Certification

Evidence Requirements

Each Continuum/AI control specifies evidence required to demonstrate compliance. This section defines evidence types, validity periods, and retention requirements.

Evidence types

TypeDescriptionValidity
Policy DocumentApproved organizational policy12 months
Configuration ExportSystem configuration demonstrating control12 months
Architecture DiagramVisual representation of system designUntil material change
Log SampleRepresentative logs demonstrating control operation30 days
Scan ReportAutomated assessment results90 days
Test ResultsManual or automated test execution6 months
Audit ReportIndependent assessment findings12 months

Evidence by control

Each control specifies required evidence in its definition. Assessors evaluate whether evidence demonstrates actual compliance rather than merely documented intention.

Configuration exports must reflect deployed configurations. Log samples must show actual logging behavior. Test results must demonstrate control effectiveness.

Inherited controls

Organizations with existing certifications may inherit applicable controls when evidence demonstrates equivalence. Inheritance documentation specifies the source certification, control mapping, and evidence of equivalence.

Evidence retention

Evidence supporting certification shall be retained for the duration of certification validity plus minimum 12 months following certification expiration.

Regulatory requirements may mandate longer retention. Organizations must identify applicable requirements and retain evidence accordingly.

Previous
Risk profiles