Plan your SOC 2, ISO 27001, or HIPAA compliance program on a Gantt chart — from gap assessment and policy writing through audit and certification.
Security compliance certifications — SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP — are not single events. They are multi-month programs with parallel workstreams, external dependencies, and evidence collection periods that cannot be compressed. Companies that approach compliance as a sprint ("we'll do it in six weeks before the enterprise deal closes") almost always fail or produce a certification that does not hold up to scrutiny. Companies that plan compliance as a Gantt-managed project, with sequenced workstreams and clear ownership, reach certification on schedule and maintain it efficiently year over year.
This guide covers the major phases of a cloud security compliance Gantt for SOC 2 and ISO 27001, with notes on HIPAA and PCI DSS where they differ.
Before any technical work begins, define the boundary of your compliance program. Scope decisions affect how much work the program requires and what the certification actually covers.
Scope definition: Which systems, services, and data are in scope? For a SaaS product, scope typically includes the production environment, the support systems that access production data, and the processes (engineering, security, HR) that govern access. Out-of-scope systems do not need to meet the same control standards — so defining scope tightly (but honestly) reduces work without reducing the value of the certification.
Framework selection: Different certifications serve different markets:
Auditor or certification body selection: For SOC 2, select a CPA firm authorized to issue SOC reports (AICPA member firms). For ISO 27001, select an accredited certification body (UKAS-accredited for UK; DAkkS for Germany; ANAB for US, etc.). Some vendors offer combined SOC 2 + ISO 27001 programs. Get proposals from 2–3 firms and evaluate on experience with similar-stage companies, timeline, and price.
Gap assessment: Before writing policies or implementing controls, assess where you stand today. A gap assessment compares your current controls against the framework's requirements and produces a prioritized remediation list. Expect to find gaps in 40–60% of control areas in a first-time compliance program — this is normal.
Compliance frameworks require documented policies. Policies demonstrate that the organization has defined its security stance; procedures demonstrate how that stance is implemented in practice. No technical control is complete without the policy that governs it.
Core policies required for SOC 2 and ISO 27001:
Policy development takes 4–8 weeks for a complete set, including review cycles with legal counsel and management approval.
This is the longest workstream in a first-time compliance program because it involves both implementing new controls and documenting existing ones. Key control areas:
Identity and Access Management (IAM):
Endpoint Detection and Response (EDR): EDR deployed on all company-managed endpoints. Alerts investigated and documented. This requires not just deployment but documented response procedures for alert triage.
SIEM and Log Management: Security events (authentication, access, network, system) are aggregated into a centralized SIEM (Splunk, Microsoft Sentinel, Sumo Logic). Log retention meets framework requirements (SOC 2: typically 12 months; PCI DSS: 12 months with 3 months immediately available). Alert rules are defined and tested.
Vulnerability Management: Authenticated vulnerability scans run against all in-scope systems on a defined schedule (monthly for most frameworks). Findings are triaged by severity, and remediation SLAs are defined and tracked: critical (patch within 72 hours), high (within 30 days), medium (within 90 days).
Patch Management: All systems, including OS and application dependencies, are patched per the remediation SLAs above. Patch compliance is measured and reported.
Encryption: Data encrypted at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher). Certificate management — certificate inventory, expiration monitoring, renewal process — documented.
Network Security: Firewall rules reviewed and documented. Network segmentation between production and non-production environments. Intrusion detection/prevention (IDS/IPS) deployed. No direct inbound access to production except through documented, MFA-protected jump hosts.
Backup and Recovery: Backups run on defined schedules (daily at minimum for production databases). Backup restoration tested quarterly and documented. Recovery time measured against RTO/RPO commitments.
Human factors are the most common root cause of security incidents. Compliance frameworks require documented employee security training.
Security awareness training: Annual training for all employees covering phishing recognition, password hygiene, data handling, incident reporting, and acceptable use. Training completion must be tracked and documented.
Phishing simulation: Regular simulated phishing campaigns (quarterly or more frequent) measure employee susceptibility and identify individuals who need additional training. Track click rates over time — improvement is the goal.
Role-specific training: Developers receive training on secure development practices (OWASP Top 10, input validation, dependency management, secrets management). Incident response team members participate in tabletop exercises simulating realistic incident scenarios. Cloud infrastructure team members receive training on cloud security configuration and the principle of least privilege.
For SOC 2 Type II and ISO 27001, the certification requires that controls not only exist but have operated effectively over time. This is the observation period.
SOC 2 Type II: Typically 6 months. During this period, the auditor will request evidence that controls operated as designed: access review records, vulnerability scan results, patching records, change management tickets, backup restoration test results, training completion records, incident response records.
ISO 27001: The certification audit (Stage 2 audit) reviews implementation and operating effectiveness. ISO 27001 does not prescribe an observation period the same way SOC 2 does, but auditors will ask for evidence of control operation.
Evidence collection discipline: Use a compliance platform (Vanta, Drata, Secureframe, Tugboat Logic) or a structured manual evidence repository to collect evidence continuously throughout the observation period. Do not try to reconstruct evidence after the fact — auditors can tell, and it is not compliant.
Auditor fieldwork: The auditor (or certification body) reviews your documentation, interviews personnel, and inspects system configurations. For SOC 2, auditors use sampling: they select a sample of records (e.g., 25 change management tickets, 10 access review records) and verify each.
Findings and management response: Auditors issue a draft report with any control deficiencies identified. Your team provides a management response — either correcting the deficiency before the report is finalized, or acknowledging it with a remediation plan.
Report issuance / certificate issuance: The final SOC 2 report or ISO 27001 certificate is issued. For SOC 2, the report goes to your customers under NDA (SOC 2 reports are not public; they are shared with customers who have signed an NDA). For ISO 27001, the certificate is public.
Compliance is not a project that ends at certification — it is an ongoing program.
SOC 2 renewal: Annual. Every year, the observation period restarts. Controls must continue to operate, evidence must continue to be collected, and the annual audit must be completed.
ISO 27001 surveillance audits: Annually. The certification body conducts a surveillance audit to verify ongoing compliance. Every three years, a full recertification audit is conducted.
Continuous monitoring: Security posture changes constantly as new vulnerabilities are discovered, team members join and leave, and systems change. Continuous monitoring — automated controls testing, regular access reviews, monthly vulnerability scans, ongoing security training — is the operational backbone of a mature security compliance program.
In gantt-chart.io, create swim lanes for scoping and framework selection, policy development, technical controls implementation (grouped by control area), training, evidence collection (with start and end dates for the observation period), audit preparation, and audit. Add milestones for the auditor kickoff meeting, the observation period start, the observation period end, and the target report or certificate date. Assign ownership to every task so accountability is clear.
The most expensive compliance failures come from treating the observation period start as the time to begin implementing controls. By then, you are already behind. Start the Gantt with enough lead time for controls to be fully operational before the observation clock starts — typically 3–4 months before the observation period begins.