Cyber AssessValydex™by iFeelTech
Implementation Guide

Small Business Cybersecurity Checklist (2026)

Practical control baseline for owners, IT leads, and operations teams

A standards-aligned SMB checklist with owner mapping, evidence requirements, and monthly governance cadence.

Last updated: September 24, 2026
3 minute read

Use this checklist

  • Mark each item verified, missing, unknown or not applicable. Unknown is work to investigate.
  • Name an owner and keep evidence of the check; a purchased tool is not evidence that the control works.
  • Prioritize essential services, finance and privileged access before optional hardening.
  • Use the 90-day roadmap to sequence the work.

Last updated: September 24, 2026

The checklist below translates NIST's small-business CSF 2.0 guidance into operating questions. It is a planning aid, not a NIST certification checklist. Your sector, contracts and state laws may add requirements; ask the appropriate adviser when an incident or regulated data is involved.

The working control board

CheckOwnerEvidence to keepReview
Inventory critical apps, data, devices and outside administratorsOperations + ITCurrent inventory and business impact notesQuarterly and after major change
Require MFA for email, admin, remote and finance accessIdentity administratorEnrollment export and exception listMonthly
Remove leavers and expiring contractor access promptlyHR + app ownersSample offboarding test and access reviewAt every departure; monthly sample
Keep supported devices updated and encryptedDevice administratorCoverage and overdue-update reportWeekly exceptions
Enable available mail filtering and authenticate sending domainsMail administratorConfiguration, sender inventory and message-header checksMonthly; after mail change
Verify payment or bank-detail changes out of bandFinance leadProcedure and approved sampleEvery change
Back up critical systems and test restoresBackup ownerScope, success report and dated restore testMonthly health; periodic restore
Maintain incident contacts and decision rightsOperations leadOffline runbook and tabletop notesQuarterly

A control can be not applicable with a written reason: for example, a business with no public server does not need a public-server patch report. A control is unknown when nobody can show its configuration or result. Do not convert unknown to verified just because a vendor invoice exists.

First pass: three actions for an unstructured team

  1. Get a list of all administrator and finance accounts; enable MFA and document any exception.
  2. Ask the backup owner to restore one critical item to a safe location and record the result.
  3. Give finance a known-number callback and second-approval rule for bank-detail changes.

These actions connect directly to account takeover, disruption and payment fraud. They also produce checks that a five-person team can understand without buying a new platform. For implementation detail see the password-manager guide, backup strategy and BEC guide.

Monthly owner meeting: twenty useful minutes

Review the exception list, not a generic score. Ask what changed in users, devices, mail senders and suppliers; which updates or backups failed; whether finance had a suspicious request; and which action is late. Record the decision, owner and due date. Escalate a recurring exception to the business owner. The security tips guide gives a weekly rhythm for the underlying checks.

If the team cannot answer a row, run the free assessment to identify questions and create a local report. It does not inspect your systems, so confirm findings with the administrator and evidence above.

A purchasing gate

Before adding a product, check the exact edition and configuration of what you already own. Write down the remaining requirement, the operator and the validation test. Compare a new tool only against that documented gap.

Sources checked September 24, 2026: NIST SP 1300, FTC Cybersecurity for Small Business, and CISA SMB resources. The cadence is Valydex editorial guidance, not a prescribed NIST schedule.