One compliance platform.
Five frameworks. Every artifact your auditor asks for.
Complyanz runs ISO 27001, ISO 27701, ISO 42001, SOC 2 and HIPAA in a single workspace — risk registers, controls, evidence and the audit-ready document set — so one team can carry certifications, attestations and regulatory programs at the same time.
Plans from $279 a month, published up front. See pricing →
Certifications, attestations and regulations — in one place
Enable the programs you need. Each one arrives with its own controls, risk library, document set and dashboard.
Add a standard. Don't start a second program.
Most tools sell one framework per subscription, so a second certification means a second set of policies, a second risk register and the same work done twice. In Complyanz the ISO standards compose: ISO 27001 is the foundation, and privacy and AI extend it into one integrated management system with a single, consistent document set.
Adding privacy to an existing ISMS moves you from 36 documents to 38 — not to 36 plus a separate privacy library. The overlapping clauses stay in one place, which is exactly what an integrated management system is supposed to deliver.
The same path your assessor expects
Each framework carries its own roadmap in the product. The shape is consistent, so a team that has run one program can run the next.
Scope
Define the organization, the boundary and the standards in play. Locations, entities and interested parties are captured once and reused across every program.
Assets and risk
Register the assets in scope with their confidentiality, integrity and availability values, then build the risk register from a library of 266 pre-written ISO scenarios.
Controls and applicability
Work through the controls for each active standard, record justifications and produce the Statement of Applicability, Controls Applicability Matrix or Safeguard Applicability the assessor wants.
Evidence and audit
Attach evidence to controls, run internal audits and management reviews, log incidents and corrective actions, and walk into the audit with the trail already assembled.
Nine modules, one system of record
Everything a compliance program generates — risks, controls, documents, evidence, incidents, people and suppliers — lives in one place and stays linked.
Risk register and treatment plans
Build the register from 266 pre-written ISO scenarios or your own. Map each risk to the controls that treat it, set owners and track residual risk to closure.
Statement of Applicability
The document an ISO auditor asks for first. Walk all 93 Annex A controls, record inclusion or exclusion with justification, and export the SoA. SOC 2 and HIPAA get their equivalent applicability views.
Document library
90 ISO documents, tagged by management-system variant, plus dedicated SOC 2 and HIPAA sets. Pre-filled with your organization's details and exported as formatted Word and PDF files.
Evidence vault
Attach evidence directly to the control or criterion it proves, with the audit period it covers. When the assessor asks, the answer is one click away instead of one email thread.
Incidents and corrective actions
Log security and privacy incidents, classify severity, and drive corrective actions to closure. Breach records and notification readiness are built in for HIPAA.
Suppliers and business associates
Track third parties, the data they touch and the assurance you hold over them — including business associate agreements for organizations handling protected health information.
Training and awareness
Assign awareness training, record completion and keep the evidence every framework asks for when it wants proof that your people know the policies.
AI systems and impact assessments
Inventory the AI systems you build or buy, classify their impact across affected domains, and produce the assessments ISO 42001 expects.
Management review and internal audit
Run the governance cycle the standards mandate — internal audits, management reviews, metrics and continual improvement — with the minutes and records generated as you go.
Spreadsheets and consultants, or one system of record
Most compliance programs start in a shared drive. They work until the first audit, the first standard added, or the first person who owned the spreadsheet leaves.
| Spreadsheets and consultants | Complyanz | |
|---|---|---|
| Getting started | A blank workbook, or a consultant's template pack that has to be adapted to your organization before it means anything. | Controls, risk scenarios and documents are pre-loaded for every standard you enable, already tied to your organization's details. |
| Writing the documents | Authored by hand or bought as a static pack, then edited in a shared drive where version history is whoever remembered to rename the file. | Generated from a maintained library, filled with your data, versioned in the platform and exported as Word or PDF. |
| Evidence at audit time | Screenshots gathered in the fortnight before the audit, chased over email, stored wherever the person who collected them put them. | Attached to the control it proves as part of normal work, with the period it covers recorded alongside it. |
| Adding a second framework | A second workbook and a second document set, with overlapping requirements maintained twice and drifting apart. | Enable the standard. ISO extensions integrate into one management system; SOC 2 and HIPAA reuse the assets, risks and evidence you already hold. |
| Keeping it alive between audits | Nothing happens until the surveillance audit is scheduled, and then the scramble repeats. | Internal audits, management reviews, corrective actions and training run on a schedule, with the records produced as a by-product. |
| Where the knowledge lives | With the consultant, or with one person and their spreadsheet. | In the platform, with roles per family so the right people see the right program. |
Three certifiable standards for less than most platforms charge for one
For a company of around 30 people, a first certification usually costs a consultant or an enterprise automation contract. Complyanz sits between them: the management system, the documents and the audit trail, at a price listed on this page.
- Template pack adapted by hand, billed by the day
- Every added standard is a new engagement
- The know-how leaves when the contract ends
- $3,000 – $8,000 for each framework you add
- Built around cloud integrations, priced like it
- AI features often sold as a paid add-on
- 42 pre-built documents, 266 risk scenarios, the SoA
- Unlimited users and AI included
- Still there for the surveillance audit in year two
US figures, published or third-party-observed ranges, 2026. The certification body's audit fee is paid separately in every case — no software replaces it.
Priced by company size, not by seat
Invite everyone who owns a control, a policy or a training record. You pay by the number of people in scope — the same number your certification body uses to size the audit.
Prices in USD, excluding sales tax.
Single Standard
One certification or attestation, done properly: ISO 27001, SOC 2 or HIPAA.
$3,990 billed yearly
Start free- The full document set for your standard
- Risk register with 266 pre-written scenarios
- Statement of Applicability and treatment plans
- Evidence vault, incidents and corrective actions
- Internal audit, management review and training
- Supplier and third-party tracking
Integrated
The complete ISO family — security, privacy and AI — as one management system instead of three programs.
$7,490 billed yearly
Start free- Everything in Single Standard, plus
- ISO 27001, ISO 27701 and ISO 42001
- Integrated document sets: ISMS, IMS1, IMS2, IMS3
- Privacy records, DPIAs and PII risk library
- AI system inventory and impact assessments
- One risk register and evidence trail across all three
Complete
Every framework in one workspace, for teams selling into the US and Europe at the same time.
$13,490 billed yearly
Start free- Everything in Integrated, plus
- SOC 2 Trust Services Criteria readiness
- HIPAA safeguards, PHI inventory and BAAs
- Assets, risks and evidence shared across all five
- Multiple organizations under one login
Add-ons
| Extra ISO standard on Single StandardAdd ISO 27701 or ISO 42001 to an ISO 27001 plan | +$149 / mo |
| Extra framework family on IntegratedAdd SOC 2 or HIPAA without moving to Complete | +$199 / mo |
| Guided onboardingOne-time: scope definition and a first pass through the documents with a specialist | $1,500 once |
Consultancies and partners
Run your clients' programs from one login. Managed client organizations are billed at partner rates, from three organizations upward.
Ask about partner pricingAI that drafts the work, not the decisions
Complyanz uses AI where it removes typing and leaves judgement with your team: drafting risk scenarios for the assets you register, filling policy content from your organization's details, suggesting control justifications, and scoring how ready a program looks.
Deterministic where it matters
Document selection, template filling and exports are deterministic. If AI is unavailable, those flows keep working exactly as before — the artifacts you hand an auditor never depend on a model being up.
Your data is not training data
Content sent to the configured model provider is used to answer your request and nothing else. It is not used to train models. Full detail is in the privacy policy.
Frequently asked
Does Complyanz certify us?
No, and no software can. Certification is issued by an accredited certification body, and a SOC 2 report is issued by a CPA firm. Complyanz gets you audit-ready and gives you the artifacts and evidence trail those assessors ask for.
How long does it take to get certified?
It depends on your scope, how much of the groundwork already exists and your assessor's availability — so anyone quoting a fixed number is guessing. What Complyanz changes is the preparation: the controls, risk library and documents are already there, so the time goes into decisions rather than authoring.
Can we run ISO 27001 and SOC 2 at the same time?
Yes. They are separate programs with separate applicability views, but they share the same assets, risks, evidence and people, so the underlying work is done once.
What is an integrated management system?
When you certify to several ISO standards, their requirements overlap heavily. An integrated management system maintains one set of policies and procedures covering all of them instead of parallel copies. Complyanz ships pre-built document sets for each combination: ISO 27001 alone, plus privacy, plus AI, or all three.
Are the documents actually accepted by auditors?
They are authored against the clause structure of each standard, tagged to the standards and management-system variant they apply to, and exported as formatted Word and PDF files. Your auditor still assesses whether the content reflects what your organization genuinely does — no document pack can substitute for that.
Can one person work across several organizations?
Yes. One identity can belong to many organizations and switch between them, which is how consultancies and groups with multiple legal entities use the platform. Roles are held per organization, and per framework family within it.
What happens to our data?
Your data belongs to you, is scoped to your organization, and can be exported. Content sent to the AI provider is not used to train models. The privacy policy has the detail.
Do we still need a consultant?
Many teams do not, and those that do use one for less time. Complyanz covers the structure and the artifacts; a consultant is most valuable on scope decisions and readiness review, which is a much smaller engagement than authoring a management system from scratch.
Can we try it before paying?
Yes. Create an organization and start building without a credit card — scope, assets, risks and controls are all there from day one. Get in touch if you want a walkthrough before committing time to it.
Why do you price by employees instead of seats?
Because a management system only works when everyone takes part. Awareness training, evidence ownership, incident reporting and management review all need people across the company in the tool, and a per-seat price would charge you for exactly that. Every plan has unlimited users.
Who counts towards the employee band?
The people inside the scope of your management system — the same headcount the certification body uses to size your audit. If only one business unit is in scope, only that unit counts. Above 250 people, scope and locations drive the effort, so we quote those directly.
Does the price include the certification audit?
No. The audit is performed and invoiced by an accredited certification body (or a CPA firm for SOC 2), and no software vendor can include it. Complyanz replaces the preparation work and the template packs, which is where most of a first certification's cost usually goes.
What happens to the price after we certify?
From month 13 you can move to a maintenance plan at half the price of your plan. It keeps everything you need for surveillance audits — the risk register, evidence vault, corrective actions, internal audits and management review — and you can move back up when you add a standard or approach recertification.
Why are prices different by region?
Compliance budgets differ a lot between markets, so we publish a price list for the United States, Europe, Brazil and Spanish-speaking Latin America. The regional price is set by your billing country and company tax ID.
Does Complyanz pull evidence from AWS, Okta or GitHub automatically?
Not today. Complyanz is a management-system platform: the documents, risk methodology, Statement of Applicability, audits and evidence trail that ISO, SOC 2 and HIPAA are assessed on. Evidence is attached to the control it proves as part of normal work. If continuous cloud monitoring is your main requirement, an automation platform is the better fit — and the price reflects that difference.
Start with one framework. Add the rest when you are ready.
Create an organization, pick the standards you are working towards, and the controls, risks and documents are waiting for you. No credit card, no sales call, and the price is on this page.