Company Policy Creation & Adoption Lifecycle
Executive Overview & Detailed Implementation Runbook — Northern Data Solutions, Office of the CTO. Service Line: Compliance-as-a-Service, powered by CyberVerify.
Purpose: A single, complete guide that pairs the executive case for a managed policy program with a working, step-by-step runbook inside CyberVerify. The Executive Overview explains the “why” — why formally authored, reviewed, adopted, and maintained policies are the backbone of every compliance framework and the precondition for cyber-insurance. The runbook that follows is the “how” — moving a policy from a deployed template through authoring, review and publication, organization-wide adoption and attestation, and long-term governance in the knowledge base.
Who performs this: A shared responsibility between the Northern Data Solutions vCISO and the client. The NDS vCISO owns the template and policy-creation phases — delivering a compliance-grade version of each policy mapped to your applicable frameworks (CMMC / NIST 800-171, FTC Safeguards, PCI DSS, SEC, HIPAA). The client owns review, approval, adoption, and operational ownership of each policy thereafter.
Executive Overview
Why This Matters
Policies are not paperwork. They are the documented, approved, and attested controls that auditors test, that insurers underwrite against, and that regulators expect when an incident occurs. A control that is not written down, formally approved, and acknowledged by the workforce effectively does not exist in the eyes of a CMMC assessor, an FTC examiner, a PCI QSA, or a cyber-liability carrier. The difference between “we do that” and “here is the approved policy, its revision history, and signed attestations from every employee” is the difference between a passed assessment and a finding — and, after a breach, between a paid claim and a denied one.
Most mid-market organizations struggle here for the same reasons: policies live in scattered Word files, go stale the moment they are written, are never formally approved, and are never acknowledged by staff. The CyberVerify policy lifecycle closes every one of those gaps by turning policy management into a structured, repeatable, evidence-producing workflow.
The rule in one sentence: A policy only counts when it is authored to a framework, formally approved, adopted with attestation, and kept current — with the evidence to prove each step.
What the Policy Lifecycle Is (CyberVerify)
CyberVerify manages a policy through five structured stages, supporting collaboration between authors, reviewers, approvers, and employees. Throughout the lifecycle you manage versions, automate reviews, deliver training content, track acknowledgments, and maintain a centralized, shareable repository of published policies.
Stage | What happens |
|---|---|
1. Deploy | Create a draft instance of a policy template — individually, in bulk, or MSP-wide. Only completed templates can be deployed. |
2. Draft | Author the policy content section by section, manage versions, optionally generate AI training videos, and submit for review. |
3. Review & Publish | Reviewers and approvers comment, handle AI-generated adoption questions, and authorize the policy — which publishes it automatically. |
4. Adoption Campaign | Distribute the published policy to an audience for review, optional training and knowledge check, and acknowledgment by electronic signature. |
5. Knowledge Base | Maintain the published policy in a searchable, shareable repository with revision history, adoption status, and scheduled review reminders. |
Shared Responsibility — The vCISO Owns the Compliance Version
Authoring a policy that will actually satisfy an assessor is specialized work. That is why the template and policy-creation phases are a shared responsibility in which the Northern Data Solutions vCISO does the heavy lifting:
NDS vCISO provides: the completed policy template and a compliance-grade version of the policy content, written to and mapped against your in-scope frameworks (CMMC / NIST 800-171, FTC Safeguards, PCI DSS, SEC, HIPAA), so the language stands up to assessment.
Client provides: organization-specific details (owners, scope, systems, enforcement specifics), and drives review, approval, adoption, and ongoing ownership.
Important: This shared-responsibility model is what separates a generic template download from an audit-ready policy. The vCISO ensures the policy maps to the controls your frameworks require; the organization ensures it reflects how the business actually operates.
How This Connects to Compliance-as-a-Service
The policy lifecycle is the engine room of our Compliance-as-a-Service (CaaS) platform. A managed policy program does not just produce documents — it produces the auditor-ready, board-reportable, insurer-acceptable evidence that converts security activity into demonstrable compliance:
Formally approved policies with a documented information-security program — the first question on every modern cyber-insurance application.
Annual (or more frequent) review cycles enforced automatically through review reminders — answering “are policies reviewed and updated at least annually?”
Workforce training and attestation evidence captured through adoption campaigns — answering “do you maintain evidence of training and policy attestation?”
A centralized knowledge base and revision history — the standing source of truth auditors, the board, and underwriters can be shown on demand.
Keep selling the outcome: Honest “no” answers to insurer questions about approved policies, annual review, and attestation typically result in declination, sub-limited ransomware coverage, or claim denial after a loss. Pairing this runbook with the CyberVerify policy engine and the NDS vCISO converts policy management from a stack of stale Word files into an automated, audited control that satisfies CMMC, FTC Safeguards, and PCI — and meets the conditions carriers now require to bind coverage.
Before You Begin
Prerequisites and Access
Active client: Policies can only be deployed to active clients. Confirm the client is set to Active in MSP Settings > Clients.
Completed templates: Only completed templates are available for policy creation. If a template is missing at deployment, open the Template Library and finish its creation (check its completion tracking).
Framework scope defined: Know which Risk Management Frameworks (RMF) apply so the vCISO can map the policy correctly during authoring.
Roles identified: Name the policy owner, at least one reviewer and one approver (optionally a legal reviewer), and the employee audience that will adopt the policy.
vCISO engaged: Confirm the NDS vCISO is engaged to deliver the compliance version of each policy before authoring begins (shared responsibility).
Important: Author to the framework first. Begin with the vCISO-provided, compliance-mapped policy content. Customizing organization-specific details on top of a framework-aligned baseline is far faster — and far safer — than writing from a blank page and hoping it satisfies an assessor.
Phase 1 — Deploy Policy (Template Deployment)
Goal: Create a draft instance of a policy from a completed template, ready for authoring.
Owner: NDS vCISO (provides the completed compliance template) with the client MSP administrator — shared responsibility.
1.1 Confirm the client is active and open the policy area
Select the company you want to deploy the policy to and navigate to Policy Scorecard > Our Policies. If you cannot deploy, verify the client is Active in MSP Settings > Clients.
1.2 Deploy a single policy from a template
Click the + Add Policy button.
Enter the policy title and select a template or policy type — OSCAL, Single One-Page Template, or Standard Operating Procedure (SOP).
Click Add. You are directed to the Edit Policy page.
Tip: Only completed templates appear here. If your template is missing, visit the Template Library, check its completion tracking, and complete its creation before deploying.
1.3 Complete the policy information
On the Edit Policy page, complete the policy metadata. Required fields are marked:
Title (Required) — the title of the policy.
Category (Required) — created under Company Config > Company Settings.
Owner (Required) — the accountable owner of the policy.
Policy Review Reminder Settings (Required) — review periodicity (quarterly, semi-annual, annual), days before notifying, and email addresses to notify.
Risk Management Frameworks (RMF) — select the frameworks the policy applies to (the vCISO confirms this mapping).
Also available: Reference Material URL, Policy Tags, Policy Creator, Compliance Risk Score (1–5), Short Description, Notes, Vendor Due Diligence, and a Knowledge Base checkbox to include the policy once published.
Click Save at the bottom of the page. The policy is saved as a Draft.
1.4 Deploy multiple policies or MSP-wide
Multiple policies: In Policy Scorecard > Template Library > My Templates, use the checkbox next to each template, click Document Actions Available, and select Deploy Policies to Company.
MSP-wide: Select the templates, click Document Actions Available, choose Deploy to MSP-Wide Documents, and click Proceed. The policies become available as drafts under Our Policies for each client company.
1.5 Use the Deploy / Renew / Redeploy bulk actions
Open a template in the Template Library and use the Bulk Policy Actions menu, then select the clients to act on:
Deploy — deploy to any client that does not yet have the policy.
Renew — renew the assessment date for any client that already has the policy.
Redeploy — deploy the newest version of the template as a new major version of the policy for the client.
Phase 2 — Draft Policy (Authoring)
Goal: Produce complete, framework-aligned policy content and submit it for review.
Owner: NDS vCISO (authors the compliance version mapped to frameworks) with client input — shared responsibility.
2.1 Start from the vCISO compliance version (shared responsibility)
The NDS vCISO delivers a compliance-grade draft of the policy mapped to your in-scope frameworks. The client then layers in organization-specific detail (owners, scope, systems, enforcement specifics). Open the policy at Policy Scorecard > Our Policies by clicking its title, then select the version number to edit at the bottom of the page.
Important: This is the core of the shared-responsibility model: the vCISO guarantees the policy language satisfies the control objectives of CMMC / NIST 800-171, FTC Safeguards, PCI DSS, and any other in-scope framework, while the organization ensures it reflects real operations.
2.2 Write the required policy sections
Use the text editor to complete every section. A standard policy draft contains:
Executive Overview — a concise summary of the policy’s purpose and key points.
Purpose — the policy’s objective and what it aims to achieve.
Scope — to whom and what the policy applies.
Policy Enforcement — how the policy is implemented and enforced, including consequences for non-compliance.
Rules and Responsibilities — specific rules, expected behaviors, and who is responsible for upholding them.
Other Provisions as Required by Laws & Related Standards — additional requirements mandated by regulations or industry standards.
Definitions and Terms — clear explanations of key terms to avoid misunderstanding.
Tip: SOP drafts instead contain Summary, Scope, and Purpose sections plus a checklist section that is connected to the Project Center under a new project tied to the document.
2.3 Set policy settings and manage versions
Use Policy Settings to confirm the policy owner and choose whether to include a revision history. You must complete all sections before submitting. Click Save Draft to save (or Export to PDF to export). If you need to revert, the editor’s Versions feature lets you preview and load past versions.
2.4 Generate AI training videos (optional)
When submitting for review you can generate AI-powered training videos that walk employees through the policy during the Adoption Campaign — a synthetic voiceover paired with corporate imagery summarizing the policy’s key points. Videos generate within a few minutes, embed automatically for employees, and are listed under Policy Scorecard > Training Videos. Under the Settings tab you can control effects/transitions, output quality, narration voice, mandatory viewing and minimum watch percentage, auto-generate on publish, and Evidence Locker backup.
2.5 Submit the draft for review
Click Submit for Review. Use the toggles to require adoption questions and to generate training videos, provide a summary of changes, and confirm. Status changes to In Review.
Assign at least one approver and one reviewer (optionally legal reviewers).
Click Submit Policy for Review. Status changes to Pending Approval and reviewers are notified in-platform and by email.
Tip: Pending items appear under Policy Scorecard > Pending Reviews, where you can Resend notifications or reassign reviewers and approvers if someone is unavailable.
Phase 3 — Review & Publish Policy
Goal: Run the formal review and approval workflow so the policy is authorized and published.
Owner: Client reviewers and approvers (with optional legal reviewers).
3.1 Open the policy for review
As an approver or reviewer, navigate to Policy Scorecard > Pending Reviews and select the policy by clicking Review Policy. The review page shows the policy content on the left and an AI summary of changes — plus the adoption training video preview, if activated — on the right.
3.2 Leave comments and inline feedback
Reviewers can leave comments. For OSCAL policies, reviewers and approvers can add inline comments within the draft. Approvers may reject a policy but must provide a written reason.
3.3 Handle AI-generated adoption questions
If AI Analysis is activated, five adoption questions are created automatically (three true/false and two multiple-choice). These can be edited or regenerated before publication — they become the knowledge check employees complete during the Adoption Campaign.
3.4 Authorize and publish
To authorize, scroll to the bottom of the page and click Approve. Once both reviewers and approvers have approved, the policy status changes to Authorized and the document is published automatically.
Important: All assigned contacts must approve before the policy can be published. This formal, recorded approval is the audit evidence that the policy was vetted and authorized — not simply posted.
Phase 4 — Adoption Campaign (Adopt & Attest)
Goal: Distribute the published policy to employees and capture acknowledgment with an electronic signature.
Owner: Client compliance/program owner.
From the adopter’s perspective, a campaign has up to four steps: read the policy text, watch the training video (optional), complete the knowledge check (optional), and acknowledge — providing an electronic signature confirming full review.
4.1 Create the campaign and select policies
Navigate to Policy Scorecard > Adoption Campaign and click + Create New Campaign.
Select the policies for the campaign and click Step 2: Add An Audience.
Tip: You can assign only a single adopter audience per campaign. Create audiences beforehand under Audiences. When multiple policies are selected, each user adopts every policy from a single page.
4.2 Assign the audience and schedule
Select the audience and click Step 3: Create Adoption Campaign. Provide a campaign name (required), description, and reminder time. Choose to start immediately or schedule it, then click Create Campaign.
4.3 Send notifications and drive completion
Click Send Notifications to start the campaign and notify the audience by email. The Review Policy button takes adopters to a copy of the document; after reviewing, they check a box to consent to eSign disclosure, click Adopt, and type their name as a digital signature. Users are also notified if a campaign contains policies that have been deleted.
4.4 Track adoption status and acknowledgments
Visit Policy Scorecard > Adoption Campaigns and click the view icon next to a campaign to see, per contact, whether they have adopted the policy and when they were last notified, and to manually resend notifications.
4.5 Manage campaign contacts
You can remove a non-adopted contact from an active campaign by clicking the Delete button next to them, and resend notifications to those still outstanding.
Keep selling the outcome: Signed attestations are gold to an auditor and an underwriter. This step turns “we told staff about the policy” into a dated, per-employee electronic signature — exactly the evidence CMMC, FTC Safeguards, and cyber-insurance questionnaires demand.
Phase 5 — Knowledge Base (Maintain & Govern)
Goal: Maintain published policies in a searchable, shareable repository and keep them current.
Owner: Client program owner with NDS vCISO oversight (ongoing governance).
5.1 Publish to and use the knowledge base
Once published, a policy is featured in the company’s knowledge base, where you can search and filter policies and review revision history and adoption status (who has adopted and who is still outstanding). MSP admins and MSP users can download published policies as PDFs. Find it at Policy Scorecard > Knowledge Base and click View Knowledge Base.
5.2 Configure sharing, allowed domains, and access
Share & embed: share policies with all contacts from the Knowledge Base page, or embed it using the provided Knowledge Base Embed Code.
Allowed Domains: click + Add Domain to specify which domains can access the knowledge base.
Public Link Password: optionally protect public links with a password (at least 8 characters) that can be toggled or updated at any time, then Save Changes.
5.3 Maintain currency with scheduled reviews
The Policy Review Reminder Settings configured at deployment drive recurring review cycles (quarterly, semi-annual, or annual). When a review comes due, re-author through the same lifecycle and use Redeploy to publish a new major version — preserving revision history and prompting a fresh adoption campaign.
Important: Document every review. A policy with a visible revision history and recent review date is defensible; a policy last touched two years ago is a finding waiting to happen and a question an underwriter will ask.
Keep selling the outcome: A one-time policy push decays without governance. Pairing the CyberVerify knowledge base with scheduled reviews and the NDS vCISO converts policy management into a standing, audited control — the documented, board-reportable, insurer-acceptable evidence at the heart of Compliance-as-a-Service. Next step: ask the Office of the CTO for a no-cost executive readiness review of your policy program.
Document Owner: Northern Data Solutions — Office of the CTO. Service Line: Compliance-as-a-Service, powered by CyberVerify. Source: CyberVerify Policy Lifecycle documentation.