Pre-Assessment Verification Workflow
Your documents are built. Now confirm your environment matches — item by item. Complete this workflow to activate your Assessment-Ready Guarantee.
Your SSP, policies, and supporting documents describe your security environment based on what you told us during intake. This workflow walks you through verifying that every claim in those documents matches what's actually deployed. Your C3PAO assessor will check these same things — this is your dress rehearsal.
Before You Start: The Evidence Clock
Your C3PAO assessor will want to see that your controls have been running for at least 90 days before the assessment. This checklist confirms your environment matches your documentation right now — but you also need time to build an evidence trail.
Recommendation: Complete this checklist now. Then start your evidence clock. Schedule your C3PAO assessment at least 90 days out to give yourself time to build the evidence trail.
Section 1: Identity & Access Control
Section 2: Network & Boundary Protection
Section 3: Endpoint Protection
Section 4: Audit & Monitoring
Section 5: Personnel & Training
Section 6: Physical Security
Section 7: Incident Response & Continuity
Section 8: Documentation Final Check
What happens when you finish
If you've checked every box above and your environment genuinely matches what's in your documents, you're ready for your C3PAO assessment. Your Assessment-Ready Guarantee is active — if any document we generated is rejected by your assessor, we remediate it at no cost.
The most common reason assessments fail isn't bad documentation — it's documentation that doesn't match reality. This workflow exists to prevent that. If you found items above that DON'T match your documents, contact us before your assessment so we can update your package.