Don't invent the wheel

A surprising amount of this field's best material is free, maintained by serious organizations, and sitting one search away. The scarce thing isn't guidance — it's selection. This field doesn't lack free resources; it lacks people who finish using any one of them.

So this page comes with a usage rule, the same one that applies to all work in progress: pick one resource per job, finish applying it, and only then collect another. A folder of forty bookmarked frameworks is not a security program — it's inventory, quietly expiring. Everything below is something I've actually used or evaluated; each entry says what the thing is for and where the catch is.

Build lists & baselines

CIS Critical Security Controls v8.1Free · registrationVerified Jun 2026

The prioritized "what to do" list this site's gap workbook is built on. Start with Implementation Group 1 and ignore the rest until IG1 is honestly done. Caveat: the full document is long — the IG1 subset is the actionable part.

CIS BenchmarksFree · registrationVerified Jun 2026

Hardening guides for almost everything you run — Windows, M365, browsers, network gear, cloud platforms. Use Level 1 profiles; Level 2 breaks things in exchange for security most SMBs don't need. Caveat: don't try to apply every setting — adopt the benchmark as your documented standard and deviate consciously.

NIST CSF 2.0 + Small Business Quick-Start GuideFreeVerified Jun 2026

The shared vocabulary for talking about your program (Govern–Identify–Protect–Detect–Respond–Recover), and the quick-start is genuinely sized for small organizations. Use it for structure and leadership conversations, not as a build list — it tells you what to think about, not what to do first.

Microsoft Security Baselines (Windows & Intune)FreeVerified Jun 2026

Microsoft's own hardened configuration sets, deployable through Intune in an afternoon. If you're an M365 shop, this is the fastest route from "default" to "defensible" — pair it with the eight tenant moves.

Risk assessment

CIS RAM (Risk Assessment Method)Free · registrationVerified Jun 2026

A full risk assessment methodology built around the CIS Controls, including the "reasonableness" framing that holds up in legal and regulatory contexts. Use it when you've outgrown a simple register and someone needs your method defended. Caveat: it's heavyweight for a first pass — start with a plain register and graduate.

NIST SP 800-30 — Guide for Conducting Risk AssessmentsFreeVerified Jun 2026

The reference text most formal methodologies trace back to. Worth reading once for the thinking; rarely worth implementing literally at SMB scale.

Policies, training & awareness

SANS Security Policy TemplatesFreeVerified Jun 2026

The largest free policy library, covering far more situations than my three-policy starter set. Use it when a specific demand (a regulation, a contract) requires a policy I don't cover. Caveat: they're templates by committee — every one needs shortening and reality-matching before adoption.

SANS OUCH! NewsletterFreeVerified Jun 2026

A monthly one-page security awareness piece written for normal humans, free to redistribute internally. The cheapest functioning awareness program available: forward it monthly, done.

NCSC Small Business Guide (UK)FreeVerified Jun 2026

The UK government's small-business security guidance — possibly the best-written introductory material in the field, useful regardless of where you operate. Their board toolkit is also a quiet gem for leadership conversations.

FTC Cybersecurity for Small BusinessFreeVerified Jun 2026

Plain-language basics with ready-made staff handouts. Less depth than NCSC, more US-specific framing.

Free checks & services

CISA Cyber Hygiene ServicesFree · US orgsVerified Jun 2026

The US government will scan your internet-facing systems for vulnerabilities, continuously, for free, with a weekly report. If you're US-based, this is the single most underused free service on this page.

CISA KEV CatalogFreeVerified Jun 2026

The list of vulnerabilities actually being exploited right now — the honest answer to "which patches first?" If it's on KEV and on your edge, it's this week's work, not this month's.

Have I Been PwnedFreeVerified Jun 2026

Free breach monitoring for your whole domain — get alerted when employee credentials show up in dumps. Five minutes to set up; pairs naturally with your password policy.

MXToolbox + DMARC.orgFreeVerified Jun 2026

Check your SPF/DKIM/DMARC posture in thirty seconds, then learn what the results mean. Most domains are still at p=none — the check is free; so is fixing it.

US government work

NIST SP 800-171 r3 + 800-171AFreeVerified Jun 2026

The requirements (171) and — more usefully — the assessment procedures (171A) that tell you exactly what an assessor will check. Score yourself against 171A, not against your own optimism.

DoD CIO — Official CMMC DocumentationFreeVerified Jun 2026

The scoping guides and assessment guides, straight from the source. Read the Level 2 scoping guide before paying any consultant — the enclave decision it describes is your biggest cost lever.

DIB SCC CyberAssistFreeVerified Jun 2026

Control-by-control implementation guidance for 800-171/CMMC, written by defense-industry practitioners, with small-business notes. The closest thing to a free CMMC consultant.

India

CERT-In — Directions, Guidelines & AdvisoriesFreeVerified Jun 2026

The primary source for the six-hour reporting directions, reportable incident categories, and the incident reporting formats themselves. Pre-stage the report format in your incident response policy — don't meet it for the first time during an incident.

MeitY — DPDP Act & RulesFreeVerified Jun 2026

The Act, the Rules, and the official notifications with the actual compliance dates. Read the primary text before any vendor's summary of it — the summaries have a way of ending in a product demo.

ISO & management systems — what's actually free

Honesty matters most here, because this corner has the worst free-to-paid ratio. The ISO standards themselves — 27001, 27002, 9001 — are paid documents, typically a few hundred dollars each from iso.org or your national standards body, and you will need the official text to certify. What's legitimately free:

ISO/IEC 27000FreeVerified Jun 2026

The overview-and-vocabulary document for the whole 27000 family is free, and it's enough to understand the structure and the language before you spend anything.

CSA Cloud Controls Matrix + CAIQFree · registrationVerified Jun 2026

A free control framework with pre-built mappings to ISO 27001 and others, plus the CAIQ — the standard self-assessment questionnaire many customers will accept in place of bespoke spreadsheets. Answer CAIQ once, reuse everywhere.

A caution on "ISO toolkits"Mostly paidVerified Jun 2026

The document-template bundles sold for 27001 mostly produce the exact failure mode the ISO page warns about: a parallel paper system describing an organization that doesn't exist. If you already run 9001 or CMMI machinery, you need far less than any toolkit sells — extend what you have.

Incident response

NIST SP 800-61 r3 — Incident ResponseFreeVerified Jun 2026

The reference for incident handling, now aligned to CSF 2.0. Read it once to sanity-check your one-page process; don't replace your one-page process with it.

CISA Incident Response PlaybooksFreeVerified Jun 2026

Step-by-step response and vulnerability playbooks. Written for federal agencies, but the phase structure adapts down to small teams better than most commercial material.

How this connects: the templates on this site aren't a replacement for these sources — they're the SMB-sized on-ramp to them. The gap workbook operationalizes CIS IG1; the policy set is the short version of what SANS offers long; the register is where you start before CIS RAM. Pick one resource per job. Finish it. Then come back for the next one.

Every link here was verified live in June 2026, and this page is re-checked each quarter. Organizations restructure their sites; if something 404s, the resource name plus the publishing organization will find it. Spotted a better free resource I've missed? Tell me — this page is meant to grow slowly and stay honest.