Skip to content

Compliance evidence

Every scan becomes auditor-ready evidence.

NANOTESTING maps every finding and every positive proof point to the control IDs your auditor cares about — across seven frameworks — and exports them as a per-framework evidence pack with a per-scan immutable snapshot. Evidence support for your auditor, not a certificate we are not allowed to issue.

Seven framework mappings, 93 controls, 223 signal mappings

ISO 27001:2022

Annex A controls

SOC 2

Trust Services Criteria

HIPAA

Security Rule safeguards

PCI DSS 4.0

requirement mappings

NIST CSF 2.0

function / category mappings

CIS Controls v8

safeguard mappings

OWASP Top 10 2021

category mappings

DORA

On request — the mapping engine is framework-agnostic.

Dual view per control

Each control shows BOTH findings (what is broken) and evidence (what is verified satisfied), with auditor-friendly green / red / grey coding — pass, fail, or not exercised this scan.

Per-scan immutable snapshot

Generated when each scan completes. Show “as of <scan date>, controls X, Y, Z were satisfied with this evidence.” The record stays stable across later scans, so audit windows have a fixed reference point.

Per-framework evidence pack

One-click PDF / CSV / JSON download per framework. Hand the right pack to the right auditor without exposing the six frameworks they have no business seeing.

Signed, independently verifiable

Every scan writes an append-only attestation, signed with Ed25519. The key lives in the scanning worker, never in the database, and the public key is published on this domain — so your auditor verifies our evidence without asking us for anything. Each record also chains to the previous one, so altering an old scan breaks every later link.

What ran, and what did not

The attestation names the tools that actually executed with their exact versions — not everything installed on the machine — and lists every check that failed or was skipped, with its error. A grade is withheld entirely when a scan produced no conclusive finding and checks failed: there is no evidence to support one.

Drill-through control → finding

Click any control row and land on the exact set of findings that contributed to its tally. “Where are the 3 mediums on PCI 6.2?” — one click answers it.

What teams use the evidence for

ISO 27001 readiness

Evidence that technical Annex A controls (cryptography, secure configuration, vulnerability management) are exercised and tracked over time.

SOC 2 preparation

Recurring proof for the Security and Availability Trust Services Criteria your auditor expects to see across the observation window.

Vendor security reviews

Answer the security questionnaire with a dated evidence pack instead of a spreadsheet of promises. Procurement reviewers stop bouncing the response.

HIPAA & PCI scoping

Map technical safeguards to the HIPAA Security Rule and PCI DSS 4.0 requirements that apply to your in-scope systems.

Compliance evidence support, not a certification or attestation. NANOTESTING gives your auditor a structured, control-mapped evidence pack and a per-scan immutable snapshot. Your auditor remains the source of truth for sign-off, framework interpretation, and the final report. We sit underneath the auditor, not above them.