Skip to main content

Export Evidence Package for Your Auditor

Generate a complete, auditor-ready evidence bundle — PDFs, logs, and supporting documentation — in a single ZIP file.

4 min readUpdated 2026-02-01
exportauditorevidencePDFZIP

Overview

When your external auditor requests evidence, use the Export for Auditor workflow to package everything into a clean, organised bundle. No more manually gathering screenshots and spreadsheets.

Output: A ZIP file containing PDFs, log exports, and a manifest document Supported frameworks: SOC 2, ISO 27001, HIPAA, NIST CSF, CIS Controls


Step 1: Navigate to the Export Workflow

  1. Open your project
  2. Go to WorkflowsExport for Auditor
Alternatively: from **Reports**, click **Generate Audit Package**

Step 2: Select the Audit Period

  1. Set Start Date and End Date for the evidence period
  2. For SOC 2 Type II, this is typically your 6–12 month audit window
  3. Nexxis will only include evidence collected within this window

Step 3: Choose Export Content

Select what to include in the bundle:

SectionDescriptionRecommended
Control EvidenceAll evidence mapped to controls✅ Always
Audit TrailWho did what and when in Nexxis✅ Always
Policy DocumentsUploaded policy PDFs✅ If applicable
Exception LogApproved exceptions with justification✅ Always
User Access ReportCurrent user permissions snapshot✅ For SOC 2
Vendor Risk RegisterThird-party risk assessmentsFor ISO 27001

Step 4: Format Options

  • ZIP with PDFs — organised folders, one PDF per control (recommended)
  • Excel summary — flat spreadsheet of all controls and their status
  • JSON export — raw data for programmatic processing

Step 5: Generate & Download

  1. Click Generate Package
  2. Nexxis compiles the bundle (usually 1–3 minutes for large projects)
  3. You'll receive an email with the download link (valid for 7 days)
  4. Download and send to your auditor

Tips for a Smooth Audit

  • Run the export 2 weeks before your audit window closes to give time to fill gaps
  • Check the completeness indicator — Nexxis shows a coverage percentage before you export
  • Name your ZIP with the period dates (e.g., AcmeCo_SOC2_2025-01-to-2025-12.zip)
  • Keep a copy in your internal document repository

What Auditors Can't See

The export package contains only the evidence you select. Auditors receive no access to your Nexxis account, other projects, or any data outside the selected period.