Identify the actual requirement
Record the source, entity, jurisdiction and deadline. A customer questionnaire, internal audit plan and legal obligation do not necessarily ask for the same work. Involve the relevant legal, compliance or certification owner when the requirement is formal.
Use frameworks as an agreed reference
NIST CSF can help structure cybersecurity outcomes; NIST SP 800-53A describes tailorable assessment procedures. An engagement may map evidence to selected outcomes or control criteria, but the mapping must show scope and limitations. Do not label a partial review as an organisation-wide conformity result.
Keep different engagements distinct
| Engagement | Boundary |
|---|---|
| Cybersecurity control audit | Agreed criteria, procedures, evidence and findings. |
| Penetration testing | Authorised adversarial technical validation of selected systems. |
| Readiness review | Preparation against stated requirements; no certificate is issued. |
| Formal assurance or certification | Separate eligibility, independence and scheme requirements. |
Agree evidence handling
Set access, secure transfer, permitted use, retention and reporting recipients. Minimise personal information and secret material. State how supplier-held or unavailable evidence will be treated. The website forms are for initial scoping and an optional NDA/RFP, not unrestricted audit evidence uploads.
Primary sources
- Atlant Security IT security audit
- NIST Cybersecurity Framework
- NIST SP 800-53A assessment methodology
General information, not a compliance opinion. Confirm legal applicability and security service requirements for your entity and jurisdiction.
Build your audit scoping brief, or send your requirements with an NDA or RFP. High-level context is sufficient for the first conversation.

