Our publications
A publication for every compliance question.
Every title carries its own directory, glossary and editorial, and every one is listed here so a partner can see exactly where their category lives and who reads it. Open any publication to see it as its readers do.
Governance, risk and compliance programs
8 publications, 2,942 listings in 40 categoriesThe starting point for building and validating compliance programs
Read by cISOs, GRC leaders, compliance officers, auditors and risk managers at mid-market and large organizations.
546 listings in 7 categoriesgovernanceauthority.orgResources, readiness consulting, and audit firms for SOC 2 and ISO 27001 compliance
Read by auditors and teams pursuing SOC 2, ISO 27001 and HITRUST - readiness, controls, evidence and attestation.
516 listings in 5 categoriescontrolinstitute.orgBuild a culture of compliance through training, awareness, and ethics programs.
Read by hR, compliance-training, ethics-hotline and security-awareness teams.
420 listings in 4 categoriesintegritypath.orgThe operational backbone of compliance from policy, controls, evidence, and audit tools
Read by cISOs, GRC leaders, compliance officers, auditors and risk managers at mid-market and large organizations.
399 listings in 6 categoriespolicyauthority.orgThe intelligence hub for GRC platforms, enterprise risk, and regulatory change
Read by cISOs, GRC leaders, compliance officers, auditors and risk managers at mid-market and large organizations.
329 listings in 6 categoriesregulatorycouncil.orgThe intelligence resource for third-party risk, vendor due diligence, and supply chain risk.
Read by third-party risk (TPRM), vendor due-diligence, procurement-security and supply-chain-risk teams.
272 listings in 6 categoriesoversightinstitute.orgWhere organizations source vCISO, fractional CISO, and security leadership services
Read by executives, boards, CISOs, procurement and enterprise-risk leaders (GRC, vCISO, advisory).
239 listings in 3 categoriescyberriskcouncil.orgThe resource for cloud posture, continuous compliance monitoring, and security controls.
Read by cISOs, GRC leaders, compliance officers, auditors and risk managers at mid-market and large organizations.
221 listings in 3 categoriesbenchmarkauthority.orgPrivacy and data
4 publications, 1,582 listings in 25 categoriesData protection and governance vendors for protecting sensitive data and proving safeguards.
Read by privacy officers, data-governance and legal teams, and DSAR/consent operators.
493 listings in 9 categoriesdataridge.orgThe definitive resource for records management, eDiscovery, legal hold, and communications governance
Read by legal operations, records managers, eDiscovery and communications-governance teams.
448 listings in 8 categoriesrecordsauthority.orgEverything privacy teams need for GDPR, DSAR, data mapping, and program management
Read by privacy officers, data-governance and legal teams, and DSAR/consent operators.
329 listings in 6 categoriesprivacytrack.orgEverything teams need for consent management platforms and cookie compliance.
Read by privacy officers, data-governance and legal teams, and DSAR/consent operators.
312 listings in 2 categoriescookiegate.orgSecurity operations
6 publications, 1,785 listings in 26 categoriesWhere identity governance, privileged access, and access control professionals find answers
Read by security leaders, SecOps, IT and cyber-risk teams (vuln management, pentest, SIEM, identity).
439 listings in 6 categoriesidentityauthority.orgYour complete resource for vulnerability and exposure management
Read by security leaders, SecOps, IT and cyber-risk teams (vuln management, pentest, SIEM, identity).
429 listings in 3 categoriesvulnerabilityinstitute.orgThe resource for cyber insurance, business continuity, disaster recovery, and incident response.
Read by incident-response, business-continuity (BCM), disaster-recovery and cyber-insurance teams.
310 listings in 4 categoriesreadinessauthority.orgThe essential resource for penetration testing services and PTaaS platforms.
Read by security leaders, SecOps, IT and cyber-risk teams (vuln management, pentest, SIEM, identity).
261 listings in 2 categoriestestscope.orgSecurity monitoring, logging, and incident response
Read by security leaders, SecOps, IT and cyber-risk teams (vuln management, pentest, SIEM, identity).
193 listings in 3 categoriesincidentsecure.orgIndependent Intelligence for Application Security & Software Supply Chain
153 listings in 8 categoriesappsecuritystandards.orgRegulated sectors and mandates
6 publications, 1,437 listings in 32 categoriesEmpowering digital accessibility for businesses
Read by cISOs, GRC leaders, compliance officers, auditors and risk managers at mid-market and large organizations.
352 listings in 15 categoriesaccessibility.comFind HIPAA and HITRUST compliance vendors, tools, and guidance
Read by healthcare and life-sciences compliance teams (HIPAA, HITRUST).
322 listings in 4 categorieshipaapath.orgThe go-to resource for KYC, AML, and financial crime compliance vendors and guidance.
Read by aML/KYC, fraud, and payments/PCI compliance teams at banks, fintechs and payment companies.
298 listings in 3 categoriesfincrimeinstitute.orgDefense and public sector cybersecurity compliance
Read by defense contractors and public-sector teams (FedRAMP, CMMC, NIST 800-53/171, ITAR/DFARS, StateRAMP).
211 listings in 5 categoriescomplydefense.orgPayment security, fraud prevention, and PCI DSS compliance
Read by aML/KYC, fraud, and payments/PCI compliance teams at banks, fintechs and payment companies.
138 listings in 2 categoriescommercesecurity.orgAI governance and model risk management
Read by aI-governance leaders, model-risk and assurance teams, and legal/compliance for enterprise AI.
116 listings in 3 categoriesbureauofai.orgNot sure which publication covers your category?
Tell us what you sell and we will tell you where its buyers read.