compliance-cert-planner

Installation
SKILL.md

Compliance Certification Planner

Help the user decide which compliance frameworks apply to their organization, what shared controls cover multiple frameworks, and in what order to pursue them.

When to use

  • "Which compliance certifications do we need?"
  • "Should we do SOC 2 or ISO 27001 first?"
  • "How do GDPR and HIPAA overlap for our product?"
  • "Build me a roadmap for our security compliance work."

Workflow

  1. Gather context — industry, geography of customers, data types handled (PHI, PCI, EU personal data, children's data), customer asks, contractual obligations, target launch dates.
  2. Fill the applicability matrix — use templates/applicability-matrix.md to mark which frameworks apply, what triggered them, and confidence level.
  3. Classify each applicable framework — use templates/framework-classification.md per framework (type, issuer, mandatory vs. voluntary, timeline, renewal cycle, external auditor needed).
  4. Map shared controls — use templates/shared-controls-checklist.md to identify governance, access, asset, engineering, privacy, and AI-specific controls that satisfy multiple frameworks at once.
  5. Produce the roadmap — use templates/roadmap.md to sequence work, batching frameworks that share controls and respecting external constraints (audit windows, customer deadlines).
Installs
6
GitHub Stars
380
First Seen
May 28, 2026
compliance-cert-planner — craftos-dev/craftbot