Zavior
For Schools

Should you run compliance in spreadsheets or GRC software?

Spreadsheets handle compliance up to your first audit on one framework, then break at multi-framework scale. The trigger to move to GRC software is stale evidence, not file size.

By Donny McGregor · Country Manager, Zavior Australia

6 min readInsight
Should you run compliance in spreadsheets or GRC software?

Spreadsheets are fine up to your first audit on a single framework. They break at multi-framework scale. Storage is not the problem; stale evidence is. Every control needs re-verified proof each quarter, and a spreadsheet cannot tell you what has expired. That refresh burden, not file size, is the switching trigger.

When do spreadsheets actually work?

Spreadsheets work when three things are true at once: one framework, fewer than 50 controls, and one person who owns the register. Inside those limits a well-kept workbook is the right tool. It costs nothing, and auditors accept it without comment. They care whether your controls operate, not what software records them.

The Essential Eight is the classic Australian starting case. Eight mitigation strategies and a target maturity level, usually with a single IT lead doing the implementing. A tab per strategy, a row per requirement, a status column, a link to the evidence. Nothing about that needs a platform.

The same holds for a first ISO 27001 gap analysis, or a one-off client security questionnaire. If the register changes monthly rather than daily, and nobody else edits it, the spreadsheet's weaknesses never get the chance to show. Buying software at this stage buys you admin, not assurance.

Where do they break?

Spreadsheets break when evidence has to stay fresh across more than one framework, which is where most growing Australian companies end up. Compliance is a set of claims that each need current proof, not a list of answers you fill in once. A spreadsheet records that the proof existed at some point. It has no way of telling you the proof has since expired.

Do the arithmetic on a single framework. ISO/IEC 27001:2022 Annex A contains 93 controls. If your auditor expects evidence refreshed quarterly (access reviews, patching reports, backup test results, firewall rule checks), that is roughly 370 artefacts a year to collect and file. Excel holds just over a million rows, and no compliance register in history has come close. Volume was never the issue. What the workbook lacks is any concept of freshness. The access-review screenshot from February sits in its cell looking exactly as valid in November, and nothing flags the difference.

Then the second framework arrives.

You keep the Essential Eight because your government clients ask about it, and you take on ISO 27001 because an enterprise deal demands certification, or SOC 2 because a US customer does. A large share of the controls overlap. Multi-factor authentication and patching sit on both lists, so every overlap becomes double data entry, and the two registers drift out of agreement within a quarter. The failure mode is never a full file. It is two files that disagree, in front of an auditor.

What does switching cost versus staying?

Switching costs a few weeks once. Staying costs a slice of every audit, forever. The honest comparison is hours per audit cycle, so here is the typical shape. Treat the numbers as illustrative ranges rather than quotes; scope and auditor move them, but the pattern holds.

Staying in spreadsheets, a surveillance audit on one framework commonly burns 40 to 60 hours chasing and re-collecting evidence, plus another 10 to 15 reconciling versions and re-checking which control answers which clause. Then there is the fortnight before the audit when normal delivery work quietly stops. Run two frameworks from separate workbooks and the chase roughly doubles, because the registers share nothing.

Switching typically costs a one-off 20 to 40 hours of migration, plus the subscription. Audit preparation then tends to fall to 10 to 20 hours, for two reasons: expired evidence surfaces continuously instead of in a pre-audit scramble, and one artefact satisfies every framework it maps to. On those ranges the switch pays for itself around your second audit or your second framework, whichever arrives first. For most companies that is the same year the first enterprise contract lands.

What are the warning signs it's time?

Four symptoms reliably mark the point where the spreadsheet costs more than software would: version conflicts, missed renewals, double-keyed controls and audit panic weeks. If two of them describe your last quarter, the trigger has already fired. The table is the checklist.

SymptomWhat it costs youThe fix
Version conflicts. Two "final" copies of the register circulate by email.Hours of reconciliation, and answers you cannot fully trust in front of an auditor.A single register with one source of truth and an edit history.
Missed renewals. An insurance renewal or a scheduled policy review passes silently.Audit nonconformities, and gaps the client finds before you do.An expiry date on every artefact, with reminders that fire before the deadline.
Double-keying. The same control is updated separately for the Essential Eight and ISO 27001.Duplicated collection effort, and registers that drift apart within a quarter.Each control recorded once and mapped to every framework it serves.
Audit panic weeks. Evidence gets assembled in a two-week scramble before each visit.Roughly a fortnight of delivery capacity lost per audit, plus whatever the scramble misses.Continuous evidence collection, so the audit reads from a live register.

None of these symptoms is about running out of rows. Every one of them is about time. The register stops reflecting reality unless someone spends hours making it true, and that is the moment the workbook stops being free. For the overlap side in practice, see our guide to mapping controls across frameworks.

Keeping that register live is the job Zavior does for Australian teams, with each control mapped once across the Essential Eight and ISO 27001 and an expiry date stamped on every artefact.

Frequently asked questions

Can I pass ISO 27001 with spreadsheets?

Yes. Certification bodies assess whether your information security management system operates as documented, and small single-framework organisations certify from workbooks every year. The practical limit is upkeep: past roughly 50 controls or a second framework, the quarterly evidence refresh makes each surveillance audit slower and more painful, even though the certificate stays within reach.

What does a GRC migration involve?

Less than most teams fear. You export the existing register, import controls into the platform, map them to your frameworks, attach current evidence with expiry dates, and assign an owner to each control. For a small organisation that is typically a few weeks of part-time effort rather than a re-implementation, because your policies and controls carry over unchanged and only the bookkeeping moves.

What about free templates?

Templates solve the blank-page problem, and a good one is a legitimate way to start an Essential Eight assessment or an ISO 27001 gap analysis. They do not solve the refresh problem, because a template is still a spreadsheet with no idea which of its linked evidence has expired. Start with one, and expect to outgrow it at the point you would outgrow any workbook.

Zavior · Cyber Security

Schools feel this wall first. A school holding student data, no security team, tracking the Essential Eight in a workbook nobody refreshes, is one surveillance audit from the mess above. Zavior runs the security assessment and the staff phishing training, leaves an incident response plan the school can use on a bad day, and hands leadership a plain-language hygiene report each cycle instead of a spreadsheet no one trusts.

Book a free 30-minute school assessment →

Sources: ISO/IEC 27001:2022 (Annex A); ACSC Essential Eight Maturity Model; certification auditor guidance.

Written by

Donny McGregor

Country Manager, Zavior Australia

Share

Let us be your Zavior.

Zavior helps Australian businesses build cyber resilience aligned to the ACSC Essential Eight, the Privacy Act, and ISO 27001.

Continue reading