Product

FutureCode Evidence Box: compliance evidence straight from your systems

Designed by our security engineers and certified auditors. It runs inside your network with no internet access. A person signs off the result, not an AI model.

Sample Evidence Box view, fictional data

What is Evidence Box?

FutureCode Evidence Box is an appliance that sits inside your network and works without internet access. It collects evidence from your systems in read-only mode, checks configurations and prepares a readiness report for NIS2 and ISO/IEC 27001 audits. An auditor reviews and signs off the result. It is built for companies getting ready for an audit or answering security questionnaires from customers.

// Context

More audits, evidence in too many places

A policy you cannot show in the system is not a control. It is a document about a control.

  • Several regulations at once

    NIS2, DORA, the AI Act and the CRA come with different deadlines and different questions, and the same team has to answer all of them. The next dates are listed below.

  • Evidence spread across systems

    Cloud configuration, the identity directory, workstations, code repositories, spreadsheets kept by control owners. Each one has its own export and its own admin.

  • Questionnaires from customers

    Customers ask about MFA, backups and suppliers. They want to see dated evidence, not a paragraph from a policy.

  • The same work before every audit

    Screenshots from last year prove nothing. Without a dated evidence index, collection starts from zero each time.

// Deadlines

Dates you will need evidence for

  1. NIS2 in Poland

    KSC Chapter 3 duties apply

    ISMS, risk management, incident handling, business continuity, supply chain and yearly management training.

    Dz.U. 2026 item 252 (opens in a new tab)
  2. AI Act

    High-risk AI under Annex III

    Duties for providers and deployers, for example in hiring and credit scoring.

    Regulation 2026/1744 (opens in a new tab)
  3. CRA

    Cyber Resilience Act fully applies

    Vulnerability reporting has applied since 11 September 2026. From this date, every product requirement applies.

    European Commission, CRA (opens in a new tab)
  4. NIS2 in Poland

    First KSC audit deadline for essential entities

    Applies to entities that were already essential on 3 April 2026. From this date the authority can also impose most fines.

    gov.pl, KSC dates (Polish) (opens in a new tab)

As of . Sources: Dz.U. 2026 item 252, gov.pl, Regulation (EU) 2026/1744, European Commission.

// Evidence sources

What Evidence Box collects and checks

Everything in read-only mode. Where the evidence is a human decision, Evidence Box sends a questionnaire to the control owner.

  1. 01Cloud

    Cloud configuration

    Account and service settings, collected with read-only access and checked by a configuration scanner.

    What a cloud audit looks at
  2. 02Identity

    Identity and access

    Accounts, roles, privileged permissions and MFA from the identity directory. The starting point for an access review.

  3. 03Endpoints

    Workstations and servers

    Configuration compared with CIS benchmarks, plus authenticated vulnerability scanning.

  4. 04Code

    Code repositories and dependencies

    Secrets committed to code, vulnerable dependencies and an SBOM for every repository.

  5. 05IaC

    Infrastructure as code

    Infrastructure definitions in your repositories checked for misconfiguration.

  6. 06People

    Answers from control owners

    Questionnaires about processes you cannot see in a configuration: business continuity, suppliers, training. Evidence Box follows up on missing answers.

// How it works

Six steps from connection to report

  1. Read-only connection

    Accounts with read-only permissions and a scope agreed up front. Evidence Box does not need internet access.

  2. Owner questionnaires

    Questions go to the people who own each process. Evidence Box sends reminders for missing answers.

  3. Checks and scanners

    Open-source scanners cover cloud configuration, IaC, secrets, dependencies and SBOMs, CIS benchmarks and authenticated vulnerability scanning.

  4. First pass and a second opinion

    An AI model makes the first assessment of each finding, and a second model from a different family checks it. Disagreements go to a person.

  5. Auditor review

    The auditor works through an exception queue. A second reviewer checks high and critical findings, and every decision carries a comment.

  6. Report and sealed evidence pack

    Every piece of evidence has a hash and a timestamp. After the auditor signs off, the pack is sealed and you receive the readiness report.

// What you get

A readiness report you can verify

At the end you receive a readiness report and an evidence pack with:

  • a maturity map for the NIS2 Article 21(2) areas,
  • a draft Statement of Applicability (SoA) for ISO/IEC 27001,
  • a gap view against NIS2 Article 21,
  • an evidence index with hashes and timestamps.

Findings are mapped to selected ISO/IEC 27001 and NIS2 requirements, including NIS2 in Poland (KSC). We keep extending the catalog.

Illustrative readiness report: maturity map, findings by severity and the auditor's sign-off

// The auditor's role

The auditor decides. We designed it that way.

Evidence Box prepares the work. Judgment and sign-off stay with a person.

Built to

  • Collect evidence from your systems in read-only mode
  • Check configurations with open-source scanners
  • Map findings to selected ISO/IEC 27001 and NIS2 requirements
  • Prepare a readiness report and evidence pack for the auditor to sign

Will not

  • Issue certificates or audit opinions
  • Replace the auditor or decide on the auditor's behalf
  • Run autonomous attacks
  • Change production systems: it proposes fixes, your team applies them
  • Send data outside your network

Evidence Box prepares a readiness assessment. Certification and formal audits stay with independent bodies: an accredited certification body for ISO/IEC 27001 and, for NIS2 in Poland, the formal KSC audit (Article 15) by an accredited body, at least two qualified auditors or a sectoral CSIRT. As of 24 September 2026.

// Foundations

Security built into the appliance

Audit data is a map of your weak spots, so these safeguards are on from first boot.

Data

  • Runs inside your network with no internet access; updates from physical media
  • Every engagement has its own encryption key
  • Personal identifiers, such as Polish PESEL (national ID) and NIP (tax) numbers, are masked before they are stored
  • Every piece of evidence has a hash and a timestamp; after the auditor signs off, the pack is sealed

Decisions and testing

  • A second reviewer for high and critical findings
  • A comment on every decision in the exception queue
  • Fixes are proposals only, with no changes to production systems
  • Active tests only on a test copy and only after signed rules of engagement (RoE)
  • No active testing in OT networks

// Two modes

For one engagement or for good

The same Evidence Box, two ways of working. They differ in who runs the review and what you can use the result for.

  1. 01Mode 1

    We run it during an engagement

    Our team connects Evidence Box, works through the exception queue and hands over a readiness report with the evidence pack. A good fit for a first pre-audit review.

    • Scope and date agreed before we start
    • Review and sign-off on our side
    • The report and evidence pack stay with you

    First step, 4-6 weeks

    First readiness report

    • Read-only connection and questionnaires for control owners
    • Exception queue reviewed by the auditor

    Key deliverable: a readiness report with an evidence index, signed off by the auditor

    IT consulting and IT audit
  2. 02Mode 2

    It stays with you for ongoing self-assessment

    Your team runs the next reviews between audits. This is a self-assessment, not an independent audit.

    • Your team starts each review
    • Updates from physical media, no internet
    • Formal audits are still done by an independent auditor
    Audits as a continuous process

// Who it is for

Designed for five industries

For companies with 50 to 1,000 people that have to demonstrate compliance with NIS2, DORA or their customers' requirements.

// FAQ

Questions about Evidence Box

Does our data leave the company?

No. Evidence Box runs inside your network with no internet access, and updates are installed from physical media. Personal identifiers, such as Polish PESEL (national ID) and NIP (tax) numbers, are masked before they are stored, and every engagement has its own encryption key.

Which standards does it support?

Findings are mapped to selected ISO/IEC 27001 and NIS2 requirements, including NIS2 in Poland (KSC). We keep extending the catalog and do not promise full coverage. In the demo we show which requirements it covers today. To see first what evidence each area needs, start with the NIS2 evidence matrix.

Who signs off the result?

A person. The auditor works through an exception queue that also receives every disagreement between the two models. A second reviewer checks high and critical findings, and every decision carries a comment. Our team includes certified auditors.

Is this a NIS2 audit or a certification?

Neither. Evidence Box prepares a readiness assessment, a review before the formal audit. ISO/IEC 27001 certificates come from accredited certification bodies. For NIS2 in Poland, the formal KSC audit under Article 15 is done by an accredited conformity assessment body, at least two qualified auditors or a sectoral CSIRT, and the auditor cannot be someone who performs tasks under Article 8 or Articles 9-13 of the act at the entity, or did so in the year before the audit. Details: who may perform a KSC audit.

As of 24 September 2026. Source: Dz.U. 2026 item 252, Article 15(2) and (2a).

Does Evidence Box change anything in our systems?

No. It collects data in read-only mode and proposes fixes without applying them. It runs active tests only on a test copy and only after signed rules of engagement (RoE). It runs no active tests in OT networks.

What does the demo look like?

It is a 30-minute online call. We walk through a run on a fictional company, from questionnaires through the exception queue to the sealed pack and the report. Nothing is connected to your systems. You can see the output right now in the sample readiness report.

A 30-minute demo on a fictional company

See how Evidence Box collects evidence and builds the report

Nothing gets connected to your systems. After the call you will know whether it is worth using before your audit.

Book a demo