Verigo Global
Resources

Knowledge that accelerates compliance.

Practical guides, on-demand webinars, and free tools — built by the practitioners who run compliance programs every day.

WebinarsArticlesFree Downloads
On-Demand Webinars

Watch at your own pace

Focused, framework-specific sessions from our practitioners — available anytime. Register to watch and get the slides delivered to your inbox.

May 20, 2026 · 55 min
On Demand

ISO 27001:2022 — Closing the Annex A Gaps in the New Four-Theme Structure

James Hartwell · Lead Practitioner, Verigo Global

The 2022 revision reorganized Annex A into four themes and added 11 new controls. We cover what changed, which gaps are most commonly missed, and how to tailor the new control set to your scope.

ISO 27001Annex A2022 Edition
April 8, 2026 · 50 min
On Demand

HITRUST e1, i1, and r2: Choosing the Right Assessment Type for Your Program

Dr. Priya Nair · Director, Healthcare Compliance

This session breaks down the three HITRUST assessment types — requirements, timelines, and assurance levels — and helps you decide which fits your customers, contracts, and risk appetite.

HITRUSTe1i1r2
March 12, 2026 · 60 min
On Demand

Cross-Framework Control Mapping: One Evidence Set for ISO 27001, SOC 2, and CMMC

Marcus Okafor · Principal, Advisory Services

Pursuing multiple certifications? Learn how to build a single control implementation that satisfies ISO 27001 Annex A, the SOC 2 Common Criteria, and NIST 800-171 simultaneously.

Cross-frameworkISO 27001SOC 2CMMC
February 4, 2026 · 45 min
On Demand

NIST CSF v2.0 and the New Govern Function: What It Means for Your Program

Sarah Chen · Senior Practitioner, Cyber Advisory

We walk through the CSF v2.0 update — the addition of Govern as the sixth function, the revised subcategory structure, and how to build a current-state and target profile in practice.

NIST CSFv2.0Govern
Articles

In-depth guides from practitioners

Authoritative analysis on compliance strategy, framework implementation, and evidence management.

Strategy8 min

SOC 2 vs ISO 27001: Which Certification Should You Pursue First?

Both are widely recognized, but they answer different questions for different buyers. Here is how to…

June 12, 2026Read
CMMC 2.06 min

How to Scope a CUI Enclave — and Why It Changes Your Level 2 Cost

The single highest-leverage decision in a CMMC 2.0 program is defining your CUI enclave. A well-scop…

June 3, 2026Read
SOC 27 min

The Evidence Engine: How to Make Your Type II Observation Window Routine

The observation window is not the problem. The scramble before it is. Embed evidence-producing contr…

May 22, 2026Read
HITRUST5 min

HITRUST Made Legible: Understanding e1, i1, and r2 Without the Jargon

HITRUST certifications come in three types with very different scope, cost, and assurance levels. Th…

May 8, 2026Read
ISO 270016 min

Why ISO 27001:2022's Four-Theme Annex A Changes Your Implementation Approach

Moving from 114 controls across 14 domains to 93 controls across four themes changes more than the n…

April 17, 2026Read
Risk Management5 min

Risk Treatment in Practice: Accept, Mitigate, Transfer, or Avoid

Every framework requires a risk treatment decision, but most documentation is vague. Learn how to ma…

April 2, 2026Read
NIST CSF7 min

NIST CSF Tiers vs Profiles: A Practical Guide to Using Both

Tiers describe how you manage cybersecurity. Profiles describe what you do. Used together, they crea…

March 19, 2026Read
Cross-framework8 min

Certify Once, Reuse Everywhere: Multi-Framework Compliance Programs

ISO 27001, SOC 2, CMMC 2.0, and NIST 800-171 share significant underlying controls. Learn how to seq…

March 5, 2026Read
Free Downloads

Templates, checklists & guides — no charge

Production-ready tools you can use immediately. We'll ask for your name and email before generating your PDF.

PDF

SOC 2 Readiness Checklist

A structured pre-assessment checklist across all five Trust Services categories. Identify gaps before the observation window opens.

SOC 2Type I & II
PDF

CMMC 2.0 Level 2 Self-Assessment Scorecard

A domain-by-domain scorecard across all 110 NIST SP 800-171 practices with a gap summary that feeds directly into your POA&M.

CMMCLevel 2800-171
PDF

ISO 27001:2022 Gap Analysis Template

Map your current state against all 93 Annex A:2022 controls across four themes. Includes applicability, implementation status, and evidence fields.

ISO 270012022Annex A
PDF

Cross-Framework Control Mapping Guide

A master cross-reference mapping ISO 27001 Annex A, the SOC 2 Common Criteria, NIST SP 800-171, and the NIST CSF functions.

ISO 27001SOC 2CMMCNIST
PDF

NIST CSF v2.0 Profile Template

Build your Current Profile and Target Profile across all six CSF v2.0 functions with a gap summary and prioritization column.

NIST CSFv2.0Profile
PDF

HITRUST CSF Quick-Start Guide

Plain-language guide to the HITRUST assessment process — selecting your type (e1/i1/r2), setting factors, and working with an External Assessor.

HITRUSTe1i1r2
Need more than a template?

Get the full practitioner-maintained toolkit for your framework.

Every free download is a sample of what our full toolkit contains — policies, procedures, control templates, and evidence checklists tailored to your scope.

Stay current

Compliance intelligence, delivered monthly.

Regulatory updates, new webinar announcements, and practitioner notes — no marketing noise.