Compliance Management for Every Organization

29 Frameworks.
One audit platform.

29 compliance frameworks. One platform. Assign controls to staff, collect evidence, and generate audit-ready PDF reports — whether you run a school district, healthcare clinic, MSP, or government agency.

Start 3-Day Trial See How It Works
FERPA
CIPA
NIST CSF 2.0
IDEA / SPED
HIPAA
PCI-DSS 4.0
https://complyiq.app
Overview
Dashboard
Frameworks
🔒 FERPA
🛡 CIPA
⚡ NIST CSF
🎓 IDEA / SPED
⚕ HIPAA
💳 PCI-DSS
Tools
📋 Assessments
📄 Reports
👥 Staff Tasks
Overall Score
74%
Needs attention
Open Gaps
22
4 critical
IEPs Due
23
This month
Staff Tasks
91%
Complete
FERPA
88%
CIPA
92%
NIST CSF
61%
IDEA / SPED
54%
HIPAA
73%
PCI-DSS 4.0
67%
Active Alerts
2 evaluations past 60-day IDEA deadline
HIPAA risk analysis not on file — required by Security Rule
PCI MFA not enabled on all cardholder system accounts

Built for organizations that can't afford compliance gaps.

From single-campus schools to multi-site MSPs, ComplyIQ scales to your compliance needs.

🏫
K-12 Schools
FERPA, IDEA, Title IX, McKinney-Vento, TEA monitoring, and 20+ more frameworks.
🏥
Healthcare
HIPAA, PCI-DSS, OSHA, and NIST CSF for clinics, dental offices, and school health.
🖥️
MSPs & IT Firms
Manage compliance for multiple clients from one dashboard. NIST, CIS Controls, HIPAA, and PCI-DSS.
🏛️
Government Agencies
NIST CSF, CISA CPGs, EDGAR, and ADA Title II compliance for local and state agencies.
🤝
Nonprofits
EDGAR grant compliance, HIPAA, OSHA, and COPPA for nonprofits serving children and families.
💼
Small Businesses
PCI-DSS, HIPAA, OSHA, and NIST CSF for SMBs that handle sensitive data or payments.

29 Frameworks.
One unified platform.

Stop juggling spreadsheets for each regulation. ComplyIQ maps overlapping controls so you answer once and get credit across every framework — all 29 of them.

🔒
FERPA
Family Educational Rights and Privacy Act
Protect student education records and prove access control, vendor agreements, audit logging, and breach notification procedures are in place.
Access ControlAudit LoggingVendor DPAsData RetentionBreach Notification
🛡
CIPA
Children's Internet Protection Act
Maintain E-Rate funding eligibility by documenting content filtering, internet safety policies, student monitoring, and annual safety education.
Content FilteringSafety PolicyMonitoringBYOD CoverageStudent Education
NIST CSF 2.0
Cybersecurity Framework + NIST 800-171
Establish a cybersecurity posture across all six functions: Govern, Identify, Protect, Detect, Respond, and Recover — with optional 800-171 mapping.
GovernIdentifyProtectDetectRespondRecover
🎓
IDEA / SPED
Individuals with Disabilities Education Act
Track IEP timelines, evaluation deadlines, parent rights, transition planning, and discipline procedures — with TEA audit prep mode built in.
IEP Timelines60-Day Eval RuleParent RightsLRE DocsCAP Tracker
⭐ New
HIPAA
Health Insurance Portability & Accountability Act
Privacy Rule, Security Rule, and Breach Notification Rule coverage for clinics, dental offices, therapists, school health, and any organization handling PHI.
Risk AnalysisAccess ControlsBAA ManagementEncryptionBreach Response
⭐ New
💳
PCI-DSS 4.0
Payment Card Industry Data Security Standard
All 12 PCI-DSS 4.0 requirements for any business that accepts credit cards — retail, restaurants, e-commerce, auto dealers, law firms, and nonprofits.
Network SecurityCardholder DataMFAVulnerability TestingLogging
💬
ESL / ELL
English Language Learner Program Compliance
Title III, LPAC requirements, parent notification, and TEA reporting for districts serving English Language Learner students.
HLS at EnrollmentLPAC CommitteeTELPASExit Criteria
Section 504
Section 504 of the Rehabilitation Act
Identification, evaluation, plan development, and procedural safeguards for students with disabilities who don't qualify under IDEA.
504 CoordinatorEvaluation ProcessAccommodationsParent Rights
Gifted & Talented
Texas 19 TAC Chapter 89.2 G/T Compliance
Identification, annual nomination process, 30-hour teacher training, state allotment compliance, and PEIMS reporting for G/T programs.
Nomination Process30-Hr TrainingPEIMS ReportingAnnual Review
📋
CAP
Corrective Action Plan Compliance
TEA monitoring findings, OCR complaint resolution, due process remediation, and post-closure sustainability tracking for districts under corrective action.
TEA FindingsOCR ComplaintsDue ProcessRoot Cause
🔒
K12 SIX ECP
Essential Cybersecurity Protections
14-control framework built by K-12 IT practitioners. The most practical K-12 cybersecurity standard, covering network safety, access management, and incident response.
MFADNS FilteringBackupsIncident Response
Title IX
Sex Discrimination Compliance
Coordinator designation, grievance procedures, training records, and incident documentation — one of the most actively enforced federal mandates in K-12.
CoordinatorGrievanceTrainingRecords
🔒
COPPA
Children's Online Privacy
Governs collection of personal data from students under 13. Covers parental consent, vendor management, data retention, and EdTech operator obligations.
Parental ConsentVendor MgmtData Retention
🛡
CISA CPGs
Cybersecurity Performance Goals
CISA's cross-sector cybersecurity goals increasingly referenced in state audits and FCC Cybersecurity Pilot applications. ~40 actionable controls.
Account SecurityPatchingIncident Response
📜
PPRA
Protection of Pupil Rights
Parental consent for surveys, data collection, and marketing research. Covers annual notification, inspection rights, and opt-out procedures.
SurveysParental RightsAnnual Notice
Title II ADA
Americans with Disabilities Act
Digital accessibility (WCAG 2.1 AA), facilities compliance, grievance procedures, and program accessibility for students and staff with disabilities.
Web AccessibilityFacilitiesGrievance
🛡
CIS Controls v8.1
Center for Internet Security
56 controls across Implementation Groups IG1-IG3. The gold standard for enterprise cybersecurity, mapped to NIST CSF and K12 SIX for comprehensive coverage.
Asset InventoryVuln MgmtPen Testing
💰
EDGAR
Federal Grant Compliance
Education Department General Administrative Regulations for Title I, Title II, and ESSER funds. Covers allowable costs, procurement, reporting, and subrecipient monitoring.
Title IESSERProcurement
📊
SDPC
Student Data Privacy Consortium
National Data Privacy Agreement framework for EdTech vendor management. Covers data governance, vendor contracts, student rights, and breach notification.
NDPAVendor ContractsData Rights
👷
OSHA
Workplace Safety
OSHA standards for K-12 school operations including written safety programs, hazard communication, bloodborne pathogens, emergency action plans, and OSHA 300 logs.
Safety ProgramBloodborne PathogensOSHA 300
🇺🇸
Texas HB 3834
Texas Student Data Privacy
Texas-specific student data privacy law governing collection, vendor contracts, security safeguards, breach notification, and parent rights for Texas districts.
Data InventoryVendor ContractsBreach Notice
💵
Title I
Improving Basic Programs
ESSA Title I compliance covering comparability, supplement not supplant, parent engagement policies, school-parent compacts, and fiscal management.
ComparabilityParent EngagementFiscal Mgmt
🏠
McKinney-Vento
Homeless Student Services
Federal law ensuring students experiencing homelessness have equal access to education. Covers identification, immediate enrollment, transportation, and liaison duties.
IdentificationEnrollmentTransportation
🚨
TEC Chapter 37
Student Discipline
Texas Education Code Chapter 37 covering DAEP placement, expulsion procedures, threat assessment teams, disproportionality monitoring, and code of conduct requirements.
DAEPThreat AssessmentDisproportionality
🎓
TEC Chapter 29
Special Programs
Texas Education Code Chapter 29 covering bilingual/ESL education, special education ARD procedures, gifted and talented identification, dyslexia services, and pre-K eligibility.
Bilingual/ESLARDDyslexia
💸
ESSER / ARP
COVID Relief Fund Compliance
ESSER I, II, and III / ARP fund compliance still actively audited by TEA through 2026. Covers allowable expenditures, set-asides, procurement, reporting, and closeout deadlines.
Allowable CostsSet-AsidesCloseout
📈
TEA Financial Accountability
FIRST Rating Compliance
Texas FIRST financial integrity indicators, budget adoption timelines, annual audit submission, PEIMS financial reporting, and competitive bidding requirements.
FIRST RatingAnnual AuditPEIMS

From setup to audit-ready in days, not months.

1
Create Your Org
Set up your profile, add campus or business sites, and choose which of the 29 frameworks apply to your environment.
2
Assign Controls
Delegate controls to the right staff — principals, SPED coordinators, and front office see only what they need to answer.
3
Collect Evidence
Staff answer guided questions and upload supporting documents. Overlapping controls across frameworks are answered once automatically.
4
Generate Report
Download a professional PDF audit report with executive summary, scorecard, gap list, and attestation block — ready for any auditor.
🤝 Works Alongside FrontLine

Not a FrontLine replacement.
A compliance layer on top.

FrontLine is built for writing IEPs. ComplyIQ is built for proving compliance to auditors. They solve different problems — which is exactly why they work better together.

💬 The pitch to your superintendent

"We already use FrontLine to write IEPs. ComplyIQ is what we show the auditor when they arrive — a unified compliance scorecard across FERPA, CIPA, NIST, and IDEA with all our evidence attached, gaps tracked, and corrective actions documented."

Feature FrontLine ComplyIQ
IEP writing & document editor
State PEIMS/IDEA reporting
Medicaid billing
IEP deadline & timeline tracking
TEA audit prep & CAP tracker
FERPA compliance assessment
CIPA / E-Rate compliance
NIST cybersecurity framework
HIPAA coverage
PCI-DSS 4.0
Cross-framework gap reports
PDF audit report generator
MSP multi-tenant white-label
Monthly cost (small district)$1,500+/mo$149/mo
🎓 SPED Module

Stop missing IDEA deadlines before auditors do.

Every missed evaluation window or late IEP meeting is a potential corrective action. ComplyIQ automatically calculates deadlines from consent and eligibility dates and alerts your team before violations occur.

  • 60-day evaluation countdown from consent date
  • Annual IEP anniversary tracking per student
  • Triennial re-evaluation reminders (3-year cycle)
  • Corrective Action Plan (CAP) tracker
  • TEA Focused & Comprehensive Monitoring prep mode
  • Campus-level delegation for SPED coordinators
  • Discipline tracking — 10-day rule & MDR alerts
Get Early Access
IDEA Timeline Tracker
3 Overdue
J.M. — Grade 3
Initial Evaluation Due
⚠ 8 days overdue
A.R. — Grade 7
Annual IEP Review
⚠ 3 days overdue
T.W. — Grade 5
Transition Plan (Age 14)
△ Due in 12 days
S.K. — Grade 10
Triennial Reevaluation
△ Due in 28 days
M.L. — Grade 1
IEP Meeting Scheduled
✓ On track
D.H. — Grade 9
Annual IEP Review
✓ On track
🏥 Healthcare & SMB

Not just for schools.

Any organization that handles patient data or takes credit cards needs compliance tooling. ComplyIQ brings enterprise-grade auditing to businesses that can't afford a compliance consultant.

HIPAA Coverage
Medical & Dental Clinics • Therapists • School Health
38 controls covering the Privacy Rule, Security Rule, and Breach Notification Rule. Includes BAA inventory, risk analysis tracking, workforce training, and PHI encryption requirements.
💳
PCI-DSS 4.0 Readiness
Retail • Restaurants • Auto Dealers • Nonprofits
44 controls mapped to all 12 PCI-DSS 4.0 requirements. Covers network segmentation, cardholder data protection, MFA enforcement, ASV scan tracking, and incident response.
🧩
Cross-Framework Deduplication
Any Organization Running Multiple Frameworks
Controls that overlap between frameworks — MFA, encryption, audit logging, incident response — are answered once and credited everywhere. A HIPAA + PCI assessment takes a fraction of the time.

Simple pricing for every size.

IDEA Part B funds and Title I allocations can often cover compliance tooling costs. All plans include a 3-day free trial.

⭐ 2 months free annually
School
Single campus with SPED tracking and 5 frameworks.
$149
per month — or $1,490/yr
  • 5 compliance frameworks
  • 5 assessments per year
  • SPED / IDEA tracking
  • Evidence upload & PDF reports
  • Email support
  • HIPAA & PCI-DSS
Start 3-Day Trial
⭐ 2 months free annually
MSP
All 29 frameworks, multi-org management, and API access.
$599
per month — or $5,990/yr
  • All 29 compliance frameworks
  • Unlimited assessments & sites
  • Multi-organization dashboard
  • API access
  • Dedicated support
  • Client report delivery
Start 3-Day Trial
Enterprise
Custom pricing for large districts, state agencies, or organizations needing white-labeling, SSO, or dedicated infrastructure. All 29 frameworks included.
Contact Us →

All plans include a 3-day free trial · No credit card charged until trial ends · Cancel anytime

Ready to simplify compliance?

Join organizations across K-12, healthcare, and government who use ComplyIQ to stay audit-ready. Start your 3-day free trial today — no credit card required.

No credit card required. Unsubscribe anytime.