Evidence assessment
Your evidence, organised against every requirement
Attach evidence to the requirements it supports and organise it against curated, versioned control libraries — 10 frameworks, 523 requirement-level criteria — so you always know what evidence you hold, and where.
How it works
From stored files to a requirement-level answer
Most tools collect and organise files, then leave the judgement of 'is this actually enough?' to you — on the day of the audit.
Per-requirement reasoning
Byte-verified citations
Coverage vs. sufficiency
Where it sits
Assessment is the fourth link in the chain
Assessment does not stand alone. It reads the evidence you have already organised, and its determinations feed readiness, blockers and review downstream.
- 1Scope
The applicable requirement set for your framework and scope.
- 2Applicable requirements
A fixed denominator — every in-scope requirement counts.
- 3Evidence
You attach and own evidence; ownership and expiry are tracked.
- 4Evidence assessment
The evidence is read against each requirement for sufficiency.
- 5Determination
A requirement-level verdict with byte-verified citations.
- 6Blocker
Negative findings surface as explicit blockers, not averages.
- 7Remediation
Track the fix; reassessment — not a checkbox — resolves it.
- 8Review (R0–R3)
Controlled human review with recorded provenance.
- 9Finalisation
A signed, scope-pinned readiness conclusion.
- 10Report / export
Readiness report, evidence index, SoA, audit ZIP + SHA-256.
- 11Lifecycle & reassessment
Evidence expires/changes → affected requirements reopen.
Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.
What you see
One requirement, assessed
Take a single access-control requirement with two evidence items attached. Here is what the assessment step actually produces.
Evidence, organised against the requirement
The requirement shows the two evidence items mapped to it — an access-control policy and an access review export — each with its owner and expiry. You can see, at a glance, that the requirement has evidence attached and whether those items are still in date. Whether that evidence is sufficient is the judgement Netallion is built to make on an assessed engagement.
Why it's different
Sufficiency, not collection
Set-aware, per dimension
Traceable to the exact bytes
What comes out
A determination per requirement
A single evidence register per tenant, organised against each framework’s catalogue, with ownership and expiry visibility on every item — ready to hand to a reviewer or export for an audit.
Where the boundary sits
Evidence organisation is status and hygiene — collection, ownership, expiry. On its own it is not an assessment of whether the evidence satisfies a requirement.
Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.
See a requirement assessed end to end
Book a walkthrough and follow one requirement from its evidence to a readiness position — with the boundary clearly drawn.