Compliance & Audit / Audit Readiness Checklist

What this is for: Multi-section audit checklist covering inventory, policy, controls, and documentation.

What a good answer looks like: You could hand this to an auditor tomorrow. If an item needs a conversation to explain, write the explanation into the item.

Worked example: Tick 'CBOM generated' and 'All systems cataloged', then add an evidence row with a CMVP certificate number: the Cryptographic Inventory readiness moves from Not Started toward Established, and an auditor can follow the row to the certificate.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
The seven readiness areas, from Cryptographic Inventory to Exceptions, each move from Not Started toward Established as items are ticked: the overall picture is what an audit will find today.
GRC / Risk & Compliance
Tick each control, for example 'CBOM generated' or 'RACI defined', and add an evidence row with the reference such as a CMVP certificate number; every item cites its source (EO 14028, SP 800-131A, CSF 2.0) so the auditor can follow the row.

Cryptographic Inventory

Ensure all cryptographic assets are cataloged for audit review.

Policy & Governance

Verify organizational policies and governance structures are in place for PQC migration.

Risk Assessment

Assess quantum-specific risks including HNDL exposure and data sensitivity classification.

Technical Controls

Confirm technical controls are deployed and tested for the PQC transition.

Vendor Management

Assess vendor PQC readiness and update contractual requirements.

Evidence & Documentation

Ensure all required evidence and documentation is prepared for audit submission.

Exceptions

Document approved deviations from policy with their compensating controls and sunset date. These rows export with the checklist.

No exceptions yet.

Evidence — CMVP / ACVP / ESV / CVE-scan

Per change, capture validation evidence. Educational template — populate from your real CMVP module IDs and ACVP run records.

No evidence rows yet.

Try it

Tick "CBOM generated" and add an evidence row with a CMVP certificate number. What moves?

Next step

Next in Compliance & Audit: Compliance Timeline Builder

Compliance Timeline Builder is the next Compliance & Audit tool in the Command Center.