What evidence is and why it matters
Marking a control asimplemented signals your intent, but it does not by itself raise your compliance score. Evidence is the supporting documentation or data that validates your claim. Without evidence, controls — especially required severity 5 controls — receive limited or no credit toward your risk score and framework readiness percentages.
Evidence is attached directly to individual controls. Each control can hold multiple evidence items, and together they form the documented proof of your security program.
Evidence types
SecurAtlas accepts the following types of evidence:| Type | Examples |
|---|---|
| Policies | Written security policies, procedures, and standards |
| Screenshots | Captured configurations, system settings, or tool outputs |
| Certificates | Compliance certificates, vendor attestations, or third-party assessments |
| Audit reports | Internal or external audit findings and remediation records |
| Automated findings | Data pulled automatically from connected integrations (such as AWS Security Hub or Microsoft Defender) |
Evidence expiry
Every evidence item has an expiry date. When evidence expires, it stops contributing to your compliance score and framework readiness percentages — as though the evidence were never there.- The default expiry window is 365 days from upload.
- Your workspace administrator can configure a different expiry window in workspace settings.
- Evidence approaching its expiry date is labeled expiring soon (within 30 days of expiry).
- Expired evidence is labeled expired and no longer counts toward your score.
Evidence statuses
| Status | Meaning |
|---|---|
| Active | Evidence is current and contributing to your score |
| Expiring soon | Evidence expires within 30 days; action recommended |
| Expired | Evidence has passed its expiry date and no longer contributes |