Resources

Compliance checklists & security guides

Practical, source-cited checklists for every framework SBCMSP maps — plus deep-dive guides on managing your clients’ attack surface.

Compliance checklists & security guides

Every checklist below maps a framework to the exact controls an auditor examines, then flags which ones SBCMSP can monitor continuously versus the ones that need a documented process and human evidence. Each cites its official source — HHS, AICPA, NIST, the PCI SSC, ISO, CIS, the FTC, and the UK NCSC — so you can trace every line item back to the standard.

How to use these checklists

Start with the framework your clients are actually assessed against, then work down its control list. For each control, ask two questions: is it designed (does a control exist), and is it operating (is there evidence it worked throughout the period)? Auditors care about the second far more than the first, which is why every checklist here is organized around the evidence you need to collect.

Roughly two-thirds of the technical controls across these frameworks can be evidenced automatically — access control, configuration, logging, encryption, and vulnerability management. SBCMSP watches those continuously and timestamps the evidence, so audits shift from a month-long scramble to reviewing a report you already have. The remaining governance, training, and policy controls still need a documented process, and each checklist flags exactly which is which.

Run your first scan free

See a client’s real posture in minutes — then unlock all 1,692 checks.