<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Agency Insights</title>
    <link>https://blog.getagency.com</link>
    <description>Expert perspectives on cybersecurity compliance, governance, and trust — from the team at Agency.</description>
    <language>en-us</language>
    <lastBuildDate>Sat, 08 Aug 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://blog.getagency.com/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>How Much Does a SOC 2 Penetration Test Cost in 2026?</title>
      <link>https://blog.getagency.com/articles/soc-2-penetration-test-cost-2026</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/soc-2-penetration-test-cost-2026</guid>
      <description>Real 2026 penetration testing prices by scope, sourced from vendors who publish them — plus what drives cost, why the cheapest AI tier can fail your audit, and the hidden fees buyers discover late.</description>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SOC 2 in Due Diligence: What Investors and Enterprise Buyers Actually Check</title>
      <link>https://blog.getagency.com/articles/soc-2-in-due-diligence-what-investors-check</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/soc-2-in-due-diligence-what-investors-check</guid>
      <description>What reviewers actually open your SOC 2 report to check during fundraising and enterprise procurement — the six items they verify in order, sample due diligence questionnaire items, and which findings reprice a deal.</description>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Switching from Drata to Vanta (or Vanta to Drata): Migration Guide, Costs, and Gotchas</title>
      <link>https://blog.getagency.com/articles/switching-drata-to-vanta-migration-guide</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/switching-drata-to-vanta-migration-guide</guid>
      <description>A practical migration guide for switching between Drata and Vanta — what transfers and what doesn&apos;t, how to remap evidence and controls, the audit-window trap, real costs, and the contract terms to check first.</description>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The Managed Compliance Buyer&apos;s Checklist: 25 Questions to Ask Before You Sign</title>
      <link>https://blog.getagency.com/articles/managed-compliance-buyers-checklist-25-questions</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/managed-compliance-buyers-checklist-25-questions</guid>
      <description>Twenty-five questions to ask any managed compliance provider before you sign — covering scope, staffing, platform lock-in, evidence SLAs, auditor independence, and pricing, with the good answer and the red flag for each.</description>
      <pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Maintain SOC 2 Compliance in 2026</title>
      <link>https://blog.getagency.com/articles/how-to-maintain-soc-2-compliance-2026</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/how-to-maintain-soc-2-compliance-2026</guid>
      <description>SOC 2 compliance maintenance gets harder over time as controls drift. A definitive guide to preventing drift with continuous monitoring, audit-ready operations, and compliance management best practices that keep you in good standing year-round.</description>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SOC 2 Readiness for Fundraising SaaS Startups</title>
      <link>https://blog.getagency.com/articles/soc-2-readiness-for-fundraising-saas-startups</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/soc-2-readiness-for-fundraising-saas-startups</guid>
      <description>A practical guide to SOC 2 compliance services for fundraising-stage SaaS startups — what readiness actually involves, why investors and enterprise buyers ask for it, and how a done-for-you team gets you audit-ready 3–4× faster.</description>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Top 7 SOC 2 Services for SaaS Startups in 2026</title>
      <link>https://blog.getagency.com/articles/top-soc-2-services-for-saas-startups-2026</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/top-soc-2-services-for-saas-startups-2026</guid>
      <description>A ranked comparison of the top SOC 2 compliance services for SaaS startups in 2026 — readiness and maintenance providers compared on startup fit, ongoing support, and implementation depth, from automation platforms to done-for-you managed teams.</description>
      <pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Can One Hire Really Run SOC 2, ISO 27001, HIPAA &amp; GDPR?</title>
      <link>https://blog.getagency.com/articles/can-one-hire-run-soc-2-iso-27001-hipaa-gdpr</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/can-one-hire-run-soc-2-iso-27001-hipaa-gdpr</guid>
      <description>Why one GRC hire hits a ceiling running SOC 2, ISO 27001, HIPAA, and GDPR together — and what a real multi-framework program requires instead.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GRC Manager Salary &amp; True Cost in 2026 (It&apos;s 2–3× the Offer Letter)</title>
      <link>https://blog.getagency.com/articles/grc-manager-salary-and-true-cost</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/grc-manager-salary-and-true-cost</guid>
      <description>GRC manager salaries span $95K–$267K+ in 2026, but fully loaded the real cost is 2–3× the offer. The full cost model, and how it compares to a managed team.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Hire a GRC Manager in 2026: Job Description, Interview Questions &amp; the Vanta/Drata Reality</title>
      <link>https://blog.getagency.com/articles/how-to-hire-a-grc-manager</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/how-to-hire-a-grc-manager</guid>
      <description>How to hire a GRC manager who can actually run Vanta or Drata: the real role, must-have skills, a job description template, and interview questions.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>In-House vs. Managed GRC: A Decision Framework for Vanta &amp; Drata Teams</title>
      <link>https://blog.getagency.com/articles/in-house-vs-managed-grc-decision-framework</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/in-house-vs-managed-grc-decision-framework</guid>
      <description>A genuinely balanced decision framework for staffing your compliance program — six criteria to score, the cases where hiring in-house really wins, the cases where a managed team wins, and what to demand from any managed provider.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The One-Person Compliance Team Is a Single Point of Failure</title>
      <link>https://blog.getagency.com/articles/one-person-compliance-team-single-point-of-failure</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/one-person-compliance-team-single-point-of-failure</guid>
      <description>Why a solo GRC manager is a single point of failure — bus factor of one, knowledge in one head, audit-window risk — and how to build redundancy.</description>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>AuditNex: The Best Place to Find an Auditor — and Actually Know What You&apos;re Paying</title>
      <link>https://blog.getagency.com/articles/auditnex-the-best-place-to-find-an-auditor</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/auditnex-the-best-place-to-find-an-auditor</guid>
      <description>AuditNex is the fastest, most transparent way to find a SOC 2 auditor — match with vetted firms, compare real quotes side by side, and get the best deal without a single sales call. Here is why we endorse it.</description>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>What Does Vanta Do? A Complete Guide to the Compliance Automation Platform</title>
      <link>https://blog.getagency.com/articles/what-does-vanta-do</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/what-does-vanta-do</guid>
      <description>Vanta automates security compliance — continuously collecting evidence, monitoring controls, and managing frameworks like SOC 2 and ISO 27001. This complete guide explains exactly what Vanta does, how it works, and how Agency, the number one Vanta partner globally, gets you live on it faster.</description>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Best Practices for ISO 27001 Internal Audit</title>
      <link>https://blog.getagency.com/articles/iso-27001-internal-audit-best-practices</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/iso-27001-internal-audit-best-practices</guid>
      <description>How to plan, execute, and follow up on ISO 27001 internal audits: evidence techniques, finding categorization, and corrective action management.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CAIQ vs SIG: Which Security Questionnaire Should You Use?</title>
      <link>https://blog.getagency.com/articles/caiq-vs-sig</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/caiq-vs-sig</guid>
      <description>CAIQ vs SIG compared: origins, scope, and structure, when to use each, cost and access, and how both map to the frameworks behind your vendor program.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Assessment Process: What to Expect from Pre-Assessment to Certification</title>
      <link>https://blog.getagency.com/articles/cmmc-assessment-process</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-assessment-process</guid>
      <description>The CMMC Assessment Process (CAP) defines how C3PAOs evaluate defense contractors. Learn what happens in each phase and how to prepare your team.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC C3PAO List: How to Find and Select an Authorized Assessment Organization</title>
      <link>https://blog.getagency.com/articles/cmmc-c3pao-list</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-c3pao-list</guid>
      <description>Find authorized CMMC C3PAOs through the Cyber AB Marketplace. Learn selection criteria, due diligence steps, and how to evaluate assessment organizations.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC C3PAO: What Defense Contractors Need to Know About Third-Party Assessors</title>
      <link>https://blog.getagency.com/articles/cmmc-c3pao</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-c3pao</guid>
      <description>Learn what CMMC C3PAOs are, how they are accredited by the Cyber AB, the assessment process, scoring methodology, and how to select the right C3PAO for your organization.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Certification Costs: What Defense Contractors Should Budget</title>
      <link>https://blog.getagency.com/articles/cmmc-certification-costs</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-certification-costs</guid>
      <description>A breakdown of CMMC certification costs — gap assessment, remediation, C3PAO fees, and ongoing maintenance — plus what drives the number up or down.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Compliance Checklist: A Phased Approach to Certification Readiness</title>
      <link>https://blog.getagency.com/articles/cmmc-compliance-checklist</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-compliance-checklist</guid>
      <description>A comprehensive CMMC compliance checklist covering scoping, gap assessment, remediation, SSP documentation, and assessment preparation for defense contractors.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Compliance Deadline: Phased Rollout Timeline and What to Expect</title>
      <link>https://blog.getagency.com/articles/cmmc-compliance-deadline</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-compliance-deadline</guid>
      <description>The CMMC compliance deadline explained: the phased rollout schedule, the 48 CFR rulemaking that triggers it, and why contractors should start now.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Compliance: Your Complete Guide to the Certification Journey</title>
      <link>https://blog.getagency.com/articles/cmmc-compliance</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-compliance</guid>
      <description>CMMC compliance requires defense contractors to prove cybersecurity maturity. Learn the three CMMC 2.0 levels, the rollout timeline, and certification path.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Final Rule: What 32 CFR Part 170 Means for Defense Contractors</title>
      <link>https://blog.getagency.com/articles/cmmc-final-rule</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-final-rule</guid>
      <description>How the CMMC final rule (32 CFR Part 170) codifies CMMC 2.0: key provisions, phased implementation, POA&amp;M rules, affirmations, and the DFARS timeline.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Gap Assessment</title>
      <link>https://blog.getagency.com/articles/cmmc-gap-assessment</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-gap-assessment</guid>
      <description>How a CMMC gap assessment measures you against NIST 800-171, surfaces compliance gaps, and builds a prioritized remediation roadmap before your C3PAO visit.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Level 1 Compliance: The 15 Basic Safeguarding Requirements Explained</title>
      <link>https://blog.getagency.com/articles/cmmc-level-1-compliance</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-level-1-compliance</guid>
      <description>CMMC Level 1 requires 15 basic safeguarding practices from FAR 52.204-21 with annual self-assessment. Learn each requirement and how to implement them.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Level 2 Compliance: The Complete Guide to 110 Controls and C3PAO Assessment</title>
      <link>https://blog.getagency.com/articles/cmmc-level-2-compliance</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-level-2-compliance</guid>
      <description>CMMC Level 2 requires all 110 NIST SP 800-171 controls across 14 families. Compare self-assessment and C3PAO paths, SPRS scoring, and the POA&amp;M process.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Managed Services: What MSPs and MSSPs Handle vs. Your Responsibility</title>
      <link>https://blog.getagency.com/articles/cmmc-managed-services</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-managed-services</guid>
      <description>CMMC managed service providers help defense contractors meet compliance requirements. Learn about shared responsibility, enclave hosting, and MSP evaluation.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC Requirements for Small Business: Scope Reduction, Costs, and Resources</title>
      <link>https://blog.getagency.com/articles/cmmc-requirements-for-small-business</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-requirements-for-small-business</guid>
      <description>Small businesses face unique CMMC challenges. Learn scope reduction strategies, cost management approaches, and available resources for small defense contractors.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC RPO: What Registered Provider Organizations Do and How to Choose One</title>
      <link>https://blog.getagency.com/articles/cmmc-rpo</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-rpo</guid>
      <description>CMMC Registered Provider Organizations (RPOs) help defense contractors prepare for certification. Learn what RPOs do, their limitations, and how to evaluate them.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMC vs NIST 800-171: What Defense Contractors Need to Know</title>
      <link>https://blog.getagency.com/articles/cmmc-vs-nist-800-171</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmc-vs-nist-800-171</guid>
      <description>Compare CMMC and NIST 800-171 side by side. Learn how CMMC Level 2 builds on the same 110 controls but adds third-party verification and accountability.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CMMI vs CMMC vs NIST: Understanding Three Distinct Frameworks</title>
      <link>https://blog.getagency.com/articles/cmmi-vs-cmmc-vs-nist</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cmmi-vs-cmmc-vs-nist</guid>
      <description>CMMI, CMMC, and NIST compared: process improvement versus cybersecurity certification versus security standards, and when each framework applies.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Compliance Audit Software: Platforms, Features, and Selection Guide</title>
      <link>https://blog.getagency.com/articles/compliance-audit-software</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/compliance-audit-software</guid>
      <description>Compliance audit software compared — Vanta, Drata, Sprinto, Secureframe, Tugboat Logic — on evidence collection, control mapping, and monitoring.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CUI Enclave</title>
      <link>https://blog.getagency.com/articles/cui-enclave</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/cui-enclave</guid>
      <description>How a CUI enclave cuts CMMC assessment scope by isolating CUI in a hardened environment: VDI, GCC High, physical segmentation, and managed options.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Extending SOC 2 to ISO 27001: A Practical Guide</title>
      <link>https://blog.getagency.com/articles/extending-soc-2-to-iso-27001</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/extending-soc-2-to-iso-27001</guid>
      <description>How to leverage your existing SOC 2 compliance program to achieve ISO 27001 certification with minimal incremental effort by mapping control overlap and addressing the gaps.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>FedRAMP Cost Breakdown: What to Budget for Authorization in 2026</title>
      <link>https://blog.getagency.com/articles/fedramp-cost</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/fedramp-cost</guid>
      <description>A detailed breakdown of FedRAMP authorization costs by phase — readiness assessment, documentation, 3PAO assessment, and continuous monitoring — with strategies to reduce spend and timelines.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>FedRAMP Levels Explained: Low, Moderate, and High Impact</title>
      <link>https://blog.getagency.com/articles/fedramp-levels</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/fedramp-levels</guid>
      <description>A detailed guide to FedRAMP impact levels — Low, Moderate, and High — including control counts, data types, authorization paths, and how to choose the right level for your cloud service.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GDPR Compliance in 2024: How AI and LLMs Impact European User Rights</title>
      <link>https://blog.getagency.com/articles/gdpr-ai-llm-compliance</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/gdpr-ai-llm-compliance</guid>
      <description>How large language models challenge GDPR rights like erasure and explanation, plus guidance on DPIAs, lawful basis for training data, and the EU AI Act.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>GRC Automation: Platforms, Workflows, and Selection Guide</title>
      <link>https://blog.getagency.com/articles/grc-automation</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/grc-automation</guid>
      <description>How GRC automation changes risk assessment, policy management, control testing, and evidence collection — with a platform comparison and rollout plan.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How Much Does a Virtual CISO Cost</title>
      <link>https://blog.getagency.com/articles/how-much-does-a-vciso-cost</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/how-much-does-a-vciso-cost</guid>
      <description>Virtual CISO pricing explained: retainer, project, and hourly models, what drives cost up or down, and total cost of ownership versus a full-time hire.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>ISO 27001, 27017, and 27018: Understanding the Differences</title>
      <link>https://blog.getagency.com/articles/iso-27001-27017-27018-differences</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/iso-27001-27017-27018-differences</guid>
      <description>A detailed comparison of ISO 27001, ISO 27017, and ISO 27018 covering how these standards relate, which industries benefit from each, and how implementing them together reduces audit overhead.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Microsoft GCC vs GCC High: Which Government Cloud Do You Need?</title>
      <link>https://blog.getagency.com/articles/microsoft-gcc-vs-gcc-high</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/microsoft-gcc-vs-gcc-high</guid>
      <description>Microsoft GCC vs GCC High compared on compliance standards, data residency, personnel screening, Microsoft 365 features, and licensing cost.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>NIST 800-171 Rev 3 Transition: What Is Changing and How to Prepare</title>
      <link>https://blog.getagency.com/articles/nist-800-171-rev-3-transition</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/nist-800-171-rev-3-transition</guid>
      <description>A comprehensive guide to the NIST 800-171 Rev 3 transition covering control consolidation, new ODP parameters, timeline for DFARS and CMMC alignment, and what organizations need to do now.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SBIR Grants: How to Secure Authority to Operate (ATO)</title>
      <link>https://blog.getagency.com/articles/sbir-ato-guide</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/sbir-ato-guide</guid>
      <description>A practical guide for SBIR and STTR awardees on securing an Authority to Operate. Covers baseline selection, inherited controls, working with Authorizing Officials, and the FedRAMP pathway for cloud products.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Security Compliance Questionnaires: SIG, CAIQ, VSA, HECVAT, and How to Manage Them</title>
      <link>https://blog.getagency.com/articles/security-compliance-questionnaires</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/security-compliance-questionnaires</guid>
      <description>A guide to SIG, CAIQ, VSA, and HECVAT security questionnaires — and how to manage questionnaire fatigue with a knowledge base and AI-assisted responses.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SIG Lite: The Streamlined Vendor Assessment for Lower-Risk Vendors</title>
      <link>https://blog.getagency.com/articles/sig-lite</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/sig-lite</guid>
      <description>When and how to use SIG Lite for vendor risk: what it covers, how it differs from the full SIG, and where it fits in a risk-tiering strategy.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SOC 2 Audit Cost: A Complete Breakdown of Engagement Fees in 2026</title>
      <link>https://blog.getagency.com/articles/soc-2-audit-cost</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/soc-2-audit-cost</guid>
      <description>What a SOC 2 audit engagement costs in 2026: readiness fees, Type 1 and Type 2 pricing, the hidden expenses teams miss, and how to manage them.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SOC 2 Automation: What Platforms Actually Automate and Where Human Judgment Still Matters</title>
      <link>https://blog.getagency.com/articles/soc-2-automation</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/soc-2-automation</guid>
      <description>An honest look at SOC 2 automation: what GRC platforms genuinely automate, what still needs human judgment, and where the ROI actually lands.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SOC 2 Controls List: Complete Reference to Trust Service Criteria and Common Criteria</title>
      <link>https://blog.getagency.com/articles/soc-2-controls-list</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/soc-2-controls-list</guid>
      <description>A full SOC 2 controls reference by Trust Service Criteria: Common Criteria CC1–CC9 plus Availability, Processing Integrity, Confidentiality, and Privacy.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>SOC 2 Password Requirements: What Auditors Expect Under CC6.1 and Modern Authentication Standards</title>
      <link>https://blog.getagency.com/articles/soc-2-password-requirements</link>
      <guid isPermaLink="true">https://blog.getagency.com/articles/soc-2-password-requirements</guid>
      <description>What SOC 2 auditors look for in authentication under CC6.1: password complexity, MFA, NIST 800-63B alignment, SSO, and policy documentation.</description>
      <pubDate>Mon, 06 Apr 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
