Skip to main content

Create Your First Compliance Project

Walk through creating a new compliance project in Nexxis, selecting a framework, and completing the initial setup.

4 min readUpdated 2026-02-01
getting-startedprojectsetuponboarding

Overview

A project in Nexxis represents one compliance scope — typically one framework for one product or business unit. You can have multiple projects (e.g., SOC 2 for your SaaS product + ISO 27001 for your managed services).


Step 1: Create a New Project

  1. From the home page, click + New Project
  2. Enter a Project Name (e.g., "Acme Platform — SOC 2 Type II")
  3. Select your Framework
  4. Set the Audit Period start date

Step 2: Configure Your Environment

Answer a few questions about your environment to help Nexxis pre-populate relevant controls:

  • What cloud providers do you use? (AWS / GCP / Azure / On-premise)
  • What is your primary tech stack? (e.g., Node.js, PostgreSQL)
  • How many employees does your organisation have?
  • Do you process personal data?
This takes ~5 minutes and unlocks a tailored control set.

Step 3: Connect Integrations

Connect at least one data source to start collecting automated evidence:

  • Cloud provider (AWS, GCP, Azure) — see Connect Your Cloud Provider
  • Identity provider (Okta, Azure AD, Google Workspace)
  • Source code (GitHub, GitLab) — for change management evidence
  • Ticketing (Jira, Linear) — for vulnerability remediation tracking

Step 4: Run the Initial Assessment

  1. Click Run Initial Assessment — this takes 3–10 minutes
  2. Nexxis evaluates all controls and gives you a baseline score
  3. Review the findings sorted by severity

Step 5: Create Your Roadmap

  1. Filter findings by Critical and High severity
  2. Assign each finding to a team member
  3. Set due dates
  4. Schedule a Monthly Compliance Audit to track progress

What Comes Next?