Guides
Editorial for buyer-side reviewers
Short, factual, and written to correct the terminology that marketing pages get wrong.
How to read a SOC 2 report in 20 minutes
Type I versus Type II, the period, the opinion, carve-outs, complementary user entity controls and exceptions: what a buyer actually needs from the report.
Updated 17 Sep 2026hipaaThe BAA checklist: what to check before sending PHI to a vendor
HIPAA has no certification. The business associate agreement is the artefact; here is what it must cover and how vendors limit it.
Updated 17 Sep 2026gdprThe EU-US Data Privacy Framework, explained for vendor reviews
What a DPF listing proves, the usage end date, the UK and Swiss extensions, and the pending Court of Justice appeal.
Updated 17 Sep 2026fedrampFedRAMP statuses in 2026: Authorized, In Process, Ready and 20x
How to read the FedRAMP Marketplace data file, what impact levels mean, and why "Ready" is disappearing.
Updated 17 Sep 2026pci dssWhere PCI DSS evidence actually lives: the Visa and Mastercard registries
Why a badge is not evidence, how the Visa Global Registry works, and the Third Party Agent trap that mislabels three quarters of it.
Updated 17 Sep 2026iso 27001ISO 27001:2013 certificates lapsed on 31 October 2025
The IAF transition deadline, what it means for certificates still citing the 2013 edition, and how to check scope and surveillance.
Updated 17 Sep 2026ProcessA 30-minute vendor security review using public evidence
The questions to answer before you email sales, in the order that saves the most time.
Updated 17 Sep 2026