Gantt Chart for Cloud Security Compliance
Security compliance certifications — SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP — are not single events. They are multi-month programs with parallel workstreams, external dependencies, and evidence collection periods that cannot be compressed. Companies that approach compliance as a sprint ("we'll do it in six weeks before the enterprise deal closes") almost always fail or produce a certification that does not hold up to scrutiny. Companies that plan compliance as a Gantt-managed project, with sequenced workstreams and clear ownership, reach certification on schedule and maintain it efficiently year over year.
This guide covers the major phases of a cloud security compliance Gantt for SOC 2 and ISO 27001, with notes on HIPAA and PCI DSS where they differ.
Phase 1: Scoping and Compliance Framework Selection
Before any technical work begins, define the boundary of your compliance program. Scope decisions affect how much work the program requires and what the certification actually covers.
Scope definition: Which systems, services, and data are in scope? For a SaaS product, scope typically includes the production environment, the support systems that access production data, and the processes (engineering, security, HR) that govern access. Out-of-scope systems do not need to meet the same control standards — so defining scope tightly (but honestly) reduces work without reducing the value of the certification.
Framework selection: Different certifications serve different markets:
- SOC 2: The standard requirement for US B2B SaaS companies. SOC 2 Type I certifies that controls are designed correctly as of a point in time; SOC 2 Type II certifies that controls operated effectively over an observation period (typically 6 months, sometimes 12). Enterprise procurement teams almost universally request SOC 2 Type II.
- ISO 27001: The international standard for information security management systems (ISMS). Widely recognized in Europe, the Middle East, and Asia-Pacific. ISO 27001 certification is awarded by an accredited certification body and requires annual surveillance audits and a triennial recertification audit.
- HIPAA: Not a certification program (there is no official HIPAA certification), but a compliance framework for organizations that handle Protected Health Information (PHI). HIPAA compliance is demonstrated through a risk analysis, implementation of required safeguards, and Business Associate Agreements (BAAs).
- PCI DSS: Required for any organization that processes, stores, or transmits cardholder data. PCI DSS v4.0 is the current standard. Compliance level depends on transaction volume.
- FedRAMP: Required for cloud services sold to US federal government agencies. FedRAMP is the most demanding of these frameworks and typically takes 12–24 months to achieve.
Auditor or certification body selection: For SOC 2, select a CPA firm authorized to issue SOC reports (AICPA member firms). For ISO 27001, select an accredited certification body (UKAS-accredited for UK; DAkkS for Germany; ANAB for US, etc.). Some vendors offer combined SOC 2 + ISO 27001 programs. Get proposals from 2–3 firms and evaluate on experience with similar-stage companies, timeline, and price.
Gap assessment: Before writing policies or implementing controls, assess where you stand today. A gap assessment compares your current controls against the framework's requirements and produces a prioritized remediation list. Expect to find gaps in 40–60% of control areas in a first-time compliance program — this is normal.
Phase 2: Policy and Procedure Development
Compliance frameworks require documented policies. Policies demonstrate that the organization has defined its security stance; procedures demonstrate how that stance is implemented in practice. No technical control is complete without the policy that governs it.
Core policies required for SOC 2 and ISO 27001:
- Information Security Policy: Top-level governance document. Management's statement of commitment to security, scope of the ISMS, and allocation of responsibilities.
- Access Control Policy: Governs who gets access to what and how access is granted, reviewed, and revoked. Must address user provisioning, least privilege, privileged access, multi-factor authentication requirements, and access review frequency.
- Incident Response Plan: Defines how the organization identifies, contains, eradicates, recovers from, and reports security incidents. Must include escalation paths, communication templates, and regulatory notification requirements (GDPR requires notification to supervisory authority within 72 hours of becoming aware of a breach).
- Business Continuity and Disaster Recovery Plan: Defines recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical systems, and documents recovery procedures.
- Vendor Risk Management Policy: Governs how third-party vendors who access company data or systems are evaluated, onboarded, and monitored. Requires a vendor inventory and risk tier classification.
- Acceptable Use Policy: Defines permitted and prohibited uses of company systems, devices, and data.
- Data Classification and Handling Policy: Classifies data by sensitivity (public, internal, confidential, restricted) and defines handling requirements for each class.
Policy development takes 4–8 weeks for a complete set, including review cycles with legal counsel and management approval.
Phase 3: Technical Controls Implementation
This is the longest workstream in a first-time compliance program because it involves both implementing new controls and documenting existing ones. Key control areas:
Identity and Access Management (IAM):
- Multi-factor authentication (MFA) enforced for all user accounts, especially administrative access
- Least privilege access — users have only the permissions needed for their role
- Privileged Access Management (PAM) — administrative and privileged accounts are managed through a dedicated PAM system (CyberArk, HashiCorp Vault, AWS IAM with tightly scoped policies)
- Quarterly access reviews — all user accounts reviewed; inactive accounts disabled
Endpoint Detection and Response (EDR): EDR deployed on all company-managed endpoints. Alerts investigated and documented. This requires not just deployment but documented response procedures for alert triage.
SIEM and Log Management: Security events (authentication, access, network, system) are aggregated into a centralized SIEM (Splunk, Microsoft Sentinel, Sumo Logic). Log retention meets framework requirements (SOC 2: typically 12 months; PCI DSS: 12 months with 3 months immediately available). Alert rules are defined and tested.
Vulnerability Management: Authenticated vulnerability scans run against all in-scope systems on a defined schedule (monthly for most frameworks). Findings are triaged by severity, and remediation SLAs are defined and tracked: critical (patch within 72 hours), high (within 30 days), medium (within 90 days).
Patch Management: All systems, including OS and application dependencies, are patched per the remediation SLAs above. Patch compliance is measured and reported.
Encryption: Data encrypted at rest (AES-256 or equivalent) and in transit (TLS 1.2 or higher). Certificate management — certificate inventory, expiration monitoring, renewal process — documented.
Network Security: Firewall rules reviewed and documented. Network segmentation between production and non-production environments. Intrusion detection/prevention (IDS/IPS) deployed. No direct inbound access to production except through documented, MFA-protected jump hosts.
Backup and Recovery: Backups run on defined schedules (daily at minimum for production databases). Backup restoration tested quarterly and documented. Recovery time measured against RTO/RPO commitments.
Phase 4: Employee Security Training
Human factors are the most common root cause of security incidents. Compliance frameworks require documented employee security training.
Security awareness training: Annual training for all employees covering phishing recognition, password hygiene, data handling, incident reporting, and acceptable use. Training completion must be tracked and documented.
Phishing simulation: Regular simulated phishing campaigns (quarterly or more frequent) measure employee susceptibility and identify individuals who need additional training. Track click rates over time — improvement is the goal.
Role-specific training: Developers receive training on secure development practices (OWASP Top 10, input validation, dependency management, secrets management). Incident response team members participate in tabletop exercises simulating realistic incident scenarios. Cloud infrastructure team members receive training on cloud security configuration and the principle of least privilege.
Phase 5: Evidence Collection and Observation Period
For SOC 2 Type II and ISO 27001, the certification requires that controls not only exist but have operated effectively over time. This is the observation period.
SOC 2 Type II: Typically 6 months. During this period, the auditor will request evidence that controls operated as designed: access review records, vulnerability scan results, patching records, change management tickets, backup restoration test results, training completion records, incident response records.
ISO 27001: The certification audit (Stage 2 audit) reviews implementation and operating effectiveness. ISO 27001 does not prescribe an observation period the same way SOC 2 does, but auditors will ask for evidence of control operation.
Evidence collection discipline: Use a compliance platform (Vanta, Drata, Secureframe, Tugboat Logic) or a structured manual evidence repository to collect evidence continuously throughout the observation period. Do not try to reconstruct evidence after the fact — auditors can tell, and it is not compliant.
Phase 6: Audit
Auditor fieldwork: The auditor (or certification body) reviews your documentation, interviews personnel, and inspects system configurations. For SOC 2, auditors use sampling: they select a sample of records (e.g., 25 change management tickets, 10 access review records) and verify each.
Findings and management response: Auditors issue a draft report with any control deficiencies identified. Your team provides a management response — either correcting the deficiency before the report is finalized, or acknowledging it with a remediation plan.
Report issuance / certificate issuance: The final SOC 2 report or ISO 27001 certificate is issued. For SOC 2, the report goes to your customers under NDA (SOC 2 reports are not public; they are shared with customers who have signed an NDA). For ISO 27001, the certificate is public.
Phase 7: Ongoing Compliance
Compliance is not a project that ends at certification — it is an ongoing program.
SOC 2 renewal: Annual. Every year, the observation period restarts. Controls must continue to operate, evidence must continue to be collected, and the annual audit must be completed.
ISO 27001 surveillance audits: Annually. The certification body conducts a surveillance audit to verify ongoing compliance. Every three years, a full recertification audit is conducted.
Continuous monitoring: Security posture changes constantly as new vulnerabilities are discovered, team members join and leave, and systems change. Continuous monitoring — automated controls testing, regular access reviews, monthly vulnerability scans, ongoing security training — is the operational backbone of a mature security compliance program.
Building the Compliance Gantt
In gantt-chart.io, create swim lanes for scoping and framework selection, policy development, technical controls implementation (grouped by control area), training, evidence collection (with start and end dates for the observation period), audit preparation, and audit. Add milestones for the auditor kickoff meeting, the observation period start, the observation period end, and the target report or certificate date. Assign ownership to every task so accountability is clear.
The most expensive compliance failures come from treating the observation period start as the time to begin implementing controls. By then, you are already behind. Start the Gantt with enough lead time for controls to be fully operational before the observation clock starts — typically 3–4 months before the observation period begins.