Product
FutureCode Evidence Box: compliance evidence straight from your systems
Designed by our security engineers and certified auditors. It runs inside your network with no internet access. A person signs off the result, not an AI model.
What is Evidence Box?
FutureCode Evidence Box is an appliance that sits inside your network and works without internet access. It collects evidence from your systems in read-only mode, checks configurations and prepares a readiness report for NIS2 and ISO/IEC 27001 audits. An auditor reviews and signs off the result. It is built for companies getting ready for an audit or answering security questionnaires from customers.
// Context
More audits, evidence in too many places
A policy you cannot show in the system is not a control. It is a document about a control.
Several regulations at once
NIS2, DORA, the AI Act and the CRA come with different deadlines and different questions, and the same team has to answer all of them. The next dates are listed below.
Evidence spread across systems
Cloud configuration, the identity directory, workstations, code repositories, spreadsheets kept by control owners. Each one has its own export and its own admin.
Questionnaires from customers
Customers ask about MFA, backups and suppliers. They want to see dated evidence, not a paragraph from a policy.
The same work before every audit
Screenshots from last year prove nothing. Without a dated evidence index, collection starts from zero each time.
// Deadlines
Dates you will need evidence for
NIS2 in Poland
KSC Chapter 3 duties apply
ISMS, risk management, incident handling, business continuity, supply chain and yearly management training.
Dz.U. 2026 item 252 (opens in a new tab)AI Act
High-risk AI under Annex III
Duties for providers and deployers, for example in hiring and credit scoring.
Regulation 2026/1744 (opens in a new tab)CRA
Cyber Resilience Act fully applies
Vulnerability reporting has applied since 11 September 2026. From this date, every product requirement applies.
European Commission, CRA (opens in a new tab)NIS2 in Poland
First KSC audit deadline for essential entities
Applies to entities that were already essential on 3 April 2026. From this date the authority can also impose most fines.
gov.pl, KSC dates (Polish) (opens in a new tab)
As of . Sources: Dz.U. 2026 item 252, gov.pl, Regulation (EU) 2026/1744, European Commission.
// Evidence sources
What Evidence Box collects and checks
Everything in read-only mode. Where the evidence is a human decision, Evidence Box sends a questionnaire to the control owner.
01Cloud
Cloud configuration
Account and service settings, collected with read-only access and checked by a configuration scanner.
What a cloud audit looks at02Identity
Identity and access
Accounts, roles, privileged permissions and MFA from the identity directory. The starting point for an access review.
03Endpoints
Workstations and servers
Configuration compared with CIS benchmarks, plus authenticated vulnerability scanning.
04Code
Code repositories and dependencies
Secrets committed to code, vulnerable dependencies and an SBOM for every repository.
05IaC
Infrastructure as code
Infrastructure definitions in your repositories checked for misconfiguration.
06People
Answers from control owners
Questionnaires about processes you cannot see in a configuration: business continuity, suppliers, training. Evidence Box follows up on missing answers.
// How it works
Six steps from connection to report
Read-only connection
Accounts with read-only permissions and a scope agreed up front. Evidence Box does not need internet access.
Owner questionnaires
Questions go to the people who own each process. Evidence Box sends reminders for missing answers.
Checks and scanners
Open-source scanners cover cloud configuration, IaC, secrets, dependencies and SBOMs, CIS benchmarks and authenticated vulnerability scanning.
First pass and a second opinion
An AI model makes the first assessment of each finding, and a second model from a different family checks it. Disagreements go to a person.
Auditor review
The auditor works through an exception queue. A second reviewer checks high and critical findings, and every decision carries a comment.
Report and sealed evidence pack
Every piece of evidence has a hash and a timestamp. After the auditor signs off, the pack is sealed and you receive the readiness report.
// What you get
A readiness report you can verify
At the end you receive a readiness report and an evidence pack with:
- a maturity map for the NIS2 Article 21(2) areas,
- a draft Statement of Applicability (SoA) for ISO/IEC 27001,
- a gap view against NIS2 Article 21,
- an evidence index with hashes and timestamps.
Findings are mapped to selected ISO/IEC 27001 and NIS2 requirements, including NIS2 in Poland (KSC). We keep extending the catalog.
// The auditor's role
The auditor decides. We designed it that way.
Evidence Box prepares the work. Judgment and sign-off stay with a person.
Built to
- Collect evidence from your systems in read-only mode
- Check configurations with open-source scanners
- Map findings to selected ISO/IEC 27001 and NIS2 requirements
- Prepare a readiness report and evidence pack for the auditor to sign
Will not
- Issue certificates or audit opinions
- Replace the auditor or decide on the auditor's behalf
- Run autonomous attacks
- Change production systems: it proposes fixes, your team applies them
- Send data outside your network
Evidence Box prepares a readiness assessment. Certification and formal audits stay with independent bodies: an accredited certification body for ISO/IEC 27001 and, for NIS2 in Poland, the formal KSC audit (Article 15) by an accredited body, at least two qualified auditors or a sectoral CSIRT. As of 24 September 2026.
// Foundations
Security built into the appliance
Audit data is a map of your weak spots, so these safeguards are on from first boot.
Data
- Runs inside your network with no internet access; updates from physical media
- Every engagement has its own encryption key
- Personal identifiers, such as Polish PESEL (national ID) and NIP (tax) numbers, are masked before they are stored
- Every piece of evidence has a hash and a timestamp; after the auditor signs off, the pack is sealed
Decisions and testing
- A second reviewer for high and critical findings
- A comment on every decision in the exception queue
- Fixes are proposals only, with no changes to production systems
- Active tests only on a test copy and only after signed rules of engagement (RoE)
- No active testing in OT networks
// Two modes
For one engagement or for good
The same Evidence Box, two ways of working. They differ in who runs the review and what you can use the result for.
01Mode 1
We run it during an engagement
Our team connects Evidence Box, works through the exception queue and hands over a readiness report with the evidence pack. A good fit for a first pre-audit review.
- Scope and date agreed before we start
- Review and sign-off on our side
- The report and evidence pack stay with you
IT consulting and IT auditFirst step, 4-6 weeks
First readiness report
- Read-only connection and questionnaires for control owners
- Exception queue reviewed by the auditor
Key deliverable: a readiness report with an evidence index, signed off by the auditor
02Mode 2
It stays with you for ongoing self-assessment
Your team runs the next reviews between audits. This is a self-assessment, not an independent audit.
- Your team starts each review
- Updates from physical media, no internet
- Formal audits are still done by an independent auditor
// Who it is for
Designed for five industries
For companies with 50 to 1,000 people that have to demonstrate compliance with NIS2, DORA or their customers' requirements.
Manufacturing and robotics
What applies in manufacturing and roboticsOT and IT stay separate: Evidence Box runs no active tests in OT networks.
Logistics and transport
What applies in logistics and transportMany sites, systems and suppliers. Evidence from every source lands in one index.
Energy and water
What applies in energy and water utilitiesAvailability comes first. Active tests only on a test copy and only after signed rules of engagement.
Finance and SaaS
What applies in finance and SaaSFinancial entities work under DORA, and SaaS vendors get security questionnaires from customers. Both need evidence with a date on it.
Telecommunications
What applies in telecommunicationsLarge infrastructure and many systems to review. Read-only collection, no changes in production.
// FAQ
Questions about Evidence Box
Does our data leave the company?
No. Evidence Box runs inside your network with no internet access, and updates are installed from physical media. Personal identifiers, such as Polish PESEL (national ID) and NIP (tax) numbers, are masked before they are stored, and every engagement has its own encryption key.
Which standards does it support?
Findings are mapped to selected ISO/IEC 27001 and NIS2 requirements, including NIS2 in Poland (KSC). We keep extending the catalog and do not promise full coverage. In the demo we show which requirements it covers today. To see first what evidence each area needs, start with the NIS2 evidence matrix.
Who signs off the result?
A person. The auditor works through an exception queue that also receives every disagreement between the two models. A second reviewer checks high and critical findings, and every decision carries a comment. Our team includes certified auditors.
Is this a NIS2 audit or a certification?
Neither. Evidence Box prepares a readiness assessment, a review before the formal audit. ISO/IEC 27001 certificates come from accredited certification bodies. For NIS2 in Poland, the formal KSC audit under Article 15 is done by an accredited conformity assessment body, at least two qualified auditors or a sectoral CSIRT, and the auditor cannot be someone who performs tasks under Article 8 or Articles 9-13 of the act at the entity, or did so in the year before the audit. Details: who may perform a KSC audit.
As of 24 September 2026. Source: Dz.U. 2026 item 252, Article 15(2) and (2a).
Does Evidence Box change anything in our systems?
No. It collects data in read-only mode and proposes fixes without applying them. It runs active tests only on a test copy and only after signed rules of engagement (RoE). It runs no active tests in OT networks.
What does the demo look like?
It is a 30-minute online call. We walk through a run on a fictional company, from questionnaires through the exception queue to the sealed pack and the report. Nothing is connected to your systems. You can see the output right now in the sample readiness report.
A 30-minute demo on a fictional company
See how Evidence Box collects evidence and builds the report
Nothing gets connected to your systems. After the call you will know whether it is worth using before your audit.
Book a demo