Resources

What we'd hand you on a free call.
In checklist form.

Plain-language readiness checklists for the work most likely to be a problem — CMMC for defense subs, HIPAA for healthcare, AI governance for everyone. No email gate. No "download report" theater. Just the questions we'd ask you on the call.

FormatFree, ungated, web-readable
Available4 checklists, more shipping
UsePrint-friendly, share-friendly
Available now

The library so far.

Each piece is the same work we'd do with a paying client, sized down to a self-serve format. We're shipping more in the next few weeks. If one you don't see here would be exactly the thing — tell us; we move them up the queue when there's specific demand.

01
AVAILABLE

CMMC Readiness Checklist.

For defense contractors and subs.

A self-audit for firms preparing for CMMC L2 assessment — whether you're at zero or you have an SSP from a vendor who doesn't return calls anymore. Boundary scoping, identity & access, documentation, the NIST 800-171 control families, and audit prep.

5 sections·~25 items·15-min read
Read the checklist
02
AVAILABLE

HIPAA Risk Analysis Checklist.

For practices, clinics, and groups.

A real risk analysis walkthrough — not a 50-question yes/no checklist someone Googled. For the §164.308 analysis OCR cites in nearly every enforcement action, done as if it had to hold up under scrutiny. Because it does.

5 sections·~25 items·18-min read
Read the checklist
03
AVAILABLE

AI Governance Quick Start.

For any business with employees.

For leadership teams with a sense that AI is happening on the ground but no real read on what's being used, where data is going, or what the policy should say. Practical first steps, written for businesses that don't have a Chief AI Officer.

5 sections·~25 items·16-min read
Read the checklist
04
AVAILABLE

Customer Audit Response Kit.

For SOC 2 and vendor security questionnaires.

For sales, ops, and IT facing a 40-page security questionnaire from a prospect or major customer. How to read the ask, draft answers that win, and build the answer library that turns the next questionnaire into an hour of work instead of a week.

5 sections·~25 items·17-min read
Read the checklist
Also planned: 23 NYCRR 500 Walkthrough · Manufacturer's Incident Playbook · Wire Fraud Response Runbook
Why ungated

No email gate. No "download report" theater.

You shouldn't have to trade your email for a 30-page PDF that turns out to be a sales brochure. The work in these checklists is the same work we'd do with a paying client — sized down to a self-serve format, with the parts that actually matter kept and the filler cut. Read them on a phone. Print them. Share them with whoever's leading this work at your firm. If you want help applying any of it, the readiness call is no fee. That's the deal.

— Hudson Sky