Evidence captured at the moment a control operates - owner-attributed, timestamped, sourced. Across ISO 27001:2022, NCSC CAF and SOC 2.
audit findings come from evidence gaps, not missing controls. When evidence is gathered reactively - the night before the audit - the result is recurring findings, scope creep and overrun.
The two columns below set the usual scramble against the alternative. When evidence is gathered the night before an audit, control owners are pulled off their work, spreadsheets are reconciled under pressure and the same findings recur from one cycle to the next.
The difference is timing: evidence captured at the moment a control operates - owner-attributed, timestamped and sourced - means the audit team arrives to a record that is already complete.
Auditors arrive, evidence is hunted. Spreadsheets reconciled the night before. Control owners scramble. Findings recur audit-to-audit because evidence was never continuous.
Evidence captured at the moment of control operation, not before an audit. Owners attributed, dates timestamped, sources referenced. Auditors arrive - the evidence is already there.
The five capabilities below are what make audit-readiness a by-product of day-to-day work rather than a project of its own: continuous evidence capture, native ISO 27001:2022 control coverage, one source of truth across frameworks, role-scoped auditor access and a tracker that holds prior findings to closure.
Every control operation timestamped, sourced and owner-attributed.
Annex A 93 controls + Statement of Applicability + risk register built in.
One platform across CAF, ISO, CE+ and SOC 2 - no duplicate evidence.
Role-scoped access for external auditors - no email attachments.
Findings from prior audits tracked to closure with linked evidence.
The figures below describe the scope a single platform holds at once: the 93 ISO 27001:2022 Annex A controls, the 14 NCSC CAF objectives and the five SOC 2 Trust Service Criteria - with evidence designed to be timestamped at the point each control operates.
The five stages below run from scoping the assessment boundary, through cross-framework mapping and continuous capture, to internal review and external sign-off. Each stage rests on the same underlying evidence, so nothing has to be re-gathered when the audit comes round.
Mapping is done at the control level, so one piece of evidence can answer several regimes at once. The grid below shows where that mapping reaches - from ISO 27001:2022 and NCSC CAF v4.0 to SOC 2 Type II, Cyber Essentials Plus, NIST CSF 2.0 and the ISO 27017 / 27018 cloud controls.
The same evidence base serves whoever needs to look at it. The three patterns below cover internal audit with evidence captured continuously, read-only access for external surveillance audits, and direct integration with a certification body for stage 1 and stage 2.
Self-assessment with evidence captured continuously in-platform.
Read-only auditor access during ISO / SOC 2 surveillance audits.
Direct integration for stage 1 + stage 2 audits.
We’ll walk a control-mapping against your next surveillance audit.