Would You Pass a Compliance Audit Today? The Complete Readiness Checklist
Most companies don't fail audits because of sophisticated attacks. They fail because nobody stopped long enough to answer basic questions: Where does our sensitive data live? Who has access? What would an assessor ask first?
This checklist is those questions — the same ones we walk through with every new client at BlueSteel Cybersecurity. Check what you have. What's left unchecked is your roadmap.
How to use it: Start with the Universal Core — it applies no matter which framework you're pursuing (CMMC, SOC 2, HIPAA Security, or ISO 27001). Then jump to your framework section and score yourself at the end.
The Universal Core (every framework starts here)
If you can't check at least 7 of these, fix this list before spending money on any audit.
- A named security owner (even fractional/vCISO) with executive backing and budget authority
- Complete asset inventory: every system, device, and cloud service that touches sensitive data
- A data map: where sensitive data lives, how it flows, and who actually has access today
- MFA enforced everywhere, least-privilege access, and documented onboarding/offboarding
- Core written policies (infosec, acceptable use, incident response, vendor management) reviewed in the last 12 months
- A risk assessment completed in the last 12 months — with a remediation plan that has owners and dates
- Security awareness training for all staff, at least annually, with completion records
- Centralized logging and monitoring on critical systems — would you know if something happened tonight?
- Tested backups and a documented disaster recovery procedure — tested, not just written
- An incident response plan that has been tabletop-exercised in the last 12 months
CMMC — Defense Contractors
DoD contracts are already requiring this. Miss the deadline, lose the revenue.
- You know which CMMC level your contracts require (Level 1 self-assessment vs. Level 2 certification)
- You've identified where CUI and FCI actually live — and scoped (shrunk) the assessment boundary
- NIST 800-171 self-assessment completed and your SPRS score submitted and current
- System Security Plan (SSP) written, current, and reflective of reality — not aspiration
- POA&M in place for every gap, with named owners and realistic dates
- FIPS-validated encryption protecting CUI at rest and in transit
- Flow-down requirements addressed with every subcontractor touching CUI
- C3PAO assessment timeline mapped against contract award deadlines — assessor calendars fill up fast
SOC 2 — SaaS & Services Companies
Usually triggered by a deal in your pipeline. The audit window means the clock is real.
- Trust Services Criteria selected: Security is mandatory — you've deliberately chosen (or excluded) the rest
- Report type decided: Type I vs. Type II — and your sales team knows the timeline
- Every control mapped to a criterion and documented — no orphan controls, no unmapped criteria
- Evidence collection systematized (compliance platform or disciplined process) — not a quarterly panic
- Subservice organizations reviewed: you've read your critical vendors' SOC 2 reports
- Change management and SDLC controls documented and actually followed by engineering
- A readiness/gap assessment done through an auditor's lens before the real audit
- Auditor selected, engagement letter signed, window aligned to your sales commitments
HIPAA Security Rule — Healthcare & Their Vendors
Applies to covered entities AND business associates. "We're just the software vendor" is not an exemption.
- A designated HIPAA Security Officer — named in writing, not implied
- Security Risk Analysis completed and documented (its absence is OCR's most-cited finding)
- Full ePHI inventory: every system, device, and application — including AI tools
- Business Associate Agreements signed with every vendor that touches ePHI
- ePHI encrypted at rest and in transit — or documented, defensible reasons why not
- Workforce HIPAA training completed and documented — proof matters as much as training
- Contingency plan in place: data backup, disaster recovery, emergency mode operations
- Breach notification procedures documented — the clock starts at discovery
ISO 27001 — Selling Globally or to Enterprises
The international gold standard. Heavier lift, but one certification answers many questionnaires.
- ISMS scope defined and documented — which parts of the business are in, which are out, and why
- Risk assessment methodology defined, applied, and producing a risk treatment plan
- Statement of Applicability drafted against all Annex A controls, with justified exclusions
- Leadership commitment documented: information security policy, roles, and resourcing
- Internal audit program established — with auditor independence from what's being audited
- Management review cadence established with documented outputs and actions
- Metrics defined for control effectiveness — show the ISMS is working, not just existing
- Certification body selected; Stage 1 and Stage 2 audits scheduled
Score Yourself
Audit-Ready (80%+ checked): You're closer than most. Remaining gaps are findings waiting to happen — close them while momentum is high, then schedule the audit.
Foundation Built (50–79%): Real progress, real exposure. This is where most companies stall for a year. Prioritize unchecked items by deal impact — a readiness sprint beats a slow drift.
At Risk (under 50%): An audit today would hurt. Don't buy an audit yet — start with the Universal Core. It's a Tuesday afternoon, not a six-figure engagement.
Three Mistakes That Make Compliance Expensive
Buying the audit before the readiness. A failed or stalled audit costs more than preparation ever would.
Scoping too big. Whether it's CUI boundaries or ISMS scope, everything you include is something you must defend.
Treating it as a project instead of a program. Compliance you rebuild from scratch every year costs three times more than compliance you maintain.
Get the checklist as a PDF
Download the full Compliance Readiness Checklist (PDF) — or get your readiness score in 3 minutes with the free Compliance Readiness Scorecard: Take the free scorecard
Ali Allage is CEO of BlueSteel Cybersecurity and a CMMC Registered Practitioner. BlueSteel helps healthcare, financial services, defense, and education SMBs achieve SOC 2, HIPAA, HITRUST, CMMC, and ISO 27001 compliance.
This checklist is general guidance, not legal advice. Framework requirements vary by contract, data, and regulator.
