How to use these checklists
Start with the framework your clients are actually assessed against, then work down its control list. For each control, ask two questions: is it designed (does a control exist), and is it operating (is there evidence it worked throughout the period)? Auditors care about the second far more than the first, which is why every checklist here is organized around the evidence you need to collect.
Roughly two-thirds of the technical controls across these frameworks can be evidenced automatically — access control, configuration, logging, encryption, and vulnerability management. SBCMSP watches those continuously and timestamps the evidence, so audits shift from a month-long scramble to reviewing a report you already have. The remaining governance, training, and policy controls still need a documented process, and each checklist flags exactly which is which.