Cyber Health Score

Governance and assurance

Compliance Evidence overview

Generated compliance-oriented evidence summaries for audit preparation.

Audience
Analysts and above
Required role
Analyst
Plan availability
All plans
Last reviewed

Compliance Evidence is a generated summary that assembles posture, findings, remediation, and audit signals into one compliance-oriented view. It supports audit and compliance preparation. It is not compliance certification and does not guarantee that your organisation meets any standard or framework.

Open it from ReportsCompliance Evidence (/dashboard/reports/evidence).

Purpose

Use Compliance Evidence when you need a structured snapshot of your workspace's security posture evidence for stakeholders, auditors, or internal assurance conversations. The report draws on live workspace data rather than uploaded files alone.

How it relates to other assurance areas

Product areaPurpose
Governance & ControlsTrack governance readiness and control-related workflows in the dashboard
Evidence VaultStore and review tenant-managed evidence records and attachments
Compliance EvidenceGenerated compliance-oriented summary from posture, findings, remediation, and audit signals
Configurable ReportsBuild custom stakeholder reports that can link approved evidence

Compliance Evidence complements the Evidence Vault. Upload policies, screenshots, and supporting documents in the Evidence Vault; use Compliance Evidence for an assembled posture and activity summary.

What the report includes

The generated view typically summarises:

  • workspace scope (domains and assets in scope)
  • posture score and confidence signals
  • finding counts by severity and workflow status
  • remediation progress (overdue, in progress, recently resolved)
  • verification outcomes where available
  • exposure priority items from recent scans
  • recent significant audit actions in the workspace

Analysts and above can view the report. Sharing controls follow the same role rules as other report sharing features in your workspace.

Supported workflow

  1. Ensure domains are verified and scans are current.
  2. Review and triage findings and remediation in the dashboard.
  3. Open Compliance Evidence to review the assembled summary.
  4. Optionally share the report using approved report-sharing controls where your plan supports it.
  5. Upload supporting material to the Evidence Vault when auditors need original documents.

Limitations

  • The report reflects data available in your workspace at generation time.
  • It does not replace professional audit advice or formal certification.
  • It does not provide penetration testing, malware scanning, or real-time monitoring.
  • Coverage is limited to the external posture checks Cyber Health Score runs; it does not detect every possible vulnerability.

Disclaimer

This report provides security posture evidence to support audit and compliance preparation. It is not a certification or guarantee of compliance.

Return to the documentation home to browse all topics.

Back to documentation