Principle Security Principle Security.

Free · no signup

What's due, and when

Pick the frameworks that apply to you. We'll show the recurring security-compliance obligations — ongoing, quarterly, annual and event-driven — so nothing sneaks up on you before an exam or audit.

Ongoing / continuous

  • CMMC 2.0
    System Security Plan (SSP) & POA&M upkeep

    Keep the SSP current and work the POA&M to closure; both are examined evidence.

  • FTC Safeguards
    Written information security program

    Maintain a written program with a Qualified Individual accountable for it.

Quarterly

  • NCUA
    Vendor due diligence review

    Review tier-one vendor security posture and contracts on a recurring cadence — most reported incidents trace to third parties.

  • SOC 2
    Access review

    Periodic user access reviews are a common control auditors sample — quarterly is typical.

  • PCI DSS
    Vulnerability scans (ASV)

    Quarterly external scans by an Approved Scanning Vendor, plus internal scans.

Annual

  • NCUA
    Board-approved information security program review

    Part 748 Appendix A requires the board to review and approve the written program at least annually, with a report on its status.

  • NCUA
    Risk assessment refresh

    Update the risk assessment yearly and after any material change to systems, vendors or the threat environment.

  • FFIEC
    Cybersecurity maturity review (post-CAT)

    The CAT was retired Aug 31 2025; maintain your maturity narrative in NIST CSF 2.0 language for examinations.

  • FFIEC
    Board reporting on information security

    Report information security program status to the board at least annually.

  • FFIEC
    Third-party risk management review

    Review third-party relationships and controls per interagency third-party risk guidance.

  • HIPAA
    Security Risk Analysis

    The Security Rule requires an accurate, current risk analysis — in practice, reviewed at least annually and on material change.

  • HIPAA
    Workforce security awareness training

    Provide and document security awareness training for the workforce.

  • CMMC 2.0
    SPRS score submission / refresh

    Maintain a current NIST 800-171 self-assessment score in SPRS; refresh annually or on material change.

  • FTC Safeguards
    Annual report to the board / governing body

    The Qualified Individual must report in writing at least annually on the program's status.

  • FTC Safeguards
    Penetration test + vulnerability assessment

    Annual penetration testing and twice-yearly vulnerability assessments (or continuous monitoring in lieu of).

  • SOC 2
    Type II audit period

    SOC 2 Type II covers a period (commonly 12 months); plan the audit window and evidence collection.

  • SOC 2
    Risk assessment

    Document an annual risk assessment as part of the control environment.

  • PCI DSS
    Self-Assessment Questionnaire / RoC

    Annual validation via SAQ or Report on Compliance depending on merchant level.

  • PCI DSS
    Penetration test

    Annual penetration testing and after significant changes to the cardholder data environment.

Event-driven

  • NCUA
    72-hour cyber incident report

    Report a reportable cyber incident to NCUA within 72 hours (12 CFR 748.1(c)). Have written reportability criteria set in advance.

  • NCUA
    ISE / ACET exam readiness

    Prepare artifacts and close prior-cycle findings ahead of the Information Security Examination or ACET self-assessment.

  • HIPAA
    Breach notification (60 days)

    Notify affected individuals without unreasonable delay and no later than 60 days after discovery of a breach of unsecured PHI.

  • CMMC 2.0
    Level 2 assessment cycle

    Level 2 (CUI) generally requires a third-party (C3PAO) assessment on a three-year cycle with annual affirmation.

On change

  • HIPAA
    Business Associate Agreement review

    Have a signed BAA before sharing PHI with any vendor; review on change of vendor or service.

A practical starting map, not legal advice. Exact deadlines depend on your contracts, examiner, audit period and merchant level — verify against your own obligations.

Why it matters

The overlap is the opportunity

Most institutions are under more than one framework, and the obligations overlap heavily — risk assessment, board reporting, vendor review, access reviews. Map them once and one piece of evidence can satisfy several. The organizations that struggle at exam time aren't missing controls; they're missing the calendar and the retrievable evidence.

Questions

Multiple frameworks apply — where do I start?+

Select them all, then satisfy the overlapping obligations (risk assessment, board reporting, vendor review) once with shared evidence.

Are these exact deadlines?+

They're recurring cadences, not calendar dates. Your specific dates come from your contract, audit period and examiner — this maps what recurs so you can schedule it.

Turn the calendar into a program that runs itself

We build the recurring cadence — risk assessments, board reporting, vendor reviews, testing — with evidence that retrieves in minutes, so exams and audits are routine, not fire drills.