Capability

Compliance evidence

Operate NIS2 and ISO 27001 framework records beside recurring calendar work, evidence, artifacts, gaps, documents, reports, and applicability decisions.

NIS2 workspace

ISO 27001 workspace

Compliance calendar

Occurrence evidence and artifacts

Operational need

Compliance work needs honest source records for framework context and gaps, plus a live calendar where owners, due dates, mappings, evidence, and artifacts remain connected.

The business can see what its stored framework record says, which work is due, what evidence is attached, and which operator decisions or gaps remain.

Operating signals

  • Controls exist, but evidence readiness is not visible until review preparation starts.
  • Framework questionnaires, system data, applicability decisions, calendar tasks, evidence, and artifacts are often collapsed into one vague status.
  • Leadership can see a requirement, but not the operational status, owner, or evidence behind it.

What you get

NIS2 workspaceISO 27001 workspaceCompliance calendarOccurrence evidence and artifactsGap trackingStatement of applicabilityEditable documents and reports

Where it starts

Common starting points.

These examples enter the product surface that owns their state. They do not all become a case, ticket, owner, or shared evidence record automatically.

How complete is our framework workspace?

Review organization-section progress, per-system data, and aggregated gaps without reducing the result to a single unsupported score.

Which requirements need an applicability decision?

Record the ISO 27001 control decision, implementation state, justification, ownership, and supporting references in the statement of applicability.

What is due, overdue, or completed this period?

Use the year calendar and report filters to inspect dated occurrences by status, category, framework, and owner.

What supports this calendar occurrence?

Attach occurrence evidence and series-level artifact links while retaining the task, due date, status, owner, notes, and framework mappings.

Can repetitive follow-up become operational work?

Create a routine draft from a compliance task so the proposed automation can be reviewed and completed in the routine workflow.

Can assistance help map a task without making the decision for us?

Request control or framework suggestions, then explicitly add the links the operator accepts; suggestions are not treated as authoritative mappings.

How it works

How work moves.

The product path below names its inputs, decisions, controls, and output without implying the same lifecycle applies to every capability.

  1. 01

    Build framework context

    Complete organization sections, shared context, and per-system records in the relevant framework workspace.

  2. 02

    Review gaps and applicability

    Inspect section and system gaps; for ISO 27001, record control applicability, implementation state, justification, and ownership.

  3. 03

    Schedule follow-through

    Create one-time or recurring task series with due dates, timezone-aware cadence, owner, category, and accepted framework links.

  4. 04

    Attach proof

    Add occurrence evidence and series artifacts, update status and notes, or draft a routine for repetitive evidence work.

  5. 05

    Report the recorded state

    Use progress, gap, calendar, compliance-document, and statement-of-applicability views according to the question being reviewed.

Product model

Compliance operating model.

The diagrams separate framework working records from scheduled follow-through, show how evidence attaches to dated occurrences, and keep assistance and operator decisions distinct.

Framework workspace

Context, gaps, documents, and reports share a source record.

Organization sections and per-system data feed progress and gap views. Generated policy text remains editable, while compliance reports reflect the stored framework record.

Diagram showing organization context and system data flowing into framework sections, gap analysis, editable policy documents, progress, and reports.

Calendar workflow

Recurring obligations become dated operating work.

A task series defines cadence, owner, category, and framework links; dated occurrences carry due state, notes, and evidence for the period being reviewed.

Diagram showing a recurring compliance task series producing dated occurrences with owners, status, notes, and evidence.

Decision boundary

Suggestions do not become mappings by themselves.

Assistance can suggest controls or frameworks. An operator explicitly accepts links, edits generated documents, and records applicability decisions and justification.

Diagram separating generated suggestions from operator-accepted framework links, document edits, and applicability decisions.

Evidence truth

Task state, evidence, artifacts, and automation drafts remain distinct.

Occurrence evidence and series artifact links support a task. A routine handoff begins as a draft, and none of these records is presented as independent certification.

Diagram showing a compliance task linked separately to occurrence evidence, artifact links, a routine draft, and reporting views without claiming certification.

What it includes

What the record shows.

These parts participate in the workflow. The record shows what was used and why it mattered.

NIS2 workspace

Organization sections, shared context, per-system records, progress, gap summaries, editable generated policy documents, and compliance report payloads form the NIS2 working record.

NIS2 progress, organization sections, systems, gaps, documents, and reports

ISO 27001 workspace

The same working surfaces are joined by system classification and a control-level statement of applicability with summary and export.

ISO 27001 progress, metadata, gaps, documents, reports, and statement of applicability

Calendar

One-time and recurring task series produce year-based occurrences with category, owner, status, notes, timezone-aware cadence, and report filters.

Task series, occurrences, categories, and reports

Framework mapping

Operators can request suggested controls or frameworks and explicitly accept or remove the links attached to a task.

Suggestions and operator-managed framework links

Evidence and artifacts

Occurrence evidence and series artifact links can be added and removed without implying that an external link was independently verified.

Occurrence evidence and task artifact records

Routine handoff

A compliance task can create a routine draft for repetitive work; the draft remains separate from a completed or approved automation run.

Compliance task and routine draft

Control model

Controls stay specific to the workflow.

Integrations, AI assistance, routines, and agents use different permissions and records. The controls below describe this capability rather than a universal approval model.

Framework progress and gap views are calculated from stored organization and system records; they are not a certification claim.

Generated policy text remains editable and operator-owned, and assistance can be reprocessed without silently replacing an accepted decision.

Suggested control or framework mappings require an operator to add the link before it becomes part of a task.

Calendar evidence, artifacts, task state, framework links, and routine drafts are distinct records so one is not presented as proof of another.

The statement of applicability records the customer decision and justification; export preserves that recorded state for review.

Value over time

Product path for Compliance.

Record

Maintain framework context

Answers, system data, gaps, documents, and applicability decisions have explicit homes.

Schedule

Create dated compliance work

Task series produce occurrences with cadence, owner, status, notes, and framework links.

Attach

Retain deliberate evidence

Operators add occurrence evidence and series-level artifact links for review.

Next step

Want to see compliance on your stack?

Book a walkthrough and I will map this workflow to the integrations and controls you already use.