Mid-Year Compliance Review: A Checklist for Contractors and Operators

Halfway through the year is a good time to check your compliance posture. Use this checklist to review CMMC, NERC CIP and pipeline security obligations.

3 min readBy Ironfield Cyber Team

By the end of June, most companies have settled into the year's projects and forgotten the compliance plans written in January. New contracts have arrived, staff have changed, systems have been added and a few commitments have slipped. A mid-year review is the cheapest way to catch drift before an assessment, an audit, a customer questionnaire or an insurance renewal brings it to light.

This checklist is meant for contractors with defense or government work, utilities and their vendors, and pipeline operators. Not every item applies to every company, so use what fits.

1. Revisit your obligations

  • List the contracts, customer requirements and regulations that apply to you
  • Note any new contracts since January and the cybersecurity language they contain
  • Confirm whether requirements such as CMMC, NERC CIP or TSA security directives apply to your role, and at what level
  • Record any deadlines, reporting duties and renewal dates

Obligations change when you win work, add sites or take on new customers, so do not assume last year's answers still hold.

2. Check your scope

For companies handling Federal Contract Information or Controlled Unclassified Information:

  1. Confirm where CUI is received, stored and shared.
  2. Review who has access and remove those who no longer need it.
  3. Check whether new systems, cloud services or vendors have entered the environment.
  4. Update diagrams and data flow documentation.

For utilities and pipeline operators, review which assets and facilities fall under which requirements, and whether any have been added, retired or reclassified.

3. Review documentation

  • Are policies and procedures current, and do they match what you actually do?
  • Has your system security plan been updated since the last significant change?
  • Are open gaps and plans of action tracked, with owners and dates?
  • Do your incident response and recovery plans list current contacts and systems?

Outdated documents are a common finding. Fix them now.

4. Test key controls

Access

Run an access review: confirm that accounts belong to current staff, privileged access is limited, and vendor accounts are justified. Check that MFA is enforced where required.

Patching and configuration

Review patch status and exceptions. For operational technology where patching is difficult, confirm that compensating controls and approvals are documented.

Backups and recovery

Run a restore test and record the result. Confirm that backups are protected from tampering.

Logging and monitoring

Make sure logs are being collected, retained and reviewed, and that alerts reach someone who can act.

Remote access

Review who can connect from outside, how and under what controls. Close any paths that are no longer needed.

5. Check people and training

  • Has everyone completed required security training this year?
  • Have new hires and seasonal staff been trained?
  • Do contractors and vendors with access understand your requirements?
  • When did you last run a tabletop exercise, and what changed as a result?

6. Review suppliers and subcontractors

If you pass requirements to others:

  1. Confirm that flow-down terms are in your subcontracts.
  2. Ask key vendors for current evidence of their security practices.
  3. Review which vendors have access to your systems or data.
  4. Update your vendor risk list, and retire vendors no longer used.

7. Prepare your evidence

Compliance depends on proof. Spot check that you can produce:

  • Dated screenshots or exports for important settings
  • Records of reviews, training and tests
  • Meeting notes showing management oversight
  • Documentation of exceptions and approvals

Fill gaps now rather than during an audit.

8. Look at your budget and timeline

Compare planned improvements with what has been done. Note delays, funding needs and dependencies. Adjust the second half of the year to focus on the highest-risk items. If you are preparing for an assessment, work backward from the target date and confirm that the schedule is realistic.

9. Report to leadership

Summarize the results in a short briefing: what is on track, what is behind, what decisions you need, and which risks remain open. Compliance programs succeed when leadership sees them and supports them.

A hypothetical example

Consider a hypothetical subcontractor that wins a federal job in March. By June, CUI has started to arrive by email and is saved on several employees' laptops, none of which were considered in the original plan. A mid-year review catches the sprawl, leading to a secure storage location and a policy before it becomes a finding.

Keep the cadence

Treat the mid-year review as a recurring event, with a second review at year-end and quick checks whenever significant changes occur.

Support

Ironfield Cyber helps contractors, utilities and pipeline operators run compliance reviews, close gaps and organize evidence. If you would like help with a mid-year check, we can work through this list with your team and give you a prioritized plan for the second half of the year.