Compliance programs tend to be built in a burst and then left alone. Policies get written, a system security plan or procedure set gets approved, and then the business changes. New staff, new systems, new vendors, and new contracts quietly make yesterday's documents inaccurate.
A midyear review is a low-cost way to find those gaps on your own schedule. This guide applies whether you are a defense subcontractor working toward CMMC, a small utility or vendor touching NERC CIP requirements, or an operator affected by TSA pipeline security directives. The details of each program differ, so treat this as a framework to run alongside your actual requirements.
Start with what has changed
Gather the people who know your environment and answer a few plain questions for the past six months.
- Which systems, applications, or cloud services were added or retired?
- Which locations, sites, or facilities opened or closed?
- Who joined, left, or changed roles in ways that affect access?
- Which vendors or subcontractors now touch regulated data or systems?
- Did any contract, customer requirement, or regulation change what you must do?
Every yes is a place where your documentation may no longer match reality.
Check the documents against the environment
For defense subcontractors
If you handle controlled unclassified information, compare your system security plan and asset inventory against what actually exists. Confirm the boundary still describes where that information lives. Review open plan-of-action items and check whether the dates and owners are realistic. Verify that flow-down requirements from your primes are tracked.
For small utilities and their vendors
Review your asset categorization against any new equipment, and confirm that access lists for electronic access points and personnel with authorized access are current. Compare training and access records for people who recently changed roles. NERC CIP expectations are specific, so use your compliance lead and the actual standards as the authority.
For pipeline operators
Review your cybersecurity plans and incident response procedures against the directives that apply to you. Confirm contact lists for reporting are current, and check that testing exercises are on the calendar and documented.
Test the controls, not just the paper
A document that says multifactor authentication is required proves nothing about whether it is enabled. Pick a handful of controls and verify them directly.
- Try to find an account without multifactor authentication.
- Pick three former employees and confirm their access is gone.
- Restore one file or system from backup and record how long it took.
- Review recent logs and confirm someone actually looked at them.
- Confirm that security updates are installed on a sample of devices.
Record what you checked, who checked it, and the result. That record is evidence.
Look at people and vendors
Training records often lapse quietly. Confirm that required awareness training is complete for all current staff, including new hires and seasonal workers. Review your list of vendors with access to sensitive systems, and confirm each one has a current agreement that covers security expectations and incident notification.
Build a short remediation plan
You will find gaps. That is the point. Sort them into three buckets.
- Fix now: simple items like disabling stale accounts or updating a contact list.
- Plan and budget: items needing money or time, such as replacing unsupported equipment.
- Accept with documentation: low-risk items where a leadership decision and a written rationale are appropriate, where your program allows it.
Assign an owner and a date to each item. Items without owners do not get done.
Common midyear findings
- Asset lists that omit laptops, tablets, or cloud services added during projects.
- Accounts for people who left months ago.
- Policies that reference tools no longer in use.
- Incident response plans with outdated phone numbers.
- Backups that exist but have never been tested.
Where Ironfield Cyber fits
Ironfield Cyber helps contractors and energy companies run this kind of readiness review and turn the findings into a practical plan. We are not a substitute for your compliance counsel or assessor, but we can show you where your documents and your environment disagree.