From nothing to provable in ninety days
September 8, 2026
Most compliance projects start the wrong way round. A manual gets written, thirty documents appear, and only after six months does anyone check whether what those documents claim is actually switched on. It turns out it is not, and the work starts anyway.
You can do it the other way. Start with reality and only write down what you have proven.
Day 1 to 30: measure
Improve nothing. Measure first.
Connect what you run, usually Microsoft 365 and maybe a cloud environment and your source control. Pull the factual state out of it. How many admins, is multi-factor authentication genuinely on everywhere, which guest accounts are still alive, how are your backups set up.
The goal of this month is one number and one list. No opinion, no assumption, and no panic if the number disappoints.
The mistake to avoid here is fixing things as you run into them. Do not. Your baseline is what later proves something changed, and you only get to take it once.
If you fall under the Dutch cybersecurity act, use this month to handle registration and the self-assessment as well. It takes an hour and it stands apart from the rest.
Day 31 to 60: close
Now you fix, and only the heavy items.
Take the ten heaviest points off your list. Not twenty. Ten is what a team can carry alongside normal work, and ten heavy items usually cover most of your risk. Multi-factor authentication for the last accounts, admin rights back to whoever needs them, legacy protocols closed, a backup actually restored once.
Put a name on each item. Not a department, a name. Items without an owner sit still, and that is the most predictable way to make this phase fail.
Only now do you write policy, and only for what you have genuinely just set up. Policy that describes practice is done in an afternoon. Policy that has to prescribe practice takes months and is still wrong afterwards.
Day 61 to 90: record
This phase is about evidence, and evidence is not the same thing as a document.
Evidence has a date, a source and someone who signs off on it. An export of a setting with the date next to it is evidence. A sentence in a policy saying that setting ought to be on is not.
Use this month to set the rhythm too. What gets checked how often, who looks at it, and what happens when it deviates. Without that rhythm you slide back to where you started within a year, and it happens on its own.
What does not fit in ninety days
Being honest about this saves disappointment.
An ISO 27001 certificate does not fit. Certification is done by an independent certification body and runs in two stages, and it expects a management system that has genuinely been running for a while. Ninety days is too short to show that.
A fully worked risk assessment covering every process does not fit either, and most companies do not need one to get started.
What does fit: you know where you stand, the heaviest gaps are closed, you have evidence with dates on it, and you can answer a customer questionnaire without taking a week off. For the large majority of smaller companies that is exactly enough, and it is infinitely more than the manual that is still in draft after six months.
What to do today
Look at what is switched on right now. Not what you think is switched on. That gap is the whole exercise, and the rest is execution.
Sources
All sources were consulted on 8 September 2026.
ISOQAR. (2026). ISO 27001 audit process. https://isoqar.com/iso-standards/iso-27001/audit/
Nationaal Cyber Security Centrum. (2026). Aan de slag: waar begin je? https://www.ncsc.nl/cyberbeveiligingswet-nis2/aan-de-slag
Nationaal Cyber Security Centrum. (2026). Zorgplicht. https://www.ncsc.nl/cyberbeveiligingswet-nis2/zorgplicht
