Checkpoint vs running it in spreadsheets
Plenty of organisations get certified with Excel and SharePoint folders. It works, until evidence goes stale, a control owner leaves, or the auditor asks who approved what and when. Checkpoint keeps the same records in the same place, your Microsoft 365, and does the chasing.
| Spreadsheets | Checkpoint | |
|---|---|---|
| Where records live | Excel workbooks in SharePoint or OneDrive. | SharePoint lists in the same tenant, with every change in an audit log. |
| Technical evidence | Screenshots, refreshed by hand before each audit. | 49 checks read from Microsoft Graph with delegated, read-only permissions. Every scan is kept as dated evidence. |
| Keeping it current | Someone remembers to check. | Owner reminders, evidence expiry dates and a weekly digest. |
| Sign-off | An email or a signature on a PDF. | Recorded review and approval, with names and dates on the exported document. |
| Cost | No licence, but the hours add up. | Published: from $7,000 a year per framework (AUD, ex GST), SOC 2 from $8,999. Enterprise from $14,999. |
Spreadsheets are enough when
- You have one small scope, a person with time to keep it current, and no customer asking for evidence between audits.
Checkpoint suits you if
- More than one person owns controls, or you are adding a second framework.
- Customers send security questionnaires and you answer the same questions each time.
- You want to keep using Excel and Word for exports, without them being the system of record.
Questions
- Can we import our existing spreadsheets?
- Yes. Checkpoint imports risks, assets, suppliers and other registers from Excel or CSV, with a column mapping, a preview and a duplicate check.
- Can we still get Excel and Word out?
- Yes. Registers export to Excel, and the Statement of Applicability, risk register and asset register export to Word as controlled documents.