Skip to main content

Statements of evidence, and sharing one with an auditor

How the NIS2, ISO 27001, GDPR, DORA and Cyber Essentials statements are built, what covered/gap/not covered mean, and how to send an auditor a read-only link that expires.

Written for an audit response8 min readUpdated

An auditor rarely asks "are you compliant" in one sentence. They ask, control by control: what proves this, when was it last checked, and can I verify it myself. Compliance > Statements answers exactly that, one page per framework, built from the same live checks and records the rest of the console already keeps.

The five frameworks

What each statement is built from.
FrameworkBuilt from
NIS2 Art. 21The same conformity checks the NIS2 conformity checklist already runs.
ISO 27001 Annex AThe same NIS2 evidence, reprojected through the NIS2 → ISO 27001 crosswalk — never measured a second way, so the two can never disagree. Covers the Annex A controls that crosswalk names, not the full Annex A.
GDPR Art. 32Encryption (vaulted credentials), the hash-chained audit log's integrity, your backups attestation, and DPIA records on file.
DORAYour ICT third-party register and the concentration-risk view.
Cyber EssentialsTwo answers straight from the insurance evidence pack (privileged-account MFA and endpoint protection); the rest — firewalls, secure configuration, patch management — read not covered, honestly, because this platform does not measure them yet.

See How findings map to DORA and ISO 27001 for the underlying crosswalk, and The insurance and Cyber Essentials evidence pack for the pack this page's Cyber Essentials rows reuse.

What each status means

Covered
A live check or record proves this control, and the evidence — a count and when it was checked — is shown.
Gap
Measured, and the answer is a real gap: partial coverage, a broken chain, or evidence that exists but does not satisfy the control.
Not covered
This platform has no data source for this control at all. Always named, never silently dropped from the page.

Sharing a statement with an auditor

  1. Choose Share with auditor

    On the statement you want to send.

  2. Enter your name and an expiry

    Up to 180 days out. The link stops working the moment it expires, or immediately if you revoke it.

  3. Copy the link

    It opens a read-only page with no login required — built for someone who should never need a console account.

Manage existing links from the same page: each one shows who shared it, its expiry, and a Revoke button. Revoking takes effect immediately — the link then reads exactly like one that never existed, so there is nothing for someone probing links to learn either way.

The NIS2 early-warning pre-fill

On a NIS2 incident that already has an early-warning draft (see Evidence-bound drafts), the incident page shows a pre-fill panel: severity, cross-border impact, affected services, and the Article 23 deadlines, read straight from that draft's own typed values — free text is left out, the same way the draft itself excludes it. Copy these into your national CSIRT's own reporting form. Nothing here files anything; the clock and the filing stay with you.

What to read next

  1. The insurance and Cyber Essentials evidence pack — the six-page pack this statement's Cyber Essentials rows reuse.
  2. How findings map to DORA and ISO 27001 — the crosswalk behind the ISO 27001 statement.
  3. Reporting an incident under NIS2 — the register the early-warning pre-fill reads from.

Was this article wrong?

If a procedure here does not match what you see, or a limit we described has changed, tell us and we will fix the page. Email us about this article, or see how to get help if you need an answer rather than a correction.

Everything in compliance evidence