What you actually receive

Sample deliverables

Every example below is illustrative sample output, clearly labeled. Your real deliverables are generated from your own answers.

Sample — illustrative data, not a real customer

Readiness score dashboard

62

out of 100 · model v1.0.0

Scores are deterministic: the same answers always produce the same score, and every point traces back to a specific control.

Governance58/100
Access Control71/100
Passwords and Authentication44/100
Devices66/100
Data Protection62/100
Incident Response35/100
Employee Training40/100
AI Use25/100
Sample — illustrative data, not a real customer

Executive risk report

critical
No written incident response plan

Adopt the generated plan and name a response lead.

critical
Multi-factor authentication is not enforced on email

Turn on MFA for every mailbox this week.

high
No AI acceptable-use rules for staff tools

Publish the AI acceptable-use policy and train staff.

high
Backups are never restore-tested

Run a restore test and keep the screenshot as evidence.

medium
Vendor list has no owner or review date

Assign an owner and set annual review dates.

Sample — illustrative data, not a real customer

30-day action plan

  1. 1Enforce MFA on email, storage, and payroll
  2. 2Approve the Information Security Policy
  3. 3Name a security and compliance owner
  4. 4Assign Security Awareness training to all staff
  5. 5Document your current vendor list
Sample — illustrative data, not a real customer

Redacted policy excerpt

3. Access Control

3.1 Every user account is assigned to one named individual. Shared logins are prohibited except for
approved service accounts documented in Appendix B.

3.2 Multi-factor authentication is required for email, file storage, remote access, financial systems,
and any administrative console.

3.3 Access is reviewed [REDACTED — review cadence] by the Security Owner. Accounts for departing
personnel are disabled the same business day.

3.4 Privileged access is limited to [REDACTED — named administrators] and reviewed quarterly.

Your policies are generated with your business name, owners, and dates filled in, and can carry your own letterhead on qualifying plans.

Sample — illustrative data, not a real customer

Training certificate

Certificate of completion

Security Awareness Essentials

Awarded to — Sample Employee

Score 92% · Certificate ID CA-SAMPLE-0001

Sample — illustrative data, not a real customer

Evidence checklist

  • MFA enforcement screenshot for email
  • Signed acknowledgement of the Information Security Policy
  • Backup restore-test screenshot with date
  • Training completion report with scores
  • Vendor list with owners and review dates
  • Device encryption report
  • Incident response tabletop notes
Sample — illustrative data, not a real customer

Mission Control screen

Good morning, Sample Owner. Your readiness score is 62 (+7 since your last review), two critical risks need attention, and your Incident Response Policy is ready for approval.

Current mission

Establish your incident response program

Progress

Waiting on you

Review and approve the policy

Samples are illustrative only. ComplianceAnvil does not publish customer names, logos, or metrics, and does not provide legal advice or certification.