Evidence, not intent
Every control row carries the artifact the auditor requests — the export, the report, the log window — because a control that ran all period but produced nothing still fails the test.
54 endpoint controls, each with the artifact an auditor actually requests, plus a 15-item evidence register and a full mapping to SOC 2, ISO/IEC 27001:2022 Annex A and NIST SP 800-53.
EXCEL
Editable Excel checklistReady after form submission
A control list organised around the evidence request rather than the control name, so preparation runs backwards from the audit date instead of forwards from a policy.
Every control row carries the artifact the auditor requests — the export, the report, the log window — because a control that ran all period but produced nothing still fails the test.
Which artifact, how many rows, what observation window, and how to produce it. Use it to work backwards from the audit date.
Each domain maps to SOC 2 Trust Services Criteria, ISO/IEC 27001:2022 Annex A clause numbers and NIST SP 800-53 Rev.5, so one checklist serves both audits.
Endpoint controls rarely fail an audit because they were absent. They fail because coverage was measured against the managed device list instead of the real device population, because nobody exported the artifact inside the observation window, or because the evidence sat on a laptop that had already been reissued. Verizon’s 2025 Data Breach Investigations Report found 46% of infostealer-compromised systems holding corporate logins were unmanaged devices — the population most coverage figures quietly leave out.
The telemetry these controls depend on, how compliance checking is automated, and the product page that exports the evidence.