SOC 2 HIPAA NIST CSF Notion workspace

US Compliance Workspace

SOC 2 Type II · HIPAA Security Rule · NIST CSF 2.0 · CCPA/CPRA · NIST AI RMF 1.0

All-in-one Notion workspace for US compliance and governance programmes.

Manage SOC 2, NIST CSF, HIPAA and AI governance activities through a structured operational workspace covering risks, controls, incidents, audits, vendors and executive reporting.

Designed as a practical alternative to spreadsheets, disconnected documents and expensive GRC software.

10
Databases
5
Frameworks
SOC 2
Evidence Repo
HIPAA
PHI Register

Organisation

$590 + VAT

one-time · single organisation · internal use

All 10 databases
SOC 2 Evidence Repository + HIPAA PHI Data Register
Executive dashboard
6 report templates

Consultant Pro

$3,490 + VAT

one-time · consulting firm · team use

Everything in Consultant
Multiple consultant user seats
Firm-wide internal collaboration
Standardised delivery framework

New to this? Try the free US Starter — 3 core databases, realistic seed data, no credit card.

Try the free Starter →

10 databases — built for US audit readiness

Every database is linked bidirectionally. SOC 2 evidence links to controls. Controls link to risks, findings and audit items. Incidents link to breach notification requirements and safeguards.

Compliance requirements
SOC 2 TSC, HIPAA safeguards, NIST CSF, CCPA/CPRA, NIST AI RMF — pre-mapped with gap status.
🛡
Controls catalogue
Controls mapped to all framework requirements. Linked to risks, evidence and audit findings.
Risk register
Cybersecurity and operational risks. Likelihood x impact scoring. Treatment tracking.
📊
SOC 2 Evidence Repository
Evidence items tagged by TSC control, collection date, owner and status. Audit period tracked.
🏥
HIPAA PHI Data Register
PHI categories, processing systems, business associates, safeguards, access controls and breach history.
Incident register
NIST CSF IR phases. HIPAA breach notification timeline tracking. Linked to controls and evidence.
🏪
Vendor risk register
Third-party providers with security classification, data access scope, BAA tracking and assessment dates.
📋
Audit
SOC 2 Type I/II readiness. Audit plans, findings, corrective actions, owners and deadlines.
🤖
AI systems register
NIST AI RMF 1.0 mapping per AI system. Risk classification, human oversight controls and governance.
📄
Policy library
Security and privacy policies with version control, approval status and review calendar.

Also included: Executive dashboard · 6 report templates (SOC 2 Readiness, HIPAA Security Summary, Risk Register Summary, Vendor Risk Summary, AI Governance Report, Board GRC Report) · Documentation & User Guide · Seed data — MedFlow Technologies scenario

Licence details

US Compliance Workspace — Organisation

$590 + VAT · one-time · single organisation · internal use

Includes

  • All 10 databases
  • SOC 2 Evidence Repository + HIPAA PHI Data Register
  • Executive dashboard
  • 6 report templates
  • Seed data — MedFlow Technologies scenario
  • Documentation and User Guide
  • All v1.x updates

Licence terms

  • Single Organisation Use
  • Unlimited Internal Users
  • Internal Business Use
  • No Client Delivery Rights

SaaS companies, healthcare organisations, technology firms and internal compliance teams.

US Compliance Workspace — Consultant Pro

$3,490 + VAT · one-time · consulting firm · team use

Includes

  • Everything in Consultant
  • Multiple consultant user seats
  • Firm-wide internal collaboration
  • Standardised delivery framework
  • Priority email support

Licence terms

  • Unlimited Client Implementations
  • Multiple Consultant Users
  • Internal Team Collaboration
  • Commercial Client Delivery Rights
  • Firm-Wide Usage Rights

Consulting firms, managed compliance providers and professional advisory teams.

All v1.x updates included. Major version upgrades (v2.0+) offered at discounted pricing for existing licence holders. Full licence terms →

Frequently asked

Does this make my organisation SOC 2 compliant?

No. SOC 2 Type II certification requires an independent audit by a licensed CPA firm. This workspace organises your controls, collects your evidence and tracks your readiness — so that when the auditor arrives, you are prepared. It accelerates readiness; it does not replace the audit.

Does this make my organisation HIPAA compliant?

No. HIPAA compliance is an ongoing operational requirement, not a certification. This workspace structures your PHI inventory, tracks your safeguards and documents your risk analysis. It does not replace legal review or constitute a HIPAA compliance certification.

What is the difference between Consultant and Consultant Pro?

The Consultant licence is for a single consultant working across multiple client engagements independently. Consultant Pro adds multiple user seats so an entire consulting team can collaborate internally and share the framework across the firm.

Is this suitable for a pre-SOC 2 startup?

Yes. Many organisations purchase this workspace to structure their security programme before beginning the formal SOC 2 audit process. The seed data shows you what a mature SOC 2 programme looks like inside the workspace.

Where is my compliance data stored?

In your own Notion workspace. AltShift has no access to your data.

Is this legal or regulatory advice?

No. This is a structured operational workspace. It does not constitute legal, regulatory or compliance advice and does not guarantee certification, audit success or regulatory compliance.

Delivered as a Notion workspace — requires an active Notion account. Notion is a trademark of Notion Labs, Inc. AltShift is not affiliated with or endorsed by Notion Labs, Inc. SOC 2 is a service mark of the American Institute of Certified Public Accountants.