Export Evidence Package for Your Auditor
Generate a complete, auditor-ready evidence bundle — PDFs, logs, and supporting documentation — in a single ZIP file.
4 min readUpdated 2026-02-01
exportauditorevidencePDFZIP
Overview
When your external auditor requests evidence, use the Export for Auditor workflow to package everything into a clean, organised bundle. No more manually gathering screenshots and spreadsheets.
Output: A ZIP file containing PDFs, log exports, and a manifest document Supported frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF, CIS Controls
Step 1: Navigate to the Export Workflow
- Open your project
- Go to Workflows → Export for Auditor
Step 2: Select the Audit Period
- Set Start Date and End Date for the evidence period
- For SOC 2 Type II, this is typically your 6–12 month audit window
- Nexxis will only include evidence collected within this window
Step 3: Choose Export Content
Select what to include in the bundle:
| Section | Description | Recommended |
|---|---|---|
| Control Evidence | All evidence mapped to controls | ✅ Always |
| Audit Trail | Who did what and when in Nexxis | ✅ Always |
| Policy Documents | Uploaded policy PDFs | ✅ If applicable |
| Exception Log | Approved exceptions with justification | ✅ Always |
| User Access Report | Current user permissions snapshot | ✅ For SOC 2 |
| Vendor Risk Register | Third-party risk assessments | For ISO 27001 |
Step 4: Format Options
- ZIP with PDFs — organised folders, one PDF per control (recommended)
- Excel summary — flat spreadsheet of all controls and their status
- JSON export — raw data for programmatic processing
Step 5: Generate & Download
- Click Generate Package
- Nexxis compiles the bundle (usually 1–3 minutes for large projects)
- You'll receive an email with the download link (valid for 7 days)
- Download and send to your auditor
Tips for a Smooth Audit
- Run the export 2 weeks before your audit window closes to give time to fill gaps
- Check the completeness indicator — Nexxis shows a coverage percentage before you export
- Name your ZIP with the period dates (e.g.,
AcmeCo_SOC2_2025-01-to-2025-12.zip) - Keep a copy in your internal document repository
What Auditors Can't See
The export package contains only the evidence you select. Auditors receive no access to your Nexxis account, other projects, or any data outside the selected period.