Setup Checklist

Use this checklist to track your progress through the AutoCISO onboarding journey.

Phase 1: Foundation

  • Complete your organization profile (name, industry, employee count)
  • Connect your identity provider or import employees via CSV
  • Set your primary contact and DPO if applicable
  • Run your first gap analysis
  • Invite at least one Compliance Manager

Phase 2: ISO baseline

  • Review the gap analysis results
  • Assign owners to each ISO 27001 control
  • Prioritize top-10 gaps for remediation
  • Upload your existing policies as evidence (if any)
  • Create your first risk register entries

Phase 3: Compliance workflows

  • Complete your first access review
  • Add your key suppliers
  • Configure at least one backup test scenario
  • Run the first round of control self-assessment
  • Review your Statement of Applicability draft

Phase 4: Audit readiness

  • Ensure evidence is uploaded for all applicable controls
  • Confirm all high-priority risks have remediation plans
  • Run the pre-audit report and review findings
  • Invite your auditor as a Reviewer
  • Complete a full backup test with sign-off

Need help?

Last reviewed: 2026-04-28

Was this page helpful?

Esc