Compliance roadmap
Also known as: security roadmap
A time plan that turns a list of gaps into ordered steps, owners and dates for meeting a set of requirements.
Draft - this entry has not been reviewed yet.
Formal
A prioritised plan, usually built from a gap analysis and risk assessment, that sets out which measures will be put in place, in what order, by whom and by when, so the organisation reaches and then keeps compliance.
In plain English
Like planning a house renovation - first the roof that leaks, then the wiring, and the new kitchen last - each job with a builder and a week.
In practice
After a gap analysis against NIS2, a Danish bus company plans MFA and backup tests in the first quarter, supplier checks in the second and its first crisis exercise before the summer holiday.
Why it matters
No organisation can fix everything at once, and a clear, agreed order shows leaders and authorities that the most important gaps come first.
Technical deep dive
A compliance roadmap is a planning artefact, not a term defined by a regulation, but ISO/IEC 27001:2022 gives it a precise anchor. Clause 6.2 requires information security objectives and, for achieving them, a determination of what will be done, what resources are required, who is responsible, when it will be completed and how results will be evaluated. Clause 6.1.3 e requires a risk treatment plan, and clause 6.3, new in the 2022 edition, requires that changes to the ISMS are carried out in a planned manner. A well-built roadmap is the time-sequenced consolidation of these: gap-analysis findings and risk treatment actions expressed as work packages with owners, dependencies, effort, deadlines and success criteria.
Sequencing is driven by three forces. Dependencies come first: an asset and software inventory must exist before vulnerability management can be measured, identity consolidation usually precedes organisation-wide MFA, and a risk method and scope must be agreed before the Statement of Applicability means anything. Risk reduction per unit of effort comes second, which typically pulls forward MFA for remote and administrative access, offline or immutable backups with restore tests, patching of internet-facing systems and removal of default credentials. External deadlines come third: NIS2-loven has applied since 1 July 2025, and for product manufacturers CRA reporting since 11 September 2026 with full obligations from 11 December 2027, and certification or customer audit dates impose their own milestones. The CIS Controls v8 Implementation Group 1, 56 safeguards regarded as essential cyber hygiene, is often used as a pragmatic first tranche for small organisations.
A common structure is phased: foundation (governance, roles, scope, policies, risk method), quick wins, structural capabilities (logging and detection, supplier management, business continuity and incident response with exercises), and assurance (internal audit, management review, certification or external attestation). Each item should carry a measurable exit criterion, for example "MFA enforced for 100% of privileged accounts, verified by identity-provider report", rather than an activity description such as "roll out MFA".
Roadmaps fail predictably. They are drawn on calendar time without checking capacity in IT operations, which executes most items; they end at certification as if compliance were a project rather than a state to maintain; they are not re-baselined when the threat picture, the scope or regulation changes; and they lose sponsorship because progress is reported as activities rather than risk reduction. Good governance means a steering forum reviewing status at least quarterly, explicit management decisions when items slip, and linking the roadmap to management review under clause 9.3. Under NIS2 Art. 20 the management body must approve and oversee the risk-management measures, which in practice means the board should see and approve the roadmap, not just the resulting policies.
What to learn first
Everything this builds on, foundations first.
- Compliance
- →Gap analysis
- →Compliance roadmap
Relationships
- Requires
- Gap analysis
Sources & further reading
Course material
- Cyber Security Fast Track - Kursuskompendium, Modul 3 (vejen til god compliance)
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…