How to use the assessment
Choose one product family or business unit. Mark a control evidenced only when you can point to the relevant artifact, test or approved process. Record an owner and target date for gaps. A documented exception is different from an implemented control.
Use the CSV for a retained assessment. The checkboxes below are a temporary browsing aid and do not persist after a page reload. Print the page to retain a working copy. The completion count is a tally, not a risk score or statement of legal compliance.
Governance
Scope
Generation
Formats
Quality
Supplier
Lifecycle
Security
Risk
Operations
Procurement
Choose the next improvement
Group gaps into inventory quality, release mapping, ownership, integration and purchasing. Address dependencies in that order where practical: a risk dashboard cannot compensate for unknown installed versions. A failed export test should influence architecture and contract terms before launch.
For an early program, a good milestone is one internal product and one supplier product with validated inventories, named owners and a completed incident drill. For a mature program, examine historical releases, exceptions, stale intelligence and recovery.
Download and retain the evidence
Readiness assessment
36 controls with evidence, owner, status, target date and next-action fields.
Record the scope and assessment date when using the file. Keep evidence references accessible to the reviewers who will approve the resulting action plan. Reassess after major changes to products, suppliers, receiving systems or applicable obligations.
Primary sources
- CISA and partners · 2026 Minimum Elements (ACSC publication)Published government guidance
- NIST · SSDF 1.1, SP 800-218Final government guidance