An evidence pack is the document you hand to a customer, an insurer or an auditor who asks "show me your controls for ISO 27001" or "how do you meet NIS2". Instead of answering the question from memory, Venvera generates a PDF from your live control record at the moment you ask for it: every requirement of the frameworks you pick, its current status, the library controls and approved policies behind it and, if you choose, the latest evidence for each requirement listed by name, source and date. You publish the pack on your Trust Center like any other document and share it through access requests.
What is in a pack
| Part | What it shows | Where it comes from |
|---|---|---|
| Cover | Your organisation, the frameworks covered, the generation date, and the headline: applicable requirements implemented, as a count and a percentage. | The requirement record |
| Summary | Requirements, implemented, in progress, and either the number of controls or the number of evidence items listed. | Requirement coverage, control links |
| One section per framework | A table with every requirement in the catalogue, its status (Implemented, In progress, Open or Not applicable), the library controls linked to it, the approved policies that back it and, when enabled, up to three of the latest current evidence items with their source (uploaded, system or platform), date and validity. | Controls, policies, evidence |
| Basis of preparation | A note that statuses are the organisation's own assertions and automated checks, not an audit opinion, and that evidence files are not included. | Fixed text |
A requirement counts as implemented when it is marked implemented or when a linked library control is implemented, so a control you proved once shows up under every framework it satisfies. That is the same rule the compliance dashboards use.
Generating a pack
The Evidence packs card sits under the published documents. It lists the packs you already have with their frameworks and generation date.
Only frameworks enabled for your organisation are offered. Pick one for a framework-specific request, or several for a customer who asks about your whole programme.
List the latest evidence per requirement adds the evidence column. Rebuild when an access request is approved makes Venvera regenerate the pack at the moment you approve a request that includes it, so the requester always opens today's position.
The pack is built, stored encrypted like any other tenant file, and published under the Report category. It appears on your public trust page and in the document list of every access request from then on.
Keeping a pack current
A pack is a snapshot. Press Rebuild at any time to regenerate it from the current record; the document keeps its identity, so access grants that already include it start serving the new version, and the previous PDF is retired. With Rebuild when an access request is approved switched on you do not need to remember: approving a request rebuilds the pack first and then sends the link.
Where it connects
- Control library: the controls and their requirement links are what the pack reports; link a control to every framework it satisfies and it appears in each section.
- Evidence: only evidence with status current is listed; expired evidence drops out of the pack on the next rebuild.
- Board reports: the same report kit and the same rules, addressed to the board rather than to a third party.