Nobody in this industry is paid to tell you "no, you don't need that framework." Platforms sell frameworks as paid add-ons. Consultants bill by the engagement. Audit firms audit what you buy. This page exists because we're the exception: our revenue comes from services partners whether you run one framework or five, so the honest answer costs us nothing - and the honest answer, for most companies, is fewer than you're being sold.
This guide is independent. GRC Migrate takes nothing from platform vendors, auditors, or certification bodies - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.
The minimum viable framework set, by situation
US B2B selling to enterprise/mid-market: SOC 2 - and usually SOC 2 alone. Meaningful EU/UK/APAC deal flow, or customers naming it: ISO 27001. Handling protected health information: HIPAA obligations apply by law - that one isn't a choice. Selling AI systems into enterprise or EU buyers: ISO 42001 is starting to appear in procurement - track it, rarely adopt it yet. Everything beyond what your customers' contracts and questionnaires actually name is optional, whatever the badge wall next to yours says.
Skip the catalog - get your minimum set.
Find your minimum framework set in 3 minutesYour deal flow, industry, and timeline in - the frameworks that actually gate your revenue out. No email required to see results.
Independent by structure: we take nothing from platform vendors - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.
The incentive nobody names
Every added framework is revenue for someone advising you to add it. On the platforms it's a paid add-on - publicly reported around $5,000 each on Vanta and roughly $1,500–7,500/yr each on Drata (up to ~$10,000 at enterprise scope) - that also rolls into your renewal base and compounds. For consultants it's a billable engagement; for audit firms it's another audit. That doesn't make any of them dishonest - it makes none of them the right person to ask whether. The cost-stacking guide shows what the compounding actually does to a contract; the GRC platform pricing guide covers how the quotes are built.
Read your deal flow, not the vendor catalog
Geography decides more than anything else. US enterprise and mid-market buyers ask for SOC 2 in security review; most have never asked a US vendor for ISO 27001. EU, UK, and APAC buyers reverse it - ISO 27001 is the lingua franca, and SOC 2 often needs explaining. If your pipeline is 90% US, start (and probably stop) with the SOC 2 decision. If international revenue is real or imminent, read the ISO 27001 decision - and if you'll genuinely need both, the sequencing guide is about doing it in the order that funds itself.
Industry adds obligations, not options. Health data is the clearest case: if you're a covered entity or a business associate touching PHI, HIPAA applies by regulation - no certificate exists, no platform makes you "HIPAA certified," and the decision there is about tooling, not whether. Selling AI into enterprise or EU buyers is the emerging case: ISO 42001 is voluntary and market-driven, and mostly matters if you ship AI rather than merely use it.
Contract language is the only trigger that pays for itself. The strongest evidence you need a framework is a customer contract, MSA, or questionnaire that names it. Before you buy anything, pull the security language from your three biggest open deals and your three biggest renewals. What's named there is the requirement; everything else is inventory.
When one framework is enough
For most US B2B companies, one is the right number for years: SOC 2 clears the overwhelming majority of US security reviews, and the platforms' cross-mapping means a second framework is cheaper to operate later if named demand ever arrives. The disciplined move is to hold the line until a real trigger - a named contract requirement, a verifiably lost deal, a regulation - and to pre-negotiate the add-on price at signing so a future yes doesn't arrive at mid-contract rates. What the platforms and the fee stack look like for that first framework: the true cost of SOC 2 and which platform fits which program.
You've just read the map - locate yourself on it.
Get your minimum framework set - 3 minutesThe assessment turns your deal flow and timeline into a concrete answer instead of a maybe.
Independent by structure: we take nothing from platform vendors - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.
The decision pages, by framework
SOC 2: Do you need it? · What it actually costs · Which platform fits
ISO 27001: Do you need it? · Which platform fits
HIPAA: Do you need the software?
ISO 42001 (AI): Do you need it yet?
Cross-cutting: SOC 2 vs ISO 27001 - which first? · How multi-framework pricing compounds
Frequently asked questions
Don't buy the catalog.
Find your minimum framework set in 3 minutesFree, no email required to see results - the same assessment our qualification calls start from.
Independent by structure: we take nothing from platform vendors - no commissions, no partnerships. Our revenue comes from services partners, disclosed plainly.