Self-audit

The Contractor-to-Cloud Self-Audit

30 questions. Six categories. Each "no" carries a severity tag. Walk through with a screen-share in about an hour.

PDF includes Y/N checkboxes per question. CSV includes blank "Your answer" + "Notes" columns for tracking.

P0
Stop the bleeding

Active or near-active exposure. Treat as an incident. Fix this week.

P1
Within the next sprint

Real risk, not on fire yet. Becomes a P0 the day traffic doubles or the contractor goes dark.

P2
Structural

Not bleeding, not on fire. The reason your next migration will be painful. Plan, don't panic.

Score yourself

Count your "no" answers in each severity tier.

P0P1P2What it means
5+anyanyActive incident state. Stop reading and rotate credentials.
2–4anyanyAt least one P0 will become a story before year-end. Plan a 1-week stabilization sprint, this month.
0–15+anyHealthy under current load, fragile under any change. Plan an infrastructure migration this quarter.
0–12–4anyReasonable shape. Address what you have on a normal cadence.
00anyEither you are doing well, or you answered too generously. Run the audit with an engineer.

Want a real audit, not a self-graded one?

I do paid one-week audits — viewer-only IAM, a 20–30 page report, optional readout call.