Skip to main content

CMMC Pause: What DoW & Primes Still Require

2026 Cybersecurity Checklist 

Use this interactive checklist to assess, close, and document essential security practices this year, from asset inventory to vulnerability management, third-party risk, AI governance, disaster recovery and incident response. It draws on the security fundamentals emphasized in the 2026 Verizon Data Breach Investigations Report and the Department of War CIO's Brilliant at the Basics guidance, alongside CIS Critical Security Controls and other frameworks used across hundreds of customers' compliance programs. Note: This checklist was first published in 2024 and has been updated for comprehensiveness and accuracy.

What you'll get:

  • Nearly 100 checklist items across 13 categories, organized so you can work through one area at a time to prepare for your security audits this year and beyond
  • Fundamental coverage for the breach entry points that matter most right now: exploited vulnerabilities, third-party and supply chain exposure, and credential compromise
  • An easy way to keep your efforts organized with tasks that you can check off, save, and share with your team