Statements of evidence, and sharing one with an auditor
How the NIS2, ISO 27001, GDPR, DORA and Cyber Essentials statements are built, what covered/gap/not covered mean, and how to send an auditor a read-only link that expires.
An auditor rarely asks "are you compliant" in one sentence. They ask, control by control: what proves this, when was it last checked, and can I verify it myself. Compliance > Statements answers exactly that, one page per framework, built from the same live checks and records the rest of the console already keeps.
The five frameworks
| Framework | Built from |
|---|---|
| NIS2 Art. 21 | The same conformity checks the NIS2 conformity checklist already runs. |
| ISO 27001 Annex A | The same NIS2 evidence, reprojected through the NIS2 → ISO 27001 crosswalk — never measured a second way, so the two can never disagree. Covers the Annex A controls that crosswalk names, not the full Annex A. |
| GDPR Art. 32 | Encryption (vaulted credentials), the hash-chained audit log's integrity, your backups attestation, and DPIA records on file. |
| DORA | Your ICT third-party register and the concentration-risk view. |
| Cyber Essentials | Two answers straight from the insurance evidence pack (privileged-account MFA and endpoint protection); the rest — firewalls, secure configuration, patch management — read not covered, honestly, because this platform does not measure them yet. |
See How findings map to DORA and ISO 27001 for the underlying crosswalk, and The insurance and Cyber Essentials evidence pack for the pack this page's Cyber Essentials rows reuse.
What each status means
- Covered
- A live check or record proves this control, and the evidence — a count and when it was checked — is shown.
- Gap
- Measured, and the answer is a real gap: partial coverage, a broken chain, or evidence that exists but does not satisfy the control.
- Not covered
- This platform has no data source for this control at all. Always named, never silently dropped from the page.
Sharing a statement with an auditor
Choose Share with auditor
On the statement you want to send.
Enter your name and an expiry
Up to 180 days out. The link stops working the moment it expires, or immediately if you revoke it.
Copy the link
It opens a read-only page with no login required — built for someone who should never need a console account.
Manage existing links from the same page: each one shows who shared it, its expiry, and a Revoke button. Revoking takes effect immediately — the link then reads exactly like one that never existed, so there is nothing for someone probing links to learn either way.
The NIS2 early-warning pre-fill
On a NIS2 incident that already has an early-warning draft (see Evidence-bound drafts), the incident page shows a pre-fill panel: severity, cross-border impact, affected services, and the Article 23 deadlines, read straight from that draft's own typed values — free text is left out, the same way the draft itself excludes it. Copy these into your national CSIRT's own reporting form. Nothing here files anything; the clock and the filing stay with you.
What to read next
- The insurance and Cyber Essentials evidence pack — the six-page pack this statement's Cyber Essentials rows reuse.
- How findings map to DORA and ISO 27001 — the crosswalk behind the ISO 27001 statement.
- Reporting an incident under NIS2 — the register the early-warning pre-fill reads from.