Annual Review Checklist
The once-a-year pass that keeps a program from quietly going stale.
Published · v1.0.0 · 2026-08-01
Exercise
Turn vague intentions into policy statements that are testable and enforceable.
Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team
Hint: Example: 'Account access is reviewed quarterly by each manager and recorded on the access review worksheet.'
Hint: If no artifact exists, the statement is not yet testable.
Hint: That becomes a POA&M item, not a rewrite.
Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.
Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.
NIST · 2.0
Cybersecurity Framework (CSF) 2.0(opens in a new tab)Link last confirmed 2026-02-01
NIST · Revision 3
SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information(opens in a new tab)Link last confirmed 2026-02-01
Federal Trade Commission
Start with Security: A Guide for Business(opens in a new tab)Link last confirmed 2026-02-01
Complete every section, acknowledge, and pass the knowledge check.
This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.
Version v1.0.0 · Document owner: ComplianceAnvil Content Team
Practice exercise. Your entries stay in this browser, are not submitted anywhere, and are not part of your compliance record.
Matched on shared frameworks, topics, and program packs.
The once-a-year pass that keeps a program from quietly going stale.
Published · v1.0.0 · 2026-08-01
Sort realistic records into classification levels and defend the handling rules that follow.
Published · v1.0.0 · 2026-08-01
Score yourself honestly across six areas and turn the two lowest into a short plan.
Published · v1.0.0 · 2026-08-01
The parent policy that states what your organization protects, who is responsible, and how the rest of your documentation hangs together.
Published · v1.0.0 · 2026-08-01
How to answer customer security questionnaires quickly, accurately, and without overpromising.
Published · v1.0.0 · 2026-08-01
Track the risks you know about, who owns them, and what you decided to do — including accepting them.
Published · v1.0.0 · 2026-08-01
Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.