What the customer receives

SecureSpec example readiness review

This Organization does not test your security. It documents what you can prove today, names what you cannot, and prepares the work so that a qualified security professional starts on the hard part.

A complete sample document, written the way SecureSpec writes one. The customer, the numbers and the sources are illustrative.

SecureSpec Security readiness review

Security Readiness Review · USD 79

You can evidence 31 of 40 controls. One of the nine is blocking.

What your security posture looks like on paper, before a customer asks you to prove it.

Prepared for
Halcyon Data Ltd · 24 staff, first enterprise customer in procurement
Reference
SS-R-60833
Issued
1 October 2026
Settlement
$SEC · USDC on Base

Your engineering team believes the company is in reasonable shape. On the evidence, they are right: 31 of 40 controls are in place and can be demonstrated. The problem is not the security. It is that three of the nine gaps are things a procurement team will ask about in the first week, and one of them will stop the deal.

Better shape than you feared, with one blocker

Access control, encryption, backups and logging are all in place and evidenced. The blocker is that eleven former staff and contractors still have active accounts in at least one system, including two in production. That is the single question most enterprise questionnaires ask directly, and it is answerable in a week.

31 / 40 Controls evidenced
9 Gaps
11 Stale accounts found
2 Of those in production
1

Position

Where you stand by area

Controls evidenced, by area · of controls
Data protection and encryption 7 7 of 7
Backup and recovery 6 6 of 6
Logging and monitoring 5 5 of 6
Device and endpoint 5 5 of 6
Access control 4 4 of 7
Policy and governance 3 3 of 5
Incident response 1 1 of 3

Evidenced means a document, a screenshot, a configuration export or a log was produced and is in the pack. It does not mean the control was tested.

2

Evidenced

What is in place, with the proof

ControlEvidence heldOwner
Encryption at rest Cloud config export, all 6 stores Platform
Encryption in transit TLS config, certificate inventory Platform
Multi factor on admin accounts Identity provider report, 100 percent IT
Automated daily backup Job history, 90 days, no failures Platform
Restore tested Test record, 14 July 2026 Platform
Centralised logging Config, 400 day retention Platform
Endpoint encryption Device report, 23 of 24 devices IT
Password policy enforced Identity provider policy export IT
Vulnerability patching Patch report, 30 day SLA met Platform
Supplier list maintained Register, 31 suppliers Operations
Data retention schedule Documented, approved March 2026 Operations

Eleven of the 31 are shown. The full register with every evidence reference is in the pack.

3

Gaps

The nine, ranked by what a buyer asks first

#GapWhy it ranks hereEffort
1 11 stale accounts, 2 in production Asked directly on almost every questionnaire, and it is a real exposure 1 week
2 No offboarding checklist It is why gap 1 exists. Fixing 1 without this repeats it 2 days
3 No incident response plan Second most asked. Currently nobody knows who to call 1 week
4 No access review cadence Asked as how often do you review access 2 days
5 One laptop unencrypted A single device, but it makes the answer to a yes or no question no 1 day
6 No security training record Training happens. Nothing records it 3 days
7 Alerting on logs is partial You collect logs and nothing watches three of them 1 week
8 No documented change approval Process exists in practice, nowhere in writing 3 days
9 No penetration test Increasingly asked at this deal size. Needs a qualified firm External
4

Questionnaire

How you would answer their questionnaire today

Answer todayAfter the 8 internal fixes
Is data encrypted at rest and in transit? Yes, evidencedYes
Is MFA enforced on privileged accounts? Yes, evidencedYes
Are backups tested? Yes, July 2026Yes
Do you remove access when staff leave? No, and 11 accounts prove itYes, with a checklist
Do you review access periodically? NoYes, quarterly
Do you have an incident response plan? NoYes, with contacts
Is all staff security training recorded? No recordYes
Are all endpoints encrypted? 23 of 24Yes
Has a penetration test been performed? NoStill no, needs a firm

Eight of the nine gaps are fixable internally in about three weeks. The ninth requires a qualified testing firm and is the one item on this page we cannot help with.

5

Order

What to do, in this order

  1. Revoke the 11 accounts, production first

    An afternoon. Record the date of each revocation, because that record is itself evidence.

  2. Write the offboarding checklist

    One page. Named owner. Otherwise this list rebuilds.

  3. Incident response plan

    Who decides, who calls, who tells customers, and in what order. One page beats none.

  4. Encrypt the last laptop, set a quarterly access review

    Two small items that each turn a no into a yes.

  5. Training record, change approval, log alerting

    All three document something you already do.

  6. Engage a qualified firm for a penetration test

    The only item here that needs testing rather than documenting. We can prepare the scope and the questions to ask three firms.

SS-R-60833 · evidence as at 30 September 2026 · $SEC · 1 October 2026 SecureSpec · $SEC
The order behind this document
Format

A control register with evidence against each item, the gaps ranked, and the questions a customer questionnaire will ask.

Back to SecureSpec →