Compliance checklist
Compliance in 15 steps, from framing to steering
The 15 steps of a compliance programme, turned into 46 control points to tick, from framing to steering, so you can see where you stand.
Framing: the texts that apply to you, perimeter, roles (steps 1 to 3)
Measuring the gap: compliance assessment and risk mapping (4 and 5)
Implementation: policies, awareness, third parties, incidents, evidence, tooling (6 to 11)
Control and steering: audits, non-conformities, indicators, watch (12 to 15)
The scale for reading your result once the boxes are ticked
A method that holds for GDPR, ISO 27001, DORA and NIS 2
September 2026 edition. This checklist describes a programme: it does not list the obligations of any single text. The requirements of NIS 2 and DORA are ticked in the ReCyF and DORA checklists.