Gantt Chart for Cybersecurity Audit
Cybersecurity audits and assessments are among the most coordination-intensive projects in IT and security operations. They require input from IT infrastructure, application teams, compliance, legal, HR, and executive leadership — often simultaneously. They have evidence collection windows that expire if missed, third-party schedules that can't flex on short notice (penetration testers, QSAs, external auditors), and findings that trigger remediation work that itself needs to be managed on a timeline.
Without a structured project timeline, cybersecurity audits routinely run over budget, miss certification deadlines, and produce findings that never get remediated because the remediation roadmap was never formally managed. A Gantt chart for cybersecurity audit maps every phase from scope definition to 90-day follow-up, so the security team, IT owners, and auditors know what's happening and when.
The Three Types of Cybersecurity Assessment
Before building the Gantt chart, clarify which type of assessment you're running — the timeline, participants, and deliverables differ significantly.
Type 1: Internal cybersecurity assessment — conducted by your own security team or a hired consultant, not tied to a formal certification. Frameworks: NIST Cybersecurity Framework (CSF), CIS Controls. Timeline: 6–12 weeks.
Type 2: External compliance audit with certification — conducted or overseen by an accredited third party, producing a formal certification or attestation. Frameworks: SOC 2 Type I/II (AICPA), ISO 27001 (BSI, SGS, Bureau Veritas), PCI DSS (QSA). Timeline: 14–24 weeks (SOC 2 Type II requires a minimum 6-month observation period).
Type 3: Continuous monitoring program — ongoing security assessment embedded in operations, supplemented by annual point-in-time assessments. No fixed endpoint; governed by a rolling annual calendar.
This post covers the full audit/assessment timeline applicable to all three types, with notes on where they diverge.
Phase 1: Scope Definition (Weeks 1–3)
Scope is the most consequential decision in any cybersecurity audit. An overly broad scope adds months and cost without improving security outcomes. An overly narrow scope creates gaps in coverage that become liabilities.
Scope definition decisions:
Systems in scope:
- Which systems, applications, data stores, and network segments are included?
- For SOC 2: define the system description — the services you provide to customers and the infrastructure that supports them
- For ISO 27001: define the information security management system (ISMS) boundary — typically all systems that store, process, or transmit sensitive information
- For PCI DSS: cardholder data environment (CDE) — all systems that store, process, or transmit cardholder data, plus all systems that could affect the security of the CDE
Data classifications in scope:
- What categories of sensitive data does the assessment cover? (PII, PHI, financial data, intellectual property, cardholder data)
- Where is that data stored, processed, and transmitted?
Framework selection:
- NIST CSF — voluntary framework for critical infrastructure, but widely adopted. Organized around 5 core functions: Identify, Protect, Detect, Respond, Recover. Good starting framework for organizations building a security program.
- ISO 27001 — international standard for information security management systems. Certification involves a two-stage audit by an accredited certification body. Certification lasts 3 years with annual surveillance audits.
- SOC 2 — AICPA framework, audited by a licensed CPA firm. Type I is a point-in-time assessment; Type II covers a period of 6–12 months, providing assurance that controls operated effectively over time. Most SaaS and cloud service providers pursue SOC 2 Type II.
- NIST SP 800-53 — comprehensive federal security control catalog, used by US government agencies and contractors.
Document scope agreement:
By the end of Week 3, the scope must be documented and agreed by:
- CISO or security lead
- IT infrastructure lead (responsible for systems in scope)
- Executive sponsor
- External auditor/assessor (if already engaged)
Scope changes after Week 3 add cost and time — typically 2–4 additional weeks per significant scope addition.
Phase 2: Questionnaire Distribution to IT and System Owners (Weeks 3–6)
The assessment begins with a structured questionnaire to system owners and IT teams. This questionnaire establishes self-reported control posture before evidence is collected.
Questionnaire content:
Questions are framework-specific. For NIST CSF:
- Asset management: do you maintain an inventory of all hardware and software in scope?
- Access control: how are privileged accounts managed? What's the MFA enforcement rate?
- Data protection: how is sensitive data encrypted at rest and in transit?
- Vulnerability management: what's your patch cadence? What's the current vulnerability backlog?
- Incident response: do you have a documented IR plan? When was it last tested?
- Business continuity: what's your RTO and RPO? When was your last DR test?
For ISO 27001: questionnaires map to the 93 controls in Annex A (ISO 27001:2022 version).
Distribution logistics:
- Assign one questionnaire per system owner or IT function — don't send one consolidated questionnaire to the IT team as a whole (it won't be completed systematically)
- Set a clear response deadline (typically 10–14 business days)
- Provide a point of contact for questions
- Use a questionnaire tool (OneTrust, RSA Archer, ServiceNow GRC) or a structured spreadsheet
Follow-up:
Questionnaire response rates are typically 60–80% by the initial deadline. Budget a week for follow-up and chasing.
Deliverable by Week 6: Questionnaire responses collected from all system owners, initial gap identification in process.
Phase 3: Evidence Collection Window (Weeks 5–12)
Evidence collection is the proof-gathering phase — the auditor or assessment team requests specific documentation that demonstrates controls are in place.
Common evidence request types:
Policies and procedures:
- Information security policy
- Access control policy
- Incident response plan
- Business continuity and disaster recovery plan
- Change management procedure
- Vendor risk management policy
Technical evidence:
- Firewall rule sets and network diagrams
- Vulnerability scan results (recent, from approved scanner)
- Patch status reports (demonstrating current patch levels for systems in scope)
- Access control lists and user access reviews (evidence that least-privilege is enforced)
- Log management configuration (what's being logged? How long retained? SIEM or SOAR in use?)
- Encryption configuration (at rest: disk encryption or database encryption; in transit: TLS configuration, certificate inventory)
- MFA enforcement reports (what percentage of privileged and end user accounts use MFA?)
Process evidence:
- Security awareness training completion records (who completed training, when)
- Penetration test reports (prior 12 months)
- Incident records (evidence that the IR plan is being followed)
- Change control records (evidence that change management is working)
- Vendor risk assessments (evidence of third-party due diligence)
Evidence collection coordinator:
Designate one person per system or function to gather evidence on behalf of the team. Don't route all requests through a single central point — it creates a bottleneck.
Evidence collection takes longer than teams expect. Policies exist but can't be found. Firewall rules exist but are exported from systems owned by network engineers who are on vacation. User access reviews were done but never documented. Budget 6–8 weeks for a thorough evidence collection cycle, with follow-up weeks built in.
Phase 4: Penetration Test Scheduling and Execution (Weeks 6–14)
Penetration testing is typically conducted by a third-party firm and has scheduling dynamics that make it one of the highest-risk items in the Gantt chart for timeline slippage.
Pen test lead time:
Quality pen test firms are booked 4–8 weeks in advance for external assessments and 6–10 weeks in advance for red team engagements. Scope a pen test engagement contract and schedule the slot before the evidence collection phase is complete.
Pen test scope:
- External penetration test: attacks from the perspective of an internet attacker (no credentials, no internal access) — focuses on internet-facing systems, web applications, and public-facing infrastructure
- Internal penetration test: assumes the attacker is already inside the network — tests lateral movement, privilege escalation, and access to sensitive systems
- Web application penetration test: focused on a specific web application, following OWASP testing methodology
- Social engineering (phishing simulation): tests employee susceptibility to phishing attacks
- Red team: comprehensive adversary simulation with no predefined scope; tests detection and response capabilities as well as technical controls
Pen test timeline:
- Scope and contract: 2–3 weeks before test start
- External test execution: 1–2 weeks
- Internal test execution: 1–2 weeks
- Report drafting by pen test firm: 1–2 weeks after test completion
- Report delivery: week 12–14 of the overall assessment
Rules of engagement:
Before the test begins, document and sign the rules of engagement: what systems can be tested, what's off-limits (production systems that can't be disrupted), test hours (business hours only or 24/7), escalation contacts, and what happens if a critical vulnerability is found during the test.
Phase 5: Vulnerability Scanning (Weeks 4–8, recurring)
Automated vulnerability scanning runs in parallel with evidence collection and pen test scheduling. Unlike pen testing, vulnerability scanning is automated and fast.
Scanning tools:
- External vulnerability scanning: Qualys, Tenable.io, Rapid7 InsightVM — scans internet-facing systems for known vulnerabilities
- Internal vulnerability scanning: same tools deployed inside the network, scanning all internal systems in scope
- Container and cloud scanning: Prisma Cloud, Wiz, Aqua Security — scanning cloud workloads and container images
Scanning frequency during audit:
Run an initial baseline scan in Week 4 and a follow-up scan in Week 8. The gap shows whether the organization is actively remediating or letting the vulnerability backlog grow.
Scan results review:
- Critical and high vulnerabilities: prioritize for immediate remediation (target: CVSS 9.0+ patched within 30 days)
- Medium vulnerabilities: track and remediate within 90 days
- Low vulnerabilities: log in risk register for periodic review
The vulnerability scan results feed directly into the auditor's findings — unaddressed critical vulnerabilities will appear in the audit report.
Phase 6: Auditor Fieldwork (Weeks 10–16)
Fieldwork is when the external auditor or assessment team is actively working in your environment — interviewing staff, reviewing evidence, and testing controls.
Fieldwork activities:
- Management interviews: CISO, IT director, legal/compliance, HR, business unit leads — structured interviews to validate that controls described in policies are actually implemented
- Technical testing: auditor reviews configurations, samples log data, tests backup and recovery procedures, observes change management workflow
- Evidence review: auditor reviews the evidence package collected in Phase 3, requests additional evidence for gaps, and validates evidence authenticity
- Control testing: for SOC 2 Type II, the auditor tests controls over the full observation period (not just at a point in time) — this is why the SOC 2 Type II observation period must be running before fieldwork begins
Fieldwork coordination:
Assign an internal project manager to coordinate fieldwork logistics: scheduling interviews, tracking evidence requests, confirming technical access for the auditor, and escalating blockers. Uncoordinated fieldwork extends the timeline by weeks.
Fieldwork typically takes 2–4 weeks depending on scope and the number of controls being assessed.
Phase 7: Preliminary Findings Presentation (Weeks 16–18)
Before the final report is issued, auditors present preliminary findings to management. This is a working session, not a final verdict.
Preliminary findings session purpose:
- Auditors present identified gaps and potential findings
- Management has the opportunity to provide context, correct factual errors, and present evidence the auditor may have missed
- Discussion of finding severity (critical, high, medium, low, informational)
- Alignment on timeline expectations for the management response
Why this matters:
Factual errors in audit findings do happen. An auditor may flag a control as missing because the evidence wasn't clearly provided, when the control actually exists. The preliminary findings session is the correct venue to resolve these discrepancies — not after the final report is issued.
Phase 8: Management Response Period (Weeks 18–21)
After the preliminary findings, management drafts a formal response for each finding:
Management response components:
- Acceptance or dispute of the finding (disputes must be substantiated with evidence)
- Root cause (why does this gap exist?)
- Remediation plan: specific action, owner, and target completion date
- Compensating controls (if full remediation is not immediately possible, what mitigating controls are in place?)
Management responses are incorporated into the final audit report. Auditors issue the final report with both the findings and management responses visible.
Phase 9: Final Report Issuance (Week 21–22)
The final audit report is the formal deliverable. Contents:
- Executive summary (suitable for board-level review)
- Scope and methodology
- Detailed findings with severity ratings
- Management responses
- Risk rating summary (if framework-specific)
For SOC 2: the final report is the SOC 2 Type I or Type II attestation report, signed by the CPA firm. It is typically distributed to customers under NDA as evidence of security posture.
For ISO 27001: the certification audit produces a certificate (valid 3 years) or a list of non-conformities that must be corrected before certification is issued.
Phase 10: Remediation Roadmap Development (Weeks 22–26)
The audit report triggers remediation work. The remediation roadmap is a prioritized project plan for addressing findings.
Remediation roadmap structure:
- Critical findings (CVSS 9.0+ or equivalent): remediated within 30 days
- High findings: remediated within 90 days
- Medium findings: remediated within 180 days
- Low findings: tracked in risk register, remediated within 12 months
For each finding:
- Assign a technical owner (who does the work)
- Assign a management owner (who is accountable for completion)
- Define the specific remediation action (not just "fix access control" — "implement MFA on all privileged accounts using [specific tool]")
- Set a target completion date
- Identify dependencies (tools that need to be procured, budget that needs to be approved)
Phase 11: 90-Day Follow-Up Assessment (Week 35)
The 90-day follow-up confirms that remediation work has been completed and controls are now operating effectively.
Follow-up assessment:
- Re-test each critical and high finding from the original audit
- Collect evidence of remediation (configuration screenshots, policy updates, training completion records)
- Issue a follow-up memo confirming closure status of each finding
Organizations that schedule the 90-day follow-up at the time of final report issuance have significantly higher remediation completion rates than organizations that leave it unscheduled.
Annual Audit vs. Continuous Monitoring
Annual audit cycle:
Most compliance frameworks require an annual assessment. Build the 24-week audit cycle into your annual calendar:
| Month | Activity |
|---|---|
| January–February | Scope definition and questionnaire |
| February–April | Evidence collection and vulnerability scanning |
| March–May | Penetration testing |
| April–June | Auditor fieldwork |
| June–July | Findings, management response, final report |
| July–October | Remediation program |
| October | 90-day follow-up |
| November | Annual calendar planning for next year |
Continuous monitoring program:
Mature security programs don't just audit annually — they monitor continuously. Continuous monitoring replaces the point-in-time evidence collection with automated control monitoring that runs year-round:
- SIEM (Security Information and Event Management) alerts on access anomalies in real time
- Automated vulnerability scanning weekly or monthly (not just at audit time)
- Continuous compliance platforms (Drata, Vanta, Secureframe) auto-collect evidence for SOC 2 and ISO 27001 throughout the year
Continuous monitoring reduces the annual audit workload and produces better security outcomes — it finds issues between audits instead of 12 months later.
Full Cybersecurity Audit Gantt Chart
| Phase | Weeks | Key Deliverable |
|---|---|---|
| Scope definition | 1–3 | Signed scope document |
| Questionnaire distribution | 3–6 | All responses collected |
| Evidence collection | 5–12 | Evidence package complete |
| Pen test scheduling | 4–8 | Test slot confirmed |
| Vulnerability scanning | 4–8 | Baseline and follow-up scans |
| Penetration testing and report | 8–14 | Pen test report received |
| Auditor fieldwork | 10–16 | Fieldwork complete |
| Preliminary findings | 16–18 | Management has reviewed findings |
| Management response | 18–21 | Responses drafted and submitted |
| Final report | 21–22 | Final report issued |
| Remediation roadmap | 22–26 | Roadmap with owners and dates |
| 90-day follow-up | Week 35 | Finding closure confirmed |
The cybersecurity audit Gantt chart is the difference between an assessment that produces real security improvement and one that produces a report that sits in the CISO's drive. Findings without a managed remediation roadmap don't get fixed. The Gantt chart owns the remediation.
Build your cybersecurity audit Gantt chart free at gantt-chart.io