
Stop starting every audit from a blank Google Doc.
ControlForge is a complete GRC policy and audit toolkit for teams preparing for SOC 2, ISO 27001, or NIST CSF. You get the policies, registers, and evidence trackers a reviewer actually expects, written in plain language you can drop into your ISMS and tailor in a weekend.
What’s inside:
• SOC 2 Type I/II policy pack covering security, availability, confidentiality, processing integrity, and privacy
• ISO 27001:2022 ISMS starter: scope, Statement of Applicability, risk methodology, and Annex A control notes
• NIST CSF 2.0 control mapping workbook with Govern, Identify, Protect, Detect, Respond, Recover
• Risk register, vendor due diligence questionnaire, internal audit checklist, and evidence collection tracker
• A short implementation guide so you know what to customize vs. what to keep
Built for GRC analysts, vCISOs, consultants, and operators at startups and SMBs. These are working templates, not theory. Copy, fill in the yellow fields, and take them to your auditor.