Guide

Building a Security Program from Scratch

A ninety-day sequence for a business with nothing written down yet — cheapest, highest-impact work first.

Intended audience
Owners with no existing program
Difficulty
Beginner
Estimated time
14 minutes
Access
Free
NIST CSF
CIS Controls
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Sequence a ninety-day plan for building a security program from nothing.
  • Identify the highest-impact, lowest-cost actions to take in the first thirty days.
  • List the core policies and inventories to produce in days 31 through 60.
  • Explain what it means to 'prove' a program during days 61 through 90.
  • Describe the ongoing maintenance cadence required after day 90.

Days 1–30: stop the bleeding

  • MFA everywhere.
  • Password manager.
  • Automatic updates.
  • Verified backups.
  • Name an owner.

Days 31–60: write it down

  • Information security policy and acceptable use.
  • Asset and vendor inventories.
  • Incident response plan.

Days 61–90: prove it

  • Train everyone and record it.
  • Run an access review.
  • Collect evidence.
  • Set review dates and a risk register.

After day 90

You now maintain rather than build. Quarterly access reviews, annual policy re-approval, and a live risk register are the whole job.

Key takeaways

  • The first thirty days should focus on cheap, high-impact fixes: MFA everywhere, a password manager, automatic updates, verified backups, and a named owner.
  • Days 31 through 60 focus on writing foundational documents including an information security policy, acceptable use policy, and asset and vendor inventories.
  • Days 61 through 90 focus on proving the program works through recorded training, an access review, and evidence collection.
  • After day 90, the work shifts from building to maintaining, with quarterly access reviews and annual policy re-approval.
  • A live risk register is part of ongoing maintenance, not a one-time deliverable.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 4
Knowledge check

80% required to pass. Answers are graded on our servers.

1. Which action is recommended in the first 30 days?

2. What should be produced during days 31-60?

3. What does 'proving it' during days 61-90 involve?

4. What is the ongoing cadence recommended after day 90?

5. What ongoing artifact should remain 'live' after the initial 90 days?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Checklist

Small Business Security Checklist

The thirty-day baseline: the controls that stop the majority of small-business incidents, ordered by impact.

Beginner
30 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Checklist

Cybersecurity Self-Assessment Checklist

A fast, honest look at your current security posture across identity, devices, data, people, and response.

Beginner
25 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Template

Acceptable Use Policy

What employees may and may not do with company systems, data, devices, and AI tools.

Beginner
25 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Template

Backup Verification Log

Proof that backups exist, run, and have actually been restored at least once.

Beginner
15 min
Free
NIST CSF
CIS Controls

Published · v1.0.0 · 2026-08-01

Exercise

Build Your First Asset Inventory

Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.

Beginner
20 min
Free
CIS Controls
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Complete a Readiness Scorecard

Score yourself honestly across six areas and turn the two lowest into a short plan.

Beginner
15 min
Free
NIST CSF

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.