Guide

Preparing for a Security Assessment

The six weeks before an assessment, sequenced: documentation, evidence, owner rehearsal, and gap honesty.

Intended audience
Program owners
Difficulty
Advanced
Estimated time
15 minutes
Access
Premium plans
CMMC
NIST SP 800-171
SOC 2
ISO 27001
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Sequence assessment preparation activities across a six-week timeline.
  • Explain why evidence should be sampled and tested before an assessment, not just collected.
  • Prepare control owners to verbally explain their controls during interviews.
  • Describe the correct way to handle unresolved gaps during an assessment interview.
  • List the operational steps to take during assessment week itself.

Weeks six to five: documentation

  • Confirm every policy is current and approved.
  • Confirm the SSP matches how the system works today.

Weeks four to three: evidence

  • Sample controls and test whether the artifact proves the claim.
  • Refresh anything stale.
  • Fix naming so nobody hunts during the assessment.

Weeks two to one: people

  • Have each owner explain their control out loud.
  • Practice saying 'that is on our POA&M' instead of improvising.

The week of

  • Freeze changes.
  • Nominate a single point of contact.
  • Keep a running log of requests and responses.

Key takeaways

  • Documentation review should confirm that every policy is current, approved, and that the SSP matches how the system actually works today.
  • Sampling controls and testing whether the artifact proves the claim catches gaps before an assessor finds them.
  • Control owners should be able to explain their control out loud rather than reading from a script.
  • Answering 'that is on our POA&M' is the correct, honest response to an unresolved gap rather than improvising an answer.
  • During assessment week, changes should be frozen and a single point of contact should manage all requests.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

Earn a Certificate of Training Completion

Complete every section, acknowledge, and pass the knowledge check.

Sections opened0 of 4
Knowledge check

80% required to pass. Answers are graded on our servers.

1. In the weeks six-to-five window, what should be confirmed?

2. What is the purpose of sampling controls during the evidence phase?

3. What should control owners practice before the assessment?

4. What is the recommended response to an unresolved gap during an interview?

5. What should happen during the week of the assessment?

This certificate recognizes completion of educational training material only. It is not a professional certification, accreditation, license, compliance assessment, audit result, or attestation of compliance with any law, regulation, or contract requirement. ComplianceAnvil is not a certification authority, accreditation body, assessor, or law firm.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This resource is educational readiness material. ComplianceAnvil is not a certification authority, assessor, or law firm, and this content is not legal advice or a compliance assessment.

Matched on shared frameworks, topics, and program packs.

Checklist

Evidence Collection Checklist

Turn what you already do into evidence: what to capture, how to label it, and how long to keep it.

Intermediate
25 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Quick reference

Evidence Collection Tips — One Page

A pocket guide to capturing artifacts that will still make sense in six months.

Beginner
4 min
Free
CMMC
SOC 2

Published · v1.0.0 · 2026-08-01

Checklist

Internal Audit Preparation Checklist

Run a dry run before anyone external looks: documentation, evidence freshness, owners, and open findings.

Intermediate
35 min
Free
SOC 2
ISO 27001

Published · v1.0.0 · 2026-08-01

Exercise

Perform a Mock Evidence Review

Play the assessor: decide whether sample artifacts actually prove the control claimed.

Intermediate
20 min
Free
CMMC
SOC 2

Published · v1.0.0 · 2026-08-01

Guide

How to Collect Compliance Evidence

What counts as evidence, how to capture it without slowing the business, and how to keep it usable.

Intermediate
11 min
Free
CMMC
SOC 2

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.