simpl.

Free compliance, quality & safety checklists

Built to the standards your team actually works under — download any of them free, or build your own in the checklist builder.

Cybersecurity GRC 17

Ransomware Readiness Assessment

Assesses organizational readiness to prevent, detect, and recover from ransomware using the CISA #StopRansomware guide and NIST controls, covering prevention, detection, and recovery.

CISA #StopRansomwareNIST 800-53CIS v8
Cybersecurity GRC 22

SOC 2 Trust Services Criteria Readiness Assessment

Evaluates readiness for a SOC 2 Type II examination across the AICPA Common Criteria and the Availability and Confidentiality categories.

SOC 2AICPA TSC
Cybersecurity GRC 20

PCI DSS 4.0 Compliance Assessment

Assesses cardholder data environment controls against the twelve PCI DSS v4.0 requirements for protecting account data.

PCI DSS 4.0
Cybersecurity GRC 21

ISO/IEC 27001:2022 Annex A Controls Audit

Internal audit of the ISO/IEC 27001:2022 Annex A controls across the four themes: organizational, people, physical, and technological.

ISO 27001:2022ISO 27002:2022
Cybersecurity GRC 17

Cybersecurity Incident Response Readiness Checklist

Assesses incident response capability across preparation, detection, containment, eradication, recovery, and post-incident activity.

NIST 800-61r2ISO 27001:2022SOC 2
Cybersecurity GRC 13

Infrastructure-as-Code (Terraform) Security Review

Reviews the security of infrastructure-as-code, focusing on Terraform, covering static analysis, policy-as-code, state protection, module trust, and drift.

CISNIST 800-53OWASP IaC
Cybersecurity GRC 13

Insider Threat Program Assessment

Assesses an insider threat program covering governance, risk indicators, monitoring and analytics, response, and privacy safeguards.

NIST 800-53CERT Insider ThreatCISA
Cybersecurity GRC 14

Breach & Attack Simulation / Purple-Team Exercise

Evaluates a breach-and-attack-simulation and purple-team program covering scoping, adversary emulation, detection validation, collaboration, and remediation.

MITRE ATT&CKNIST 800-53CIS
Cybersecurity GRC 13

Threat Modeling (STRIDE) Review

Reviews the threat modeling practice for a system or feature using STRIDE, covering scoping, decomposition, threat identification, mitigation, and integration into the SDLC.

OWASPNIST 800-154Microsoft SDL
Cybersecurity GRC 14

HSM & Key Ceremony Review

Reviews hardware security module operations and key ceremony procedures covering HSM security, ceremony controls, key lifecycle, and audit evidence.

NIST 800-57FIPS 140-3PCI PIN
Cybersecurity GRC 12

Passwordless / FIDO2 Rollout Review

Reviews a passwordless authentication rollout using FIDO2/passkeys, covering strategy, enrollment, phishing resistance, recovery, and legacy path closure.

FIDO2NIST 800-63BNIST 800-53
Cybersecurity GRC 14

WAF & Bot Management Review

Reviews web application firewall and bot management deployment covering coverage, rule tuning, bot mitigation, monitoring, and evasion resistance.

OWASPPCI DSSNIST 800-53
Cybersecurity GRC 13

DDoS Resilience Assessment

Assesses DDoS resilience covering risk assessment, network and application protections, mitigation services, response readiness, and testing.

NIST 800-53CISAISO 27001
Cybersecurity GRC 14

External Attack Surface Management (EASM) Review

Reviews an external attack surface management program covering continuous discovery, exposure identification, prioritization, and remediation of internet-facing assets.

NIST 800-53CISCISA
Cybersecurity GRC 12

Post-Quantum Cryptography Readiness Assessment

Assesses readiness for the migration to post-quantum cryptography covering cryptographic inventory, risk prioritization, crypto agility, and migration planning.

NIST PQCNIST 800-53CISA
Cybersecurity GRC 12

GRC Tool & Control Automation Review

Reviews a GRC platform and control automation program covering control mapping, automated evidence collection, continuous monitoring, and audit readiness.

NIST 800-53ISO 27001SOC 2
Cybersecurity GRC 15

Active Directory / Entra ID Hardening

Evaluates hardening of on-premises Active Directory and Entra ID, covering the tiered admin model, privileged access, attack-path reduction, and hybrid identity security.

CISNIST 800-53MITRE ATT&CK
Cybersecurity GRC 13

Network Access Control (NAC) Deployment Review

Reviews a network access control deployment covering authentication, device posture, guest and IoT handling, dynamic segmentation, and enforcement.

IEEE 802.1XNIST 800-53CIS
Cybersecurity GRC 13

Cloud Access Security Broker (CASB) Deployment Review

Assesses a CASB deployment covering SaaS discovery, access governance, data protection, threat detection, and deployment mode coverage.

CSA CCMNIST 800-53CIS
Cybersecurity GRC 13

ZTNA / SASE Deployment Assessment

Assesses a Zero Trust Network Access and SASE deployment covering identity-based access, policy enforcement, converged security services, and legacy VPN replacement.

NIST 800-207NIST 800-53CSA
Cybersecurity GRC 14

CI/CD Pipeline Security Review

Reviews the security of a CI/CD pipeline covering source integrity, build environment hardening, artifact signing, secrets, and deployment controls per software supply chain guidance.

SLSAOWASPNIST 800-53
Cybersecurity GRC 15

Cloud Security Posture Management (CSPM) Review

Reviews a CSPM program covering cloud asset discovery, misconfiguration detection, policy-as-code guardrails, drift, and remediation across multi-cloud environments.

CISNIST 800-53CSA CCM
Cybersecurity GRC 15

Microsoft 365 Security Baseline Review

Assesses a Microsoft 365 tenant against security baseline recommendations covering identity, email, collaboration, data protection, and auditing.

CIS Microsoft 365 BenchmarkNIST 800-53Microsoft SLA
Cybersecurity GRC 14

PKI & Certificate Lifecycle Management

Assesses public key infrastructure and certificate lifecycle governance covering CA security, issuance, inventory, renewal automation, and revocation.

NIST 800-57CA/Browser ForumNIST 800-53
Cybersecurity GRC 17

HITRUST CSF Readiness Assessment

Assesses readiness for a HITRUST CSF validated assessment, covering scoping, the PRISMA maturity model, control implementation, and corrective action planning.

HITRUST CSFHIPAANIST 800-53
Cybersecurity GRC 18

Cyber Insurance Readiness Assessment

Prepares an organization for cyber insurance underwriting and renewal by validating the technical controls carriers commonly require and ensuring application accuracy and documentation.

NIST CSFCIS v8NIST 800-53
Cybersecurity GRC 16

Email Security Authentication (DMARC/SPF/DKIM) Audit

Audits email authentication and anti-spoofing controls including SPF, DKIM, and DMARC, plus inbound filtering and encryption in transit, aligned to NIST SP 800-177.

RFC 7489RFC 7208RFC 6376
Cybersecurity GRC 16

OT/ICS Security Assessment (IEC 62443)

Assesses operational technology and industrial control system security using IEC 62443 and NIST SP 800-82, covering zones and conduits, remote access, patching, and safety.

IEC 62443NIST 800-82NIST 800-53
Cybersecurity GRC 16

Database Security Hardening Review

Reviews security hardening of relational and NoSQL database platforms, covering access control, encryption, auditing, configuration, and patching against CIS Benchmarks.

CIS BenchmarksNIST 800-53PCI DSS
Cybersecurity GRC 16

Multi-Factor Authentication (MFA) Rollout Readiness

Guides planning and execution of an enterprise MFA rollout, covering scoping, authenticator selection, deployment, and support to maximize coverage and phishing resistance.

NIST 800-63BCIS v8NIST 800-53
Cybersecurity GRC 15

Security Metrics & KPI Program Review

Reviews a security metrics and KPI program for measurement definition, data quality, operational and risk metrics, and reporting to leadership aligned to NIST SP 800-55 and ISO 27004.

NIST 800-55ISO 27004NIST 800-53
Cybersecurity GRC 15

Media Sanitization & Secure Data Disposal (NIST 800-88)

Assesses secure media sanitization and data disposal practices using NIST SP 800-88, covering categorization, sanitization methods, verification, and certificate of destruction.

NIST 800-88NIST 800-53ISO 27001
Cybersecurity GRC 17

SIEM Detection Engineering Review

Reviews the detection engineering lifecycle for a SIEM or analytics platform, covering log coverage, rule development, ATT&CK mapping, tuning, and detection-as-code practices.

MITRE ATT&CKNIST 800-53CIS v8
Cybersecurity GRC 16

Cyber Threat Intelligence Program Assessment

Assesses the maturity of a cyber threat intelligence program across the intelligence lifecycle, from requirements and collection through analysis, dissemination, and operational integration.

NIST 800-53MITRE ATT&CKISO 27001
Cybersecurity GRC 14

Security Operations Center (SOC) Operations Runbook Audit

Audits the operational runbooks and processes of a security operations center, including alert triage, escalation, shift management, and continuous improvement.

NIST 800-61NIST 800-53ISO 27001
Cybersecurity GRC 12

Threat Hunting Program Readiness

Evaluates the readiness of a proactive threat hunting program, covering hypothesis development, data access, hunt execution, and the operationalization of findings into detections.

MITRE ATT&CKNIST 800-53
Cybersecurity GRC 14

DNS Security Controls Review

Reviews DNS security controls across resolver protection, DNSSEC, protective filtering, logging, and registrar/zone integrity to defend against tunneling, hijacking, and abuse.

NIST 800-81NIST 800-53CIS v8
Cybersecurity GRC 14

Patch Management Program Audit

Audits the patch management lifecycle including coverage, prioritization, deployment cadence, and exception handling across enterprise assets.

CIS v8NIST 800-40NIST 800-53
Cybersecurity GRC 17

Zero Trust Architecture Assessment (NIST 800-207)

Assesses maturity against the zero trust tenets and pillars defined in NIST SP 800-207 and the CISA Zero Trust Maturity Model.

NIST 800-207CISA ZTMMNIST 800-53
Cybersecurity GRC 18

Identity & Privileged Access Management (IAM/PAM) Audit

Audits the identity lifecycle, authentication controls, and privileged access management for administrative and service accounts across on-premises and cloud systems.

CIS v8NIST 800-53ISO 27001
Cybersecurity GRC 15

Endpoint Detection & Response (EDR) Program Review

Reviews endpoint protection coverage, detection efficacy, and response capabilities of the EDR/XDR deployment across managed devices.

CIS v8NIST 800-53MITRE ATT&CK
Cybersecurity GRC 15

Phishing & Social Engineering Resilience Assessment

Evaluates technical email defenses and human resilience against phishing, business email compromise, and social engineering attacks.

CIS v8NIST 800-53NIST 800-50
Cybersecurity GRC 14

Mobile Device Management & BYOD Security Audit

Audits enrollment, configuration, and data protection controls for corporate and personally owned mobile devices under an MDM/UEM program.

CIS v8NIST 800-124ISO 27001
Cybersecurity GRC 14

Data Loss Prevention (DLP) Program Audit

Audits the coverage, policy tuning, and incident handling of the data loss prevention program across endpoints, email, network, and cloud channels.

CIS v8NIST 800-53ISO 27001
Cybersecurity GRC 15

Backup & Recovery Testing Audit

Audits backup coverage, immutability, and restore testing to validate recoverability from data loss and ransomware events.

CIS v8NIST 800-53ISO 27001
Cybersecurity GRC 15

Disaster Recovery Tabletop Exercise Checklist

Structures the planning, execution, and after-action review of a disaster recovery tabletop exercise validating the DR plan against a realistic scenario.

NIST 800-84NIST 800-34ISO 22301
Cybersecurity GRC 15

Firewall & Network Device Configuration Review

Reviews firewall and network device rulesets, hardening, and change management to ensure secure and least-privilege network configurations.

CIS v8NIST 800-41PCI DSS 4.0
Cybersecurity GRC 16

CIS Controls v8 Implementation Group 1 (IG1) Checklist

Assesses implementation of the CIS Controls v8 Implementation Group 1 safeguards that define essential cyber hygiene for all organizations.

CIS v8CIS IG1
Cybersecurity GRC 14

IT Asset Inventory & Management Audit

Audits the accuracy and completeness of hardware and software asset inventories and the processes that keep them current.

CIS v8NIST 800-53ISO 27001
Cybersecurity GRC 15

Web Application Security Assessment (OWASP Top 10)

Assesses a web application against the OWASP Top 10 (2021) risk categories and core application security controls.

OWASP Top 10OWASP ASVSCIS v8
Cybersecurity GRC 13

API Security Assessment (OWASP API Top 10)

Assesses REST and GraphQL API security against the OWASP API Security Top 10 (2023), focusing on authorization, authentication, and resource controls.

OWASP API Security Top 10NIST 800-53
Cybersecurity GRC 15

Kubernetes & Container Security Hardening

Assesses hardening of container images, workloads, and the Kubernetes control plane against NIST 800-190 and the NSA/CISA Kubernetes hardening guidance.

CIS Kubernetes BenchmarkNIST 800-190NSA/CISA K8s
Cybersecurity GRC 13

Secrets Management & Credential Hygiene Audit

Audits how application secrets, API keys, and credentials are stored, rotated, and prevented from leaking into code and pipelines.

CIS v8NIST 800-53OWASP
Cybersecurity GRC 12

Data Classification & Handling Compliance Checklist

Verifies that data is classified, labeled, and handled according to its sensitivity across its lifecycle.

ISO 27001:2022NIST 800-53SOC 2
Cybersecurity GRC 17

SOC 2 Logical & Physical Access Control Audit

Audits logical and physical access controls against the SOC 2 CC6 series covering provisioning, authentication, and de-provisioning.

SOC 2AICPA TSC
Cybersecurity GRC 15

HIPAA Security Rule Compliance Checklist

Evaluates administrative, physical, and technical safeguards required to protect electronic protected health information (ePHI) under the HIPAA Security Rule.

HIPAA Security Rule45 CFR Part 164
Cybersecurity GRC 18

NIST Cybersecurity Framework 2.0 Program Assessment

Assesses a cybersecurity program against the six NIST CSF 2.0 Functions: Govern, Identify, Protect, Detect, Respond, and Recover.

NIST CSF 2.0
Cybersecurity GRC 19

NIST 800-171 / CMMC 2.0 Level 2 Self-Assessment

Self-assessment of Controlled Unclassified Information (CUI) safeguards required for CMMC 2.0 Level 2, mapped to NIST SP 800-171 control families.

NIST 800-171 Rev 2CMMC 2.0
Cybersecurity GRC 12

PCI DSS 4.0 Network Segmentation Verification

Verifies that segmentation controls effectively isolate the cardholder data environment (CDE) to reduce PCI DSS scope.

PCI DSS 4.0
Cybersecurity GRC 16

GDPR Data Protection Compliance Checklist

Assesses compliance with core General Data Protection Regulation obligations covering lawful processing, data subject rights, and accountability.

GDPREU 2016/679
Cybersecurity GRC 12

Third-Party & Vendor Risk Management Assessment

Assesses the third-party risk management lifecycle from onboarding due diligence through ongoing monitoring and offboarding.

SOC 2ISO 27001:2022NIST CSF 2.0
Cybersecurity GRC 15

Business Continuity & Disaster Recovery Audit

Audits business continuity and disaster recovery capability including impact analysis, plans, recovery objectives, and testing.

ISO 22301ISO 27001:2022SOC 2
Cybersecurity GRC 12

Security Awareness & Training Program Review

Reviews the effectiveness of the security awareness and training program including phishing simulations and role-based training.

NIST 800-53ISO 27001:2022PCI DSS 4.0
Cybersecurity GRC 14

Logging, Monitoring & Detection Audit

Audits security logging, centralized monitoring, and detection capabilities to ensure events are captured, protected, and reviewed.

NIST 800-53ISO 27001:2022PCI DSS 4.0
Cybersecurity GRC 14

Encryption & Cryptographic Key Management Audit

Audits cryptographic controls and the key management lifecycle covering algorithms, key generation, storage, rotation, and destruction.

NIST 800-53ISO 27001:2022PCI DSS 4.0
Cybersecurity GRC 15

Cloud Security & CIS Benchmark Hardening Review

Reviews cloud environment hardening against CIS Benchmark recommendations for identity, logging, networking, storage, and encryption.

CIS BenchmarksCIS Controls v8NIST 800-53
Cybersecurity GRC 15

Vulnerability Management Program Audit

Audits the maturity of a vulnerability management program covering discovery, prioritization, remediation, and metrics.

NIST 800-53ISO 27001:2022PCI DSS 4.0
Cybersecurity GRC 16

Secure Software Development Lifecycle (SSDLC) Review

Reviews security integration across the software development lifecycle, from requirements and design through testing and deployment.

NIST SSDF 800-218OWASP ASVSISO 27001:2022
Cybersecurity GRC 2

SOC 2 Access Control Review

Review logical access controls against SOC 2 CC6.

SOC 2ISO 27001