Skip to content
OnTrackio

Methodology

How we label compliance evidence

Every control mapping OnTrackio prints, in the product and on this site, carries one of four evidence-class labels. This page is the methodology: what each class means, what it looks like in practice, and how to read it. No tool makes you compliant, including ours; the labels exist so nothing we hand you ever implies otherwise.

The four classes

ITAM-native evidence

What it means. The platform produces full evidence for this slice directly from live data.

Example. MFA enrolment counts per user, the reconciled asset register, offboarding completion records with dates.

How to read it. You can hand this to an auditor as primary evidence for the mapped slice.

ITAM hygiene floor

What it means. The platform contributes a necessary baseline the control builds on; your programme produces the rest.

Example. A current inventory underneath a risk-analysis policy: the policy is yours, the register it stands on is ours.

How to read it. Treat it as a prerequisite met, not a control satisfied.

ITAM proxy

What it means. The platform contributes a coverage metric that correlates with the control, not direct control evidence.

Example. Patch-freshness dates as a proxy for vulnerability handling: they show the loop runs, not that it runs correctly.

How to read it. An assessor will treat this as partial. So do we, in print.

Outside ITAM scope

What it means. This evidence has to come from your own programme; asset data does not meaningfully contribute.

Example. Business continuity and crisis management under NIS2: nothing in an asset register demonstrates it.

How to read it. If a vendor claims an ITAM tool covers this, ask them to show the artifact.

Why this exists

The compliance-tool market rewards the checkmark matrix: every framework, every control, green across the board. We relabelled our own NIS2 evidence pack away from that pattern after concluding the marketing was writing cheques the evidence could not cash, and published the honest version instead. The result is that of the ten NIS2 Article 21(2) measures, we claim native evidence for three, a floor for four, a proxy for two, and nothing for one, and the full mapping is public, including exactly what you still produce yourself.

The same discipline applies to our own posture: what we hold, what is targeted, and what is pending is stated plainly on the security page, and the SOC 2 crosswalk carries per-criterion contribution notes rather than a green wall. If you are comparing vendors, take this page's test with you: ask each one which controls their evidence does NOT cover. The honest ones have an answer ready.

Frequently asked questions

Why label evidence at all? No competitor does.

Because the alternative is the industry default: a coverage matrix with a checkmark in every row, which survives exactly until an auditor reads it. An overclaimed evidence pack transfers risk to the customer, who walks into an audit believing a sub-control is handled when it is not. Labels move that discovery from the audit to the sales conversation, where it belongs.

Where do the labels actually appear?

In the product's generated evidence PDFs, on every mapped sub-control, and publicly on the NIS2 Article 21(2) checklist page, which mirrors the same classification the product prints. What you show an auditor and what our marketing says are the same taxonomy on purpose.

Who decides which class a control gets?

We do, and we publish the reasoning per sub-control so you can disagree. The classification followed two independent regulatory review passes against the directive text and the Implementing Regulation, and it has moved in the honest direction over time: where a claim could not be defended, it was downgraded and the change shipped publicly.

Is OnTrackio itself certified against these frameworks?

Not yet, and we say so rather than hiding it: our own SOC 2 and ISO 27001 attestations are targeted, not held, and the current posture is public on the security page. A compliance-evidence vendor that overclaims its own posture is telling you how it will label yours.

Read a labelled evidence pack yourself

Bring your framework to a 30-minute demo and we will generate the pack live, labels and gaps included.