Free compliance, quality & safety checklists
Built to the standards your team actually works under — download any of them free, or build your own in the checklist builder.
Ransomware Readiness Assessment
Assesses organizational readiness to prevent, detect, and recover from ransomware using the CISA #StopRansomware guide and NIST controls, covering prevention, detection, and recovery.
SOC 2 Trust Services Criteria Readiness Assessment
Evaluates readiness for a SOC 2 Type II examination across the AICPA Common Criteria and the Availability and Confidentiality categories.
PCI DSS 4.0 Compliance Assessment
Assesses cardholder data environment controls against the twelve PCI DSS v4.0 requirements for protecting account data.
ISO/IEC 27001:2022 Annex A Controls Audit
Internal audit of the ISO/IEC 27001:2022 Annex A controls across the four themes: organizational, people, physical, and technological.
Cybersecurity Incident Response Readiness Checklist
Assesses incident response capability across preparation, detection, containment, eradication, recovery, and post-incident activity.
Infrastructure-as-Code (Terraform) Security Review
Reviews the security of infrastructure-as-code, focusing on Terraform, covering static analysis, policy-as-code, state protection, module trust, and drift.
Insider Threat Program Assessment
Assesses an insider threat program covering governance, risk indicators, monitoring and analytics, response, and privacy safeguards.
Breach & Attack Simulation / Purple-Team Exercise
Evaluates a breach-and-attack-simulation and purple-team program covering scoping, adversary emulation, detection validation, collaboration, and remediation.
Threat Modeling (STRIDE) Review
Reviews the threat modeling practice for a system or feature using STRIDE, covering scoping, decomposition, threat identification, mitigation, and integration into the SDLC.
HSM & Key Ceremony Review
Reviews hardware security module operations and key ceremony procedures covering HSM security, ceremony controls, key lifecycle, and audit evidence.
Passwordless / FIDO2 Rollout Review
Reviews a passwordless authentication rollout using FIDO2/passkeys, covering strategy, enrollment, phishing resistance, recovery, and legacy path closure.
WAF & Bot Management Review
Reviews web application firewall and bot management deployment covering coverage, rule tuning, bot mitigation, monitoring, and evasion resistance.
DDoS Resilience Assessment
Assesses DDoS resilience covering risk assessment, network and application protections, mitigation services, response readiness, and testing.
External Attack Surface Management (EASM) Review
Reviews an external attack surface management program covering continuous discovery, exposure identification, prioritization, and remediation of internet-facing assets.
Post-Quantum Cryptography Readiness Assessment
Assesses readiness for the migration to post-quantum cryptography covering cryptographic inventory, risk prioritization, crypto agility, and migration planning.
GRC Tool & Control Automation Review
Reviews a GRC platform and control automation program covering control mapping, automated evidence collection, continuous monitoring, and audit readiness.
Active Directory / Entra ID Hardening
Evaluates hardening of on-premises Active Directory and Entra ID, covering the tiered admin model, privileged access, attack-path reduction, and hybrid identity security.
Network Access Control (NAC) Deployment Review
Reviews a network access control deployment covering authentication, device posture, guest and IoT handling, dynamic segmentation, and enforcement.
Cloud Access Security Broker (CASB) Deployment Review
Assesses a CASB deployment covering SaaS discovery, access governance, data protection, threat detection, and deployment mode coverage.
ZTNA / SASE Deployment Assessment
Assesses a Zero Trust Network Access and SASE deployment covering identity-based access, policy enforcement, converged security services, and legacy VPN replacement.
CI/CD Pipeline Security Review
Reviews the security of a CI/CD pipeline covering source integrity, build environment hardening, artifact signing, secrets, and deployment controls per software supply chain guidance.
Cloud Security Posture Management (CSPM) Review
Reviews a CSPM program covering cloud asset discovery, misconfiguration detection, policy-as-code guardrails, drift, and remediation across multi-cloud environments.
Microsoft 365 Security Baseline Review
Assesses a Microsoft 365 tenant against security baseline recommendations covering identity, email, collaboration, data protection, and auditing.
PKI & Certificate Lifecycle Management
Assesses public key infrastructure and certificate lifecycle governance covering CA security, issuance, inventory, renewal automation, and revocation.
HITRUST CSF Readiness Assessment
Assesses readiness for a HITRUST CSF validated assessment, covering scoping, the PRISMA maturity model, control implementation, and corrective action planning.
Cyber Insurance Readiness Assessment
Prepares an organization for cyber insurance underwriting and renewal by validating the technical controls carriers commonly require and ensuring application accuracy and documentation.
Email Security Authentication (DMARC/SPF/DKIM) Audit
Audits email authentication and anti-spoofing controls including SPF, DKIM, and DMARC, plus inbound filtering and encryption in transit, aligned to NIST SP 800-177.
OT/ICS Security Assessment (IEC 62443)
Assesses operational technology and industrial control system security using IEC 62443 and NIST SP 800-82, covering zones and conduits, remote access, patching, and safety.
Database Security Hardening Review
Reviews security hardening of relational and NoSQL database platforms, covering access control, encryption, auditing, configuration, and patching against CIS Benchmarks.
Multi-Factor Authentication (MFA) Rollout Readiness
Guides planning and execution of an enterprise MFA rollout, covering scoping, authenticator selection, deployment, and support to maximize coverage and phishing resistance.
Security Metrics & KPI Program Review
Reviews a security metrics and KPI program for measurement definition, data quality, operational and risk metrics, and reporting to leadership aligned to NIST SP 800-55 and ISO 27004.
Media Sanitization & Secure Data Disposal (NIST 800-88)
Assesses secure media sanitization and data disposal practices using NIST SP 800-88, covering categorization, sanitization methods, verification, and certificate of destruction.
SIEM Detection Engineering Review
Reviews the detection engineering lifecycle for a SIEM or analytics platform, covering log coverage, rule development, ATT&CK mapping, tuning, and detection-as-code practices.
Cyber Threat Intelligence Program Assessment
Assesses the maturity of a cyber threat intelligence program across the intelligence lifecycle, from requirements and collection through analysis, dissemination, and operational integration.
Security Operations Center (SOC) Operations Runbook Audit
Audits the operational runbooks and processes of a security operations center, including alert triage, escalation, shift management, and continuous improvement.
Threat Hunting Program Readiness
Evaluates the readiness of a proactive threat hunting program, covering hypothesis development, data access, hunt execution, and the operationalization of findings into detections.
DNS Security Controls Review
Reviews DNS security controls across resolver protection, DNSSEC, protective filtering, logging, and registrar/zone integrity to defend against tunneling, hijacking, and abuse.
Patch Management Program Audit
Audits the patch management lifecycle including coverage, prioritization, deployment cadence, and exception handling across enterprise assets.
Zero Trust Architecture Assessment (NIST 800-207)
Assesses maturity against the zero trust tenets and pillars defined in NIST SP 800-207 and the CISA Zero Trust Maturity Model.
Identity & Privileged Access Management (IAM/PAM) Audit
Audits the identity lifecycle, authentication controls, and privileged access management for administrative and service accounts across on-premises and cloud systems.
Endpoint Detection & Response (EDR) Program Review
Reviews endpoint protection coverage, detection efficacy, and response capabilities of the EDR/XDR deployment across managed devices.
Phishing & Social Engineering Resilience Assessment
Evaluates technical email defenses and human resilience against phishing, business email compromise, and social engineering attacks.
Mobile Device Management & BYOD Security Audit
Audits enrollment, configuration, and data protection controls for corporate and personally owned mobile devices under an MDM/UEM program.
Data Loss Prevention (DLP) Program Audit
Audits the coverage, policy tuning, and incident handling of the data loss prevention program across endpoints, email, network, and cloud channels.
Backup & Recovery Testing Audit
Audits backup coverage, immutability, and restore testing to validate recoverability from data loss and ransomware events.
Disaster Recovery Tabletop Exercise Checklist
Structures the planning, execution, and after-action review of a disaster recovery tabletop exercise validating the DR plan against a realistic scenario.
Firewall & Network Device Configuration Review
Reviews firewall and network device rulesets, hardening, and change management to ensure secure and least-privilege network configurations.
CIS Controls v8 Implementation Group 1 (IG1) Checklist
Assesses implementation of the CIS Controls v8 Implementation Group 1 safeguards that define essential cyber hygiene for all organizations.
IT Asset Inventory & Management Audit
Audits the accuracy and completeness of hardware and software asset inventories and the processes that keep them current.
Web Application Security Assessment (OWASP Top 10)
Assesses a web application against the OWASP Top 10 (2021) risk categories and core application security controls.
API Security Assessment (OWASP API Top 10)
Assesses REST and GraphQL API security against the OWASP API Security Top 10 (2023), focusing on authorization, authentication, and resource controls.
Kubernetes & Container Security Hardening
Assesses hardening of container images, workloads, and the Kubernetes control plane against NIST 800-190 and the NSA/CISA Kubernetes hardening guidance.
Secrets Management & Credential Hygiene Audit
Audits how application secrets, API keys, and credentials are stored, rotated, and prevented from leaking into code and pipelines.
Data Classification & Handling Compliance Checklist
Verifies that data is classified, labeled, and handled according to its sensitivity across its lifecycle.
SOC 2 Logical & Physical Access Control Audit
Audits logical and physical access controls against the SOC 2 CC6 series covering provisioning, authentication, and de-provisioning.
HIPAA Security Rule Compliance Checklist
Evaluates administrative, physical, and technical safeguards required to protect electronic protected health information (ePHI) under the HIPAA Security Rule.
NIST Cybersecurity Framework 2.0 Program Assessment
Assesses a cybersecurity program against the six NIST CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, and Recover.
NIST 800-171 / CMMC 2.0 Level 2 Self-Assessment
Self-assessment of Controlled Unclassified Information (CUI) safeguards required for CMMC 2.0 Level 2, mapped to NIST SP 800-171 control families.
PCI DSS 4.0 Network Segmentation Verification
Verifies that segmentation controls effectively isolate the cardholder data environment (CDE) to reduce PCI DSS scope.
GDPR Data Protection Compliance Checklist
Assesses compliance with core General Data Protection Regulation obligations covering lawful processing, data subject rights, and accountability.
Third-Party & Vendor Risk Management Assessment
Assesses the third-party risk management lifecycle from onboarding due diligence through ongoing monitoring and offboarding.
Business Continuity & Disaster Recovery Audit
Audits business continuity and disaster recovery capability including impact analysis, plans, recovery objectives, and testing.
Security Awareness & Training Program Review
Reviews the effectiveness of the security awareness and training program including phishing simulations and role-based training.
Logging, Monitoring & Detection Audit
Audits security logging, centralized monitoring, and detection capabilities to ensure events are captured, protected, and reviewed.
Encryption & Cryptographic Key Management Audit
Audits cryptographic controls and the key management lifecycle covering algorithms, key generation, storage, rotation, and destruction.
Cloud Security & CIS Benchmark Hardening Review
Reviews cloud environment hardening against CIS Benchmark recommendations for identity, logging, networking, storage, and encryption.
Vulnerability Management Program Audit
Audits the maturity of a vulnerability management program covering discovery, prioritization, remediation, and metrics.
Secure Software Development Lifecycle (SSDLC) Review
Reviews security integration across the software development lifecycle, from requirements and design through testing and deployment.
SOC 2 Access Control Review
Review logical access controls against SOC 2 CC6.
