Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What belongs on a cybersecurity due diligence checklist?

Last verified

A cybersecurity due diligence checklist walks control domains, vulnerability posture, incident history, supply-chain risk, data-protection exposure, and certifications — verifying scope and dates, not logos. Prior-breach silence is itself a risk. This page is not legal advice.

Cyber due diligence checklist, last verified 10 September 2026 against NIST CSF 2.0, NIST SP 800-53 Rev. 5, ISO/IEC 27001:2022, CIS Controls v8, AICPA TSC, and ENISA supply-chain guidance. Contractual reps and warranties are legal territory — not legal advice. Not investment advice.

Security facts, not logo collecting

Audience: a CISO or acquirer. This page is not legal advice and not investment advice. Kind of text: NIST CSF 2.0 and SP 800-53 are frameworks / catalogs (guidance unless a contract incorporates them). ISO/IEC 27001:2022 is a certifiable standard if you pursue it. CIS Controls v8 are community best practice. AICPA TSC are attestation criteria. ENISA supply-chain papers are agency guidance. Reps and warranties about security and breach disclosure are counsel’s territory.

Checklist by control domain

Last verified 10 September 2026. Not YOUR audit. Not legal advice.

Cyber due diligence checklist by control domain (not a certification; not legal advice)
DomainWhat to collectKind of text
Identify / inventoryAsset and data-class inventory, in-scope systems for any attestation.NIST CSF 2.0 Identify; ISO inventory practice.
ProtectIdentity, access, encryption, secure SDLC, backup.CSF Protect; CIS Controls; TSC Security.
DetectLogging, vuln ingest (KEV/EPSS/CVSS), last pen test or documented alternative.CSF Detect; see security-testing cluster on this site.
Respond / recoverIR plan, tabletop dates, RTO/RPO evidence, counsel/retainer facts.CSF Respond/Recover; not a substitute for the incident-response hub.
Supply chainCritical vendors, SOC reports received, SBOM, concentration risk.ENISA supply-chain guidance; CSF supply-chain category.
Data protectionLawful basis story, subprocessors, cross-border facts — for counsel to apply.Legal territory if you interpret GDPR or state law. This page does not.

Prior-breach and undisclosed-incident risk

Ask for a written incident chronology covering a defined lookback, including near-misses the target classified as non-notifiable. Silence, a “we have never had an incident” claim with no logging evidence, or a mismatch with public reporting is a diligence flag. Whether a past event was legally notifiable is counsel’s question — this page does not apply breach-notification statutes to YOU. Last verified 10 September 2026. Not legal advice.

Certification-verification note

A logo in a deck is not evidence. For SOC 2, read the report: type, period, exceptions, and carve-outs. For ISO/IEC 27001, read the certificate: standard year, scope statement, sites, and expiry. Confirm the legal entity matches the target. Expired, wrong-entity, or marketing-only marks are red flags. Last verified 10 September 2026. Not legal advice.

What to do now

Operational steps. Last verified 10 September 2026. Not legal advice.

  • Issue the domain table as a request list with a date certain.
  • Send certification PDFs to someone who will read scope, not only the badge.
  • Open the pre-acquisition security playbook and the tech-DD hub on this site.
  • If you already have a session: signed-in app → Compliance for the crosswalk (~72 controls, density-honest) and evidence overlay; Security for the cyber risk register. Naming those surfaces is not a public href.

Checklist

Question list. Not legal advice.

  • Every domain has an artifact or an explicit gap?
  • Incident chronology signed by a named officer?
  • SOC 2 / ISO scope and dates verified?
  • Reps-and-warranties language parked with counsel, not rewritten here?

Where this shows up in ShipReady Metrics

About 24 frameworks crosswalked to about 72 canonical controls with a density-honesty layer, vulnerability management (KEV, EPSS, CVSS), evidence review and met-verdict overlay, and a cyber risk register. The product does not certify the target and does not give legal advice on breach disclosure.

Primary sources (last verified 10 September 2026)

NIST CSF 2.0. NIST SP 800-53 Rev. 5. ISO/IEC 27001:2022. CIS Controls v8. AICPA TSC. ENISA supply-chain guidance. Not legal advice.

Frequently asked questions