Use this checklist
- Mark each item verified, missing, unknown or not applicable. Unknown is work to investigate.
- Name an owner and keep evidence of the check; a purchased tool is not evidence that the control works.
- Prioritize essential services, finance and privileged access before optional hardening.
- Use the 90-day roadmap to sequence the work.
Last updated: September 24, 2026
The checklist below translates NIST's small-business CSF 2.0 guidance into operating questions. It is a planning aid, not a NIST certification checklist. Your sector, contracts and state laws may add requirements; ask the appropriate adviser when an incident or regulated data is involved.
The working control board
| Check | Owner | Evidence to keep | Review |
|---|---|---|---|
| Inventory critical apps, data, devices and outside administrators | Operations + IT | Current inventory and business impact notes | Quarterly and after major change |
| Require MFA for email, admin, remote and finance access | Identity administrator | Enrollment export and exception list | Monthly |
| Remove leavers and expiring contractor access promptly | HR + app owners | Sample offboarding test and access review | At every departure; monthly sample |
| Keep supported devices updated and encrypted | Device administrator | Coverage and overdue-update report | Weekly exceptions |
| Enable available mail filtering and authenticate sending domains | Mail administrator | Configuration, sender inventory and message-header checks | Monthly; after mail change |
| Verify payment or bank-detail changes out of band | Finance lead | Procedure and approved sample | Every change |
| Back up critical systems and test restores | Backup owner | Scope, success report and dated restore test | Monthly health; periodic restore |
| Maintain incident contacts and decision rights | Operations lead | Offline runbook and tabletop notes | Quarterly |
A control can be not applicable with a written reason: for example, a business with no public server does not need a public-server patch report. A control is unknown when nobody can show its configuration or result. Do not convert unknown to verified just because a vendor invoice exists.
First pass: three actions for an unstructured team
- Get a list of all administrator and finance accounts; enable MFA and document any exception.
- Ask the backup owner to restore one critical item to a safe location and record the result.
- Give finance a known-number callback and second-approval rule for bank-detail changes.
These actions connect directly to account takeover, disruption and payment fraud. They also produce checks that a five-person team can understand without buying a new platform. For implementation detail see the password-manager guide, backup strategy and BEC guide.
Monthly owner meeting: twenty useful minutes
Review the exception list, not a generic score. Ask what changed in users, devices, mail senders and suppliers; which updates or backups failed; whether finance had a suspicious request; and which action is late. Record the decision, owner and due date. Escalate a recurring exception to the business owner. The security tips guide gives a weekly rhythm for the underlying checks.
If the team cannot answer a row, run the free assessment to identify questions and create a local report. It does not inspect your systems, so confirm findings with the administrator and evidence above.
A purchasing gate
Before adding a product, check the exact edition and configuration of what you already own. Write down the remaining requirement, the operator and the validation test. Compare a new tool only against that documented gap.
Sources checked September 24, 2026: NIST SP 1300, FTC Cybersecurity for Small Business, and CISA SMB resources. The cadence is Valydex editorial guidance, not a prescribed NIST schedule.