Sample evidence pack with control mapping
A 10-page working pack showing how a penetration-testing finding becomes audit evidence: the five-link finding-to-control chain, a mapping by finding class across SOC 2, ISO 27001:2022 and PCI DSS v4.0, the artefacts an assessor actually asks for, and a worksheet for your own findings. Every finding in it is synthetic.
Sample Evidence Pack with Control Mapping
Enter your work email to download the evidence pack showing how findings map to SOC 2 / ISO 27001 / PCI DSS controls.
Check your inbox
We've emailed you a link to download Sample Evidence Pack with Control Mapping.
The link expires in 48 hours. If it hasn't arrived in a few minutes, check your spam folder.
We couldn't send the download link. Please try again, or contact us and we'll email you Sample Evidence Pack with Control Mapping.
What's inside
Evidence mapped to your controls
SOC 2 Trust Services Criteria
Findings mapped to Security, Availability, Confidentiality criteria with evidence-gap identification.
ISO 27001:2022 Annex A
Per-finding Annex A control mapping showing which sub-controls are satisfied, partially satisfied, or gapped.
PCI DSS v4.0 Requirements
PCI-specific control mapping with SAQ alignment for merchants and service providers.
Evidence Artefact Samples
Sanitised samples of evidence artefacts — screenshots, logs, configuration excerpts — that accompany every finding.
Evidence pack under review
The sanitised evidence pack is being finalised from real engagement output. Your download will be available shortly after Yash's review and redlines are applied.
Need evidence for your compliance framework?
Every compliance framework has its own evidence requirements. Reach out and we'll show you how our deliverables map to yours.
Request a Scoping Call