TroutTrout

Example Evidence Pack for a Regulator Process

A walkthrough for assembling what a regulator, auditor, or funding body asks for, using data Access Gate already holds rather than a documentation project.

5 min read · Last updated 2026-08-21

This document walks through an example flow for assembling a compliance evidence pack, across four steps: scope, generate, fill the gaps, and hand over.

Treat it as a template for inspiration rather than a procedure to follow to the letter. Copy it, cut what does not apply to you, add the checks your site actually requires, and make it your own.

The example assembles a pack for a water utility ahead of a state review. The same sequence applies to a NERC CIP audit, a NIS2 supervisory request, a CMMC assessment, or a grant application that asks you to evidence your posture.

Step 1: Scope the request

Before generating anything, work out what is actually being asked.

  • Identify the framework or requirement behind the request. NY DOH Part 5 and DEC 6 NYCRR Parts 616, 650 and 750 for a New York water system, NERC CIP for a registered entity, NIS2 Article 21 for an EU essential or important entity.
  • Identify the site or sites in scope. Evidence is per site.
  • Identify the period covered. A point-in-time snapshot and a twelve-month change history are different asks.
  • Confirm who is receiving it and in what form.

Step 2: Generate what the system already holds

  • Confirm the site exists in Access Gate with its name, location, and scope recorded.
  • Confirm a contact holds the Cybersecurity Auditor role for that site, which is what allows assessments to be run against it.
  • Create the assessment: pick the framework, the enclaves in scope, and the audit team.
Creating an assessment against a framework, scoped to enclaves
Creating an assessment against a framework, scoped to enclaves

Controls that Access Gate enforces directly are marked in place automatically, with the supporting data attached. In practice that covers a large share of what is asked: personnel and asset inventory, security event logging, MFA, least-privilege access, and segmentation.

Framework controls auto-filled with live Access Gate data
Framework controls auto-filled with live Access Gate data

Alongside the assessment, pull the supporting exhibits:

  • The asset inventory, answering what is on the network.
  • The permission matrix per enclave, answering who can reach what.
  • The enclave change history for the period, answering what changed and who changed it.
  • Confirmation that logs reached your SIEM, answering whether anyone was watching.
Enclave change history for the period under review
Enclave change history for the period under review

Step 3: Fill the gaps honestly

The controls Access Gate does not enforce are still yours to answer.

  • Complete the remaining controls with a description and an attachment each.
  • Cover the things no network control produces: physical security, staff training records, your incident response plan, backup and restore testing, contracts with suppliers.
  • Where a control is not met, say so and record the compensating control or the remediation plan.

Attach your incident response procedure here, along with your access review records. Both are commonly requested, and both are far more convincing as a written procedure with evidence of it being run than as a policy statement.

Step 4: Submit, export, and hand over

  • Submit the finalised assessment.
  • Generate the PDF report and export it.
  • Assemble the pack: the report, the exhibits from Step 2, and the supporting documents from Step 3.
  • Keep a copy of exactly what you sent and when.
The exported assessment report
The exported assessment report

Note the date the data was current. Evidence ages, and a pack assembled in March does not describe your posture in October.

See Creating and Exporting a Risk Assessment Report for the full workflow.

What we have achieved

Across the four steps we have:

  • Scoped the request to a framework, a site, and a period, rather than preparing for everything.
  • Generated the controls Access Gate already evidences, auto-filled with live data.
  • Documented the rest honestly, including the gaps and what is being done about them.
  • Exported a dated pack, with a record of what was handed over.

The work was assembly, not authorship. That is the difference between compliance as an annual project and compliance as a by-product of running the controls you already run.