Skip to main content

Compliance checklist

Compliance in 15 steps, from framing to steering

The 15 steps of a compliance programme, turned into 46 control points to tick, from framing to steering, so you can see where you stand.

Framing: the texts that apply to you, perimeter, roles (steps 1 to 3)
Measuring the gap: compliance assessment and risk mapping (4 and 5)
Implementation: policies, awareness, third parties, incidents, evidence, tooling (6 to 11)
Control and steering: audits, non-conformities, indicators, watch (12 to 15)
The scale for reading your result once the boxes are ticked
A method that holds for GDPR, ISO 27001, DORA and NIS 2

September 2026 edition. This checklist describes a programme: it does not list the obligations of any single text. The requirements of NIS 2 and DORA are ticked in the ReCyF and DORA checklists.

The information collected via this form is processed by Make IT Safe to follow up on your enquiry. To learn about and exercise your rights, see our Terms of Use.