Create Your First Compliance Project
Walk through creating a new compliance project in Nexxis, selecting a framework, and completing the initial setup.
4 min readUpdated 2026-02-01
getting-startedprojectsetuponboarding
Overview
A project in Nexxis represents one compliance scope — typically one framework for one product or business unit. You can have multiple projects (e.g., SOC 2 for your SaaS product + ISO 27001 for your managed services).
Step 1: Create a New Project
- From the home page, click + New Project
- Enter a Project Name (e.g., "Acme Platform — SOC 2 Type II")
- Select your Framework
- Set the Audit Period start date
Step 2: Configure Your Environment
Answer a few questions about your environment to help Nexxis pre-populate relevant controls:
- What cloud providers do you use? (AWS / GCP / Azure / On-premise)
- What is your primary tech stack? (e.g., Node.js, PostgreSQL)
- How many employees does your organisation have?
- Do you process personal data?
Step 3: Connect Integrations
Connect at least one data source to start collecting automated evidence:
- Cloud provider (AWS, GCP, Azure) — see Connect Your Cloud Provider
- Identity provider (Okta, Azure AD, Google Workspace)
- Source code (GitHub, GitLab) — for change management evidence
- Ticketing (Jira, Linear) — for vulnerability remediation tracking
Step 4: Run the Initial Assessment
- Click Run Initial Assessment — this takes 3–10 minutes
- Nexxis evaluates all controls and gives you a baseline score
- Review the findings sorted by severity
Step 5: Create Your Roadmap
- Filter findings by Critical and High severity
- Assign each finding to a team member
- Set due dates
- Schedule a Monthly Compliance Audit to track progress