Cybersecurity compliance
Practical cybersecurity compliance for businesses with 1–100 employees
A documented program you can actually operate, not a framework binder.
What a small-business cybersecurity program actually contains
- Written policies that name real tools and real people, approved by the owner and dated.
- Identity controls — individual accounts, MFA on email and administrative access, a password manager, and access removal at departure.
- Device standards — encryption, screen locks, automatic updates, endpoint protection.
- Data protection — knowing what you hold, where it lives, and who can reach it.
- Backups that are tested, stored separately from production.
- An incident response plan with named contacts and a defined first hour.
- Trained people, because most incidents start with a person, not a firewall.
- Evidence, because the question is never only "do you do this?" but "can you show it?"
Where small businesses most often fall short
Across the controls ComplianceAnvil evaluates, the same items dominate: incomplete MFA coverage, backups that were never restore-tested, no written offboarding process, shared logins, and policies that were downloaded once and never approved or reviewed. These are the highest-value fixes and most cost nothing but attention.
About frameworks
Frameworks such as the NIST Cybersecurity Framework and CIS Critical Security Controls are useful references, and both publishers offer small-business guidance directly. ComplianceAnvil organizes similar practical ground in a workflow sized for a small business. We do not certify you against any framework, and no self-assessment tool can.
Sources worth reading directly: the NIST Small Business Cybersecurity Corner (nist.gov), CISA's Cyber Essentials (cisa.gov), and the FTC's small business cybersecurity guidance (ftc.gov). Reviewed February 2026.
Ready to see where you stand?
The assessment is free and takes about 15 minutes. You keep your score either way.
