Compliance Journey · 90-Day Project Timeline Template

Your 90-Day Compliance Timeline

Edit, download, and share your project roadmap. Template works for SOC 2, HIPAA, ISO 27001, and PCI-DSS — fill in owners, dates, and status, then print or export to share with your team.

Editable Template

Track your 90-day compliance project

Pick a framework, assign owners, and update status as you progress. Print or export to PDF to share with stakeholders.

Week Phase Key Activities Deliverables Owner Status
1–2 Gap Analysis • Run STACK Compass
• Identify missing controls
• Estimate effort
• Prioritize quick wins
Compliance gap report
3 Roadmap • Map controls to systems
• Create policies
• Plan evidence collection
• Schedule audit
Control mapping + roadmap
4–8 Implementation • Deploy controls
• Document evidence
• Run internal audits
• Remediate findings
Control evidence + logs
9–12 Audit Ready • Final internal audit
• Prepare for auditor
• Coordinate scope
• Receive attestation
Signed report/certificate
Project Details (Optional)

Add context for your PDF export

Project name, target audit date, and team members appear on the printed PDF header so stakeholders know exactly what they're looking at.

Additional Resources

Framework-specific roadmaps and references

Each roadmap walks you through the specific controls, deliverables, and audit-ready milestones for that framework.

SOC 2 Roadmap

90-day path from gap analysis to signed attestation.

Open SOC 2 Roadmap →

HIPAA Roadmap

PHI-focused 90-day program with BAA review and acceleration.

Open HIPAA Roadmap →

ISO 27001 Roadmap

ISMS scoping through Annex A controls to certification.

Open ISO 27001 Roadmap →

PCI-DSS Roadmap

CDE scoping through 12 requirements to QSA assessment.

Open PCI-DSS Roadmap →

Internal Audit Checklist

Run an internal audit before the QSA or external auditor arrives.

Open Checklist →

Control Mapping Reference

Cross-framework mapping between SOC 2, HIPAA, ISO 27001, and PCI-DSS.

Open Reference →

Need Help Executing

Don't go it alone

Compliance Acceleration pairs you with a named vCISO and weekly check-ins to keep your 90-day timeline on track.