Glossary of Compliance
Compliance Glossary
Our list of curated compliance glossary offers everything you to know about compliance in one place.
AOC
An Attestation of Compliance (AOC) is a documented declaration of an organization’s compliance with the PCI DSS. It proves that a company can successfully implement outstanding security best practices to protect cardholder data.
Additional reading
Proving Compliance: Why SOC 2 Evidence Collection Matters
TL,DR: SOC 2 evidence proves your controls operate as described during the audit period. Auditors expect policies, logs, screenshots, configurations, attestations, tickets, and control owner records. The article explains evidence types, collection mistakes, repository hygiene, and continuous audit readiness. Years ago, collecting evidence was a walk in the park. But we can’t say the same…
From Compliance to Confidence: Preparing for Enterprise Security Reviews
TL,DR: Enterprise security reviews test whether your controls satisfy customer, vendor, and enterprise buyer expectations. The article covers review readiness across policies, access controls, certifications, risks, and evidence. Use it to prepare security responses before sales, procurement, or customer assurance reviews stall. When startups engage with enterprise prospects, the initial conversations often revolve around features,…
Vanta Pricing: Should You Invest?
TL;DR Vanta pricing typically ranges from ~$10K to $80K+ per year, depending on company size, frameworks, and add-ons. Vanta’s pricing includes four custom-quoted plans that add automation, customization, and risk capability as you move up. Costs can rise due to add-ons, integrations, Trust Center features, and implementation services. Companies often compare alternatives like Sprinto when they want pricing…

Sprinto: Your growth superpower
Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.






