, and no attorney-client relationship is formed by your use of this site or any product purchased from it.

You should not rely on any content from this site as a substitute for advice from a qualified legal professional licensed in your jurisdiction. Laws and regulations vary significantly by country, state, and sector. Before implementing any compliance program or relying on any template, you should consult a qualified solicitor, attorney, or legal counsel familiar with your specific circumstances.

2. Not Audit or Certification Advice

ComplianceKitPro is not a certified public accounting firm, auditing body, or accredited certification authority. Our SOC 2 templates, checklists, and tools do not constitute audit advice and do not guarantee, imply, or represent that your organisation will achieve or maintain SOC 2 certification, GDPR compliance, or compliance with any other regulatory standard.

SOC 2 certification requires a formal audit conducted by a qualified, AICPA-accredited CPA firm. GDPR compliance is a continuous legal obligation that requires ongoing legal oversight. Using our templates is a starting point — not a substitute for a qualified auditor or legal counsel.

3. No Warranty

All products, templates, tools, and content are provided "as is" without warranty of any kind, either express or implied, including but not limited to warranties of:

Regulations change. We make reasonable efforts to keep templates current but cannot guarantee that any template reflects the most recent regulatory requirements at the time of your use. Always verify against the current text of the applicable regulation.

4. Jurisdiction Variation

GDPR, UK GDPR, CCPA, SOC 2, NYDFS 23 NYCRR 500, CMMC, DFARS, DORA, and other frameworks referenced in our products have requirements that vary by jurisdiction, sector, organisation size, and data type. A template that is appropriate for one organisation may not be appropriate for another. ComplianceKitPro makes no representation that any template is suitable for your specific jurisdiction, industry, or business context.

5. Limitation of Liability

To the fullest extent permitted by applicable law, ComplianceKitPro and its owners, employees, and affiliates shall not be liable for any direct, indirect, incidental, consequential, special, or punitive damages arising from or related to:

6. No Ongoing Relationship

Purchase of a template or use of a free tool does not create an ongoing advisory, consulting, or professional relationship between you and ComplianceKitPro. We are not your compliance advisor, legal counsel, or auditor.

7. Seek Professional Advice

We strongly recommend that before publishing any privacy policy, entering into any data processing agreement, or submitting to any compliance audit, you have your documentation reviewed by a qualified professional appropriate to your jurisdiction and sector:

8. Contact

If you have questions about this disclaimer or our products, contact us at: legal@compliancekitpro.com