Evidence assessment

Your evidence, organised against every requirement

Attach evidence to the requirements it supports and organise it against curated, versioned control libraries — 10 frameworks, 523 requirement-level criteria — so you always know what evidence you hold, and where.

How it works

From stored files to a requirement-level answer

Most tools collect and organise files, then leave the judgement of 'is this actually enough?' to you — on the day of the audit.

Per-requirement reasoning

Each evidence item is mapped to the requirements it supports, so your evidence is structured requirement by requirement rather than piled into a shared folder.

Byte-verified citations

Every evidence item keeps its provenance — what it is, who owns it, and when it expires — so a reviewer can always trace a claim back to its source file.

Coverage vs. sufficiency

You can see, at a glance, which requirements have evidence attached and which are still bare — coverage across the whole framework catalogue.

Where it sits

Assessment is the fourth link in the chain

Assessment does not stand alone. It reads the evidence you have already organised, and its determinations feed readiness, blockers and review downstream.

  1. 1Scope

    The applicable requirement set for your framework and scope.

  2. 2Applicable requirements

    A fixed denominator — every in-scope requirement counts.

  3. 3Evidence

    You attach and own evidence; ownership and expiry are tracked.

  4. 4Evidence assessment

    The evidence is read against each requirement for sufficiency.

  5. 5Determination

    A requirement-level verdict with byte-verified citations.

  6. 6Blocker

    Negative findings surface as explicit blockers, not averages.

  7. 7Remediation

    Track the fix; reassessment — not a checkbox — resolves it.

  8. 8Review (R0–R3)

    Controlled human review with recorded provenance.

  9. 9Finalisation

    A signed, scope-pinned readiness conclusion.

  10. 10Report / export

    Readiness report, evidence index, SoA, audit ZIP + SHA-256.

  11. 11Lifecycle & reassessment

    Evidence expires/changes → affected requirements reopen.

Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.

What you see

One requirement, assessed

Take a single access-control requirement with two evidence items attached. Here is what the assessment step actually produces.

Product screenshot
A requirement-level determination with its verdict, the evidence it read, and byte-verified citations back to the source.

Evidence, organised against the requirement

The requirement shows the two evidence items mapped to it — an access-control policy and an access review export — each with its owner and expiry. You can see, at a glance, that the requirement has evidence attached and whether those items are still in date. Whether that evidence is sufficient is the judgement Netallion is built to make on an assessed engagement.

Why it's different

Sufficiency, not collection

Set-aware, per dimension

A requirement can carry several evidence items at once; Netallion keeps them organised together against that requirement rather than judging one file in isolation.

Traceable to the exact bytes

Every evidence item keeps its provenance, so a reviewer can always open the source file a claim was based on.

What comes out

A determination per requirement

A single evidence register per tenant, organised against each framework’s catalogue, with ownership and expiry visibility on every item — ready to hand to a reviewer or export for an audit.

Where the boundary sits

Evidence organisation is status and hygiene — collection, ownership, expiry. On its own it is not an assessment of whether the evidence satisfies a requirement.

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. Where the boundary sits.

See a requirement assessed end to end

Book a walkthrough and follow one requirement from its evidence to a readiness position — with the boundary clearly drawn.