Direct answer: Roughly fifteen things recur in a mature compliance programme, and each one is only useful if it produces a dated artefact with a named owner. Monthly items are access and vulnerability work. Quarterly items are reviews: vendors, policies, risk. Annual items are the expensive ones: penetration test, training, recovery testing, risk assessment refresh, and the audit itself. A calendar without owners and artefacts is a list of intentions.
Why most compliance calendars fail
The usual version is a spreadsheet with dates, built during readiness, never opened again. It fails for a specific reason: it records when something is due but not who does it, what it produces, or where that artefact goes. When the date arrives, nobody is accountable and there is nothing to file, so the entry gets moved rather than done.
A calendar entry that works has four parts. What the activity is, who owns it by name, what artefact it produces, and which controls that artefact evidences. The last part is what turns a chore into evidence.
Monthly
Access review of privileged systems. Not every system every month, but production, cloud console and identity provider are worth a monthly pass at most companies, with the full review quarterly. Produces: a dated record naming the reviewer, the accounts examined, and what changed.
Joiner and leaver evidence. Produced per event rather than on a schedule, but reviewed monthly to catch anything missed. Produces: provisioning and deprovisioning records with timestamps.
Vulnerability scan triage. The scan may be continuous. The triage is the control. Produces: findings with severity, owner, and either a fix with a date or an accepted risk with a rationale.
Backup verification. Confirming backups completed is monthly. Confirming they restore is annual and different. Produces: backup job records with failures explained.
Quarterly
Full user access review. Every system in scope, including the ones nobody thinks of, like the billing platform and the analytics tool with customer data in it. Produces: the review record, plus the tickets for revocations that came out of it.
Vendor and subprocessor review. Which vendors touch what data, tiered by that rather than by spend. Reports collected where the vendor claims one. Produces: an updated register with report expiry dates.
Policy review. Not every policy every quarter, but on a rotation so each is reviewed annually and the reviews are spread. Produces: version history and a re-approval record.
Risk register review. Owners confirmed, treatments progressed, new risks added from incidents and changes. Produces: an updated register showing movement rather than an identical copy of last quarter.
An exercise. A tabletop, a failover test, or a restore. Rotating the type across the year covers more ground than repeating one. Produces: an after-action record with what broke.
Annual
Penetration test. Scoped to what customers ask about, with retesting of the findings. The retest is the part that turns a report into evidence of remediation. Produces: the report, the remediation record, and the retest.
Security awareness training. Everyone, with completion tracking, including the people who joined mid-year. Produces: completion records by person and date.
Risk assessment refresh. The full methodology, not the quarterly register review. Produces: the assessment document and whatever it changes in the register.
Business continuity and disaster recovery test. An actual restore into an actual environment. Produces: the test record, the recovery time achieved, and the gaps found.
Internal audit. Required for ISO 27001, and a good idea regardless. Produces: findings and corrective actions, which the certification body will look at.
Management review. Also an ISO requirement, and the one most often faked. Produces: minutes showing leadership actually considered the ISMS and made decisions.
The audit or surveillance cycle itself. Fieldwork, sampling, evidence requests, and the report. Produces: the report, and the exception list that becomes next year's first priority.
Framework-specific additions
ISO 27001 adds the internal audit and management review above, plus Statement of Applicability maintenance whenever scope changes. PCI DSS adds quarterly external scanning by an approved vendor and annual attestation. HIPAA and PHIPA add workforce training with specific content and a documented risk analysis. Quebec Law 25 and PIPEDA add privacy impact assessments triggered by projects rather than dates, which is why they get missed. CPCSC and CMMC add an annual affirmation that somebody senior has to sign.
Making it survive contact with a real year
Put the artefact, not the activity, in the calendar entry. "Q3 access review" is a task. "Q3 access review record filed against CC6.2 and A.5.18, owner Priya, due 30 September" is an obligation with a shape.
Schedule the annual items early in the cycle rather than late. A penetration test in month eleven leaves no room to remediate and retest before the period ends, and the finding you cannot close becomes an exception.
Review the calendar itself quarterly. Cadences drift as the company changes, and a calendar that no longer matches your system description is worse than none, because the description is what the auditor holds you to.
If nobody internally has the calendar as an actual job, it will slip, and it will slip invisibly. That is the specific gap an ongoing retainer exists to close: the cadence is operated on a schedule that is somebody's responsibility, and the artefacts land against the controls as they are produced.
Want this handled? Tell us what your buyer is asking for and we will tell you what the work involves, what it costs, and what you can do yourself.
Talk to usOr talk about a retainer