Generate audit-ready evidence
A design that has been checked is not yet evidence. This recipe turns it into the three artefacts an audit asks for — the report, the obligation register and the evidence pack — and shows what each one does and does not claim.
An auditor arrives holding an obligation, not a drawing. The question is never “is the network well designed” but “show me, for this clause, what you rely on and when it was true”. Synapse answers that from one model: the same zones, conduits and findings that drive the canvas are printed as a report, laid against each regulatory instrument, and exported row by row with the design version on every line.
What an auditor is handed
Three artefacts, each with a different job:
- The design report (PDF). The diagram, the asset inventory, zones and conduits, the risk assessment, findings with their basis, the firewall rule schedule, the countermeasure ledger and the acceptance test pack. The document of record.
- The obligation register. Every clause of IEC 62443, NIS2, the Network Code on Cybersecurity, the CRA, CER, the Cybersecurity Act and ISO 27001 that this design can speak to, with how it is evidenced. It prints inside the report and on the Audit workspace.
- The evidence pack(CSV). The register as rows, one per clause, with the design version on every row, for the auditor’s own working papers.
01Read the report before you export it
In the left navigation, under stage 6 Document the cyber requirements (CRS), open Requirements & reports. The page is the report, rendered live: the cover with its verdict, Findings with a basis column, Requirement coverage, Zones & conduits, the risk assessment and the SL posture.
The basis column is what makes the findings table auditable. Each line says whether it was checked against the model, twin-observed on a live run, or rests on an unconfirmed declaration. Without it every row would read as equally proven, and the first weak one taken apart in a review would take the strong ones with it.
02The obligation register
Scroll to Obligation register. One block per instrument. Each clause carries an evidence mode, and the modes are never mixed in a count:
- Derived from the design: the model proves it, traceably, and the row names the IEC 62443-3-3 or NIST SP 800-82 requirement that does so. These carry a status: Satisfied, Partial, Open, or Not yet derived.
- Attested by the organisation: you assert it; the register holds the pointer and the date. No status is printed, because the model cannot give one.
- Outside this tool: incident handling, training, continuity. Listed so the register states its own blind spots rather than implying coverage.
Below the instruments sits the Control crosswalk, the register turned inside out: one engineering control and every clause it answers, widest reach first. An open segmentation control that answers clauses in four instruments is the highest-value fix on the page, and this table is where you find it.
03Export the three artefacts
On the Reports toolbar open Export. Under Document, takePDF report for the design report and CRS traceability for the requirement-allocation matrix. The report prints the obligation register and the crosswalk after the findings, with the caveats beneath them.
For the evidence pack, go to stage 7 and open Audit. The Evidence packbutton downloads the register as CSV. It is built from exactly the rows the report prints, so the two can never disagree. Auditor access on the same toolbar grants a read-only seat with comment and export, which is usually what an external reviewer needs.
04Bind it to a sign-off
Above the report on the Reports page, Asset-owner approval records the ZCR 7 sign-off against the current design version, and Reviews records design, safety, security and operations reviews the same way. Record the approval, then export. The version printed on the report cover, on every evidence-pack row and on the approval now match, which is the fact an auditor checks first.
Why there is no percentage
A design-time model speaks to the network and segmentation clauses of each instrument and is silent on policy, training, continuity and incident handling. A product that prints “NIS2 · 94%” over that gap is manufacturing assurance, and an asset owner carries personal liability for the difference under Article 20. The register counts clauses by evidence mode and says so in words. That is a weaker-looking claim and a stronger one.
Recap
- Three artefacts: the design report, the obligation register and the evidence pack — from one model, never from three spreadsheets.
- Three evidence modes: derived, attested, outside this tool — printed separately, never summed.
- One version: the approval, the report cover and every pack row name the same design version, or the pack is stale.
To see how the register is proved rather than inferred, run the adversary on a live twin in The vendor-VPN stress test.
Produce your own pack
Open the Voltara reference, record an approval and export. The whole loop takes four minutes.
Open the studio