Readiness checklist · 2026 edition
Forty-two control questions across ISO/IEC 27001, SOC 2, HIPAA, PCI DSS v4.0, DORA and the SAMA Cyber Security Framework — with the evidence an auditor asks for beside each one. Answer each question with the record you would hand over, not the intention you hold.
How to use it: work one framework at a time. Mark Y only where the evidence exists today, in a form someone outside your team could locate. Mark P where the control operates but the record is thin. Mark N where neither exists. Everything not marked Y is a finding waiting to happen.
Scoring guide — count your Y answers per section. 6 of 7 or better: you are in readiness territory; focus on evidence packaging. 4 to 5: a remediation roadmap is needed before you book an audit. 3 or fewer: start with scope and control design, not tooling.
Management system, risk process, Annex A controls
| # | CONTROL QUESTION | EVIDENCE AN AUDITOR ASKS FOR | Y/P/N |
|---|---|---|---|
| 1 | Is the ISMS scope written down, agreed and current? | Signed scope statement naming services, locations and exclusions | ☐ ☐ ☐ |
| 2 | Does a documented risk assessment method exist, and has it been applied? | Risk method document plus a populated risk register with owners | ☐ ☐ ☐ |
| 3 | Is the Statement of Applicability complete, with justification for exclusions? | Current SoA with control status and exclusion rationale | ☐ ☐ ☐ |
| 4 | Has an internal audit covering the ISMS been completed in the last 12 months? | Internal audit plan, report and corrective actions with closure dates | ☐ ☐ ☐ |
| 5 | Has management review taken place with recorded decisions? | Minutes showing inputs, decisions and resource commitments | ☐ ☐ ☐ |
| 6 | Are access rights reviewed periodically with revocation evidence (A.5.15–A.5.18)? | Completed review campaign records and dated revocation tickets | ☐ ☐ ☐ |
| 7 | Is supplier security assessed before onboarding and monitored afterwards? | Supplier register, assessment records, contract security clauses | ☐ ☐ ☐ |
Security trust services criteria, evidence period
| # | CONTROL QUESTION | EVIDENCE AN AUDITOR ASKS FOR | Y/P/N |
|---|---|---|---|
| 8 | Are control narratives written for each criterion in scope? | System description and control matrix mapped to CC criteria | ☐ ☐ ☐ |
| 9 | Is logical access provisioned and de-provisioned through an approved workflow? | Sample of joiner and leaver tickets with approvals and timestamps | ☐ ☐ ☐ |
| 10 | Is MFA enforced for remote and administrative access without exception? | Policy configuration export and exception register | ☐ ☐ ☐ |
| 11 | Are changes to production authorised, tested and traceable? | Change records linked to tickets, approvals and deployment logs | ☐ ☐ ☐ |
| 12 | Is security monitoring producing alerts that someone demonstrably actions? | Alert samples with triage notes and resolution times | ☐ ☐ ☐ |
| 13 | Has the incident response plan been exercised in the period? | Tabletop or live exercise record with lessons and actions | ☐ ☐ ☐ |
| 14 | Is the evidence period agreed with your auditor and already running? | Engagement letter with period dates and readiness assessment | ☐ ☐ ☐ |
ePHI safeguards, USA healthcare
| # | CONTROL QUESTION | EVIDENCE AN AUDITOR ASKS FOR | Y/P/N |
|---|---|---|---|
| 15 | Is there a current risk analysis covering every system that touches ePHI? | Dated risk analysis with asset inventory and risk management plan | ☐ ☐ ☐ |
| 16 | Is access to ePHI granted on a minimum-necessary basis by role? | Role definitions, entitlement report, approval records | ☐ ☐ ☐ |
| 17 | Is emergency (break-glass) access controlled, logged and reviewed? | Break-glass procedure, usage log, post-use review records | ☐ ☐ ☐ |
| 18 | Are audit logs of ePHI access retained and actually examined? | Log retention configuration plus review evidence with reviewer names | ☐ ☐ ☐ |
| 19 | Is ePHI encrypted at rest and in transit, with key custody documented? | Encryption standard, configuration evidence, key management procedure | ☐ ☐ ☐ |
| 20 | Are business associate agreements in place for every vendor touching ePHI? | BAA register mapped to the vendor inventory | ☐ ☐ ☐ |
| 21 | Do workforce members receive role-appropriate security training with records? | Completion reports by role, including clinical and contractor staff | ☐ ☐ ☐ |
Cardholder data environment, access and segmentation
| # | CONTROL QUESTION | EVIDENCE AN AUDITOR ASKS FOR | Y/P/N |
|---|---|---|---|
| 22 | Is the cardholder data environment defined, with data flows documented? | Current scope diagram and data flow diagrams with dates | ☐ ☐ ☐ |
| 23 | Is segmentation tested to confirm what is out of scope? | Segmentation penetration test report within the required frequency | ☐ ☐ ☐ |
| 24 | Is access to cardholder data restricted by role on a need-to-know basis? | Role-to-privilege matrix and approval records (Req. 7) | ☐ ☐ ☐ |
| 25 | Is every account uniquely identified, with shared accounts eliminated or justified? | Account inventory, shared-account exceptions with compensating controls | ☐ ☐ ☐ |
| 26 | Are system and application accounts inventoried, with credentials managed? | Service-account register, rotation evidence (Req. 8.6) | ☐ ☐ ☐ |
| 27 | Are logs of access to cardholder data reviewed and retained? | Log review records and retention configuration (Req. 10) | ☐ ☐ ☐ |
| 28 | Is a targeted risk analysis documented for each flexible requirement you rely on? | Targeted risk analyses with frequency justification and approval | ☐ ☐ ☐ |
EU financial entities, ICT risk and third parties
| # | CONTROL QUESTION | EVIDENCE AN AUDITOR ASKS FOR | Y/P/N |
|---|---|---|---|
| 29 | Is there a board-approved ICT risk management framework? | Framework document with board approval minutes | ☐ ☐ ☐ |
| 30 | Are critical or important functions identified and mapped to ICT assets? | Function-to-asset mapping and dependency register | ☐ ☐ ☐ |
| 31 | Is the register of information on ICT third-party arrangements complete? | Register extract in the required structure, with contract references | ☐ ☐ ☐ |
| 32 | Do critical third-party contracts contain the required access, audit and exit terms? | Contract clause matrix and exit plan per critical provider | ☐ ☐ ☐ |
| 33 | Are ICT incidents classified and reportable within the required timelines? | Classification procedure and reporting decision log | ☐ ☐ ☐ |
| 34 | Is a digital operational resilience testing programme in place and executed? | Test plan, results and remediation tracking | ☐ ☐ ☐ |
| 35 | Are privileged and remote access to critical systems controlled and recorded? | PAM configuration, session records, periodic review evidence | ☐ ☐ ☐ |
KSA financial institutions, maturity-based
| # | CONTROL QUESTION | EVIDENCE AN AUDITOR ASKS FOR | Y/P/N |
|---|---|---|---|
| 36 | Is cyber security governance defined with board-level oversight? | Governance charter, committee minutes, reporting pack | ☐ ☐ ☐ |
| 37 | Has a maturity assessment been performed against each framework domain? | Domain-level maturity scores with supporting evidence | ☐ ☐ ☐ |
| 38 | Is identity and access management operating to the required maturity level? | IAM procedures, review records, privileged access controls | ☐ ☐ ☐ |
| 39 | Are cloud services governed, approved and assessed before use? | Cloud policy, approval records, provider assessments | ☐ ☐ ☐ |
| 40 | Is third-party cyber risk assessed and monitored through the contract lifecycle? | Third-party register, assessment reports, monitoring records | ☐ ☐ ☐ |
| 41 | Are data classification and protection requirements applied to regulated data? | Classification standard, labelling evidence, control mapping | ☐ ☐ ☐ |
| 42 | Is there evidence of periodic independent review of the cyber programme? | Independent review or audit report with management response | ☐ ☐ ☐ |
Group your N and P answers by control rather than by framework. Access governance, logging and third-party oversight will account for most of them, and each fix serves several frameworks at once. Sequence by audit exposure: what your next auditor will sample first, not what is easiest to close.
ACE IT Solutions runs this as a scoped engagement: gap assessment, remediation roadmap, control implementation with evidence, then audit support. Talk to a practice lead at info@aceitsolutions.ai or +1 (650) 606-5553.
© 2026 ACE IT Solutions. ACE IT Solutions — an Autharva company. This checklist is general information, not legal or audit advice. Applicability of each framework depends on your licences, regions and data flows. ACE IT Solutions provides advisory and implementation services; certification is granted solely by accredited certification bodies.