HomeSECORA › Compliance calendar generator

Free tool · 12-month compliance calendar for ISO 27001, SOC 2, CMMC, NIS2, HIPAA, GDPR

Compliance calendar generator: every recurring ISO 27001, SOC 2, CMMC and NIS2 duty, month by month, with owners and artefacts

Frameworks are lost between audits, not during them. SOC 2 Type II tests operating effectiveness over a window and CMMC assessors sample recurring practices, so "we do that" has to become "here is the evidence for every month". Pick your frameworks and estate and this tool lays out the year.

Updated 22 September 2026 · By ITSECOPS, CISA-certified compliance consultants

Duties, cadences and artefacts follow the SECORA planner catalogue (45 recurring duties). The full calendar and CSV download are unlocked with a work email.

0recurring duties
0dated tasks over 12 months
0owner roles

Unlock the full 12-month calendar

See every month, download the CSV and get the same calendar as a written plan for your frameworks.

What happens next: the calendar unlocks now; a consultant emails the written plan within 1 business day. No newsletter.

Have SECORA run this calendar for you

What is in the calendar

The catalogue mirrors the SECORA planner: 45 recurring duties across weekly, monthly, quarterly and annual cadences, each with a department owner and the artefact an auditor accepts. Examples: weekly SIEM alert triage review (Sentinel export), monthly stale user and device review (Entra sign-in report, Intune compliance export), monthly change management sample (ticketing export, merged pull requests with approvals), quarterly backup restore test (signed record plus screenshot), quarterly privileged and user access reviews, quarterly MFA coverage and Conditional Access policy review, annual risk assessment, annual vendor risk assessments, annual incident response tabletop and DR exercise, annual policy re-approval, internal audit and management review for ISO, SSP and POA&M refresh and SPRS affirmation for CMMC, records of processing and DSR log review for GDPR, business associate agreement review and ePHI audit log review for HIPAA, supply-chain check-ins and management briefings for NIS2.

Filtered by your estate

A Microsoft 365 client gets Purview, Entra and Sentinel exports; an AWS client gets CloudTrail and IAM credential reports; an on-premises client gets firewall rule reviews, media sanitisation and physical access log checks. The generator applies the same filter SECORA uses when it seeds the planner from your inventory, so owners are never asked for an Azure export they cannot produce.

How SECORA runs this calendar for you

Inside SECORA every task carries the cadence, the artefact format, the source path, the controls it evidences, the owner from the users register (with the client POC as fallback) and a Remind button. Reminders are previewed and sent from the sender’s mailbox through Microsoft Graph, stamped on the task and written to the audit trail. Overdue items turn red on the card, the dashboard tile and the board report. Done means the artefact is in the evidence library, mapped to the controls the task lists. Regenerate when the estate or timeline changes; completed tasks are never touched.

Planner · compliance calendar
SECORA compliance calendar with owners and reminders
Evidence · IA.L2-3.5.3
SECORA evidence recipes: exact report, format and menu path per control

What SECORA costs

SECORA is licensed per organisation. You pay a one-time deployment fee that covers installation in your tenant, framework configuration, policy library seeding, dashboard customisation and hand-over, with twelve months of maintenance, updates and support by ITSECOPS included. There are no per-user, per-month or per-framework charges, and an optional maintenance renewal is available from year two. Because there is nothing to export at exit (the lists are already yours), there is no lock-in either. Model your own numbers in the three-year GRC cost calculator or request a written quote.

Frequently asked

Type II tests operating effectiveness over an observation window, so auditors sample recurring evidence: access reviews, change management approvals, vulnerability and patch management, backup restore tests, incident response exercises, vendor reviews, security awareness training and risk assessment. The generator schedules each with a cadence, owner and artefact.

Annex A does not fix cadences, but certification bodies expect at least annual risk assessment, internal audit, management review, policy review and awareness training, quarterly or more frequent access and privileged access reviews, and continuous logging and monitoring evidence. The calendar reflects those norms.

Continuous monitoring evidence for the 110 practices: log reviews, account management, configuration changes, vulnerability scanning, incident response testing, awareness training including insider threat, SSP and POA&M maintenance and the annual SPRS affirmation. Phase 1 self-assessment duties still apply after the July 2026 Phase 2 suspension.

Yes. After unlocking with a work email you can download the generated calendar as CSV to import into Planner, Outlook or Jira. SECORA customers get the same calendar generated inside their tenant with owners, reminders and evidence links.

See SECORA running in your own tenant

Walkthrough slots, deployment scope and a written quote within 1 business day.

Book a walkthrough
SECORA, GRC platform by ITSECOPS

Ready for a walkthrough
in your own tenant?

Tell us your frameworks and estate. A CISA-certified ITSECOPS consultant replies within one business day with a walkthrough slot, the deployment scope for your tenant and a written quote. No newsletter, no phone call unless you ask for one.

What happens next: a consultant replies by email within 1 business day with slots and a written scope. No phone call unless you ask for one. No newsletter.

Book a walkthrough in your tenant