Compliance Frameworks Decoded
Cut through the alphabet soup. Learn which frameworks actually apply to you (HIPAA, PCI DSS, GDPR, SOC 2, ISO 27001, NIST/CMMC), the ~65% of controls they all share, how to satisfy many at once with one control set, and how to build a compliance roadmap. The hub course — take the deep-dive spoke for each framework you pick. For founders, managers, compliance leads, and engineers.
"We need SOC 2 and GDPR, most of the work is shared, and here's our one-control-set roadmap to satisfy both"
6 Interactive Sessions
Short, interactive sessions — watch it work, steer it, then build it yourself. Go deeper anytime with the full code walkthrough.
- 1
Why compliance exists — the breach and the fine
Compliance isn't bureaucracy for its own sake — it's trust written down, enforced by two forces: regulators who fine you and customers who won't buy without proof.
- 2
Which frameworks apply to you
You don't get to pick your frameworks off a menu — your business decides them. Applicability is conditional (triggered by what you handle and who you sell to) and additive (most companies need two or three, not one).
- 3
The shared DNA — the ~65% every framework repeats
Almost every framework asks for the same handful of control families — access control, encryption, logging, incident response, vendor risk, awareness training, and governance — just filed under different code numbers.
- 4
Do it once, satisfy many — the crosswalk
Because the frameworks share most of their controls, you don't do the work N times — you maintain ONE internal control set, map each framework onto it, and collect the evidence once.
- 5
Scope & the framework-specific overlays
A framework only applies to the part of your business that touches the regulated thing — so you draw the in-scope line deliberately, do the shared core once, and add only the thin overlay each framework needs.
- 6
Your compliance roadmap
Compliance is one navigable program, not a pile of monsters: pick what applies, build the shared core once, map & add the overlays, collect evidence once, and keep it running — then go deep per framework in the spoke courses.
Production patterns you'll master
Synthetic data included
- Framework picker (applies-when)
- Shared control families
- Cross-framework crosswalk example
- Overlays by framework
What you walk away with
Shareable portfolio
A public URL showing your module timeline, patterns mastered, and completion status.
All the code
Download everything as a ZIP — pipelines, guardrails, deployment configs. Yours forever.
Module walkthrough
Each module documented with deliverables and the production pattern you implemented.
Ready to build your compliance frameworks decoded?
First course free. $20 per course after that.