How complete is our framework workspace?
Review organization-section progress, per-system data, and aggregated gaps without reducing the result to a single unsupported score.
Capability
Operate NIS2 and ISO 27001 framework records beside recurring calendar work, evidence, artifacts, gaps, documents, reports, and applicability decisions.
NIS2 workspace
ISO 27001 workspace
Compliance calendar
Occurrence evidence and artifacts
Operational need
The business can see what its stored framework record says, which work is due, what evidence is attached, and which operator decisions or gaps remain.
Operating signals
What you get
Where it starts
These examples enter the product surface that owns their state. They do not all become a case, ticket, owner, or shared evidence record automatically.
Review organization-section progress, per-system data, and aggregated gaps without reducing the result to a single unsupported score.
Record the ISO 27001 control decision, implementation state, justification, ownership, and supporting references in the statement of applicability.
Use the year calendar and report filters to inspect dated occurrences by status, category, framework, and owner.
Attach occurrence evidence and series-level artifact links while retaining the task, due date, status, owner, notes, and framework mappings.
Create a routine draft from a compliance task so the proposed automation can be reviewed and completed in the routine workflow.
Request control or framework suggestions, then explicitly add the links the operator accepts; suggestions are not treated as authoritative mappings.
How it works
The product path below names its inputs, decisions, controls, and output without implying the same lifecycle applies to every capability.
Complete organization sections, shared context, and per-system records in the relevant framework workspace.
Inspect section and system gaps; for ISO 27001, record control applicability, implementation state, justification, and ownership.
Create one-time or recurring task series with due dates, timezone-aware cadence, owner, category, and accepted framework links.
Add occurrence evidence and series artifacts, update status and notes, or draft a routine for repetitive evidence work.
Use progress, gap, calendar, compliance-document, and statement-of-applicability views according to the question being reviewed.
Product model
The diagrams separate framework working records from scheduled follow-through, show how evidence attaches to dated occurrences, and keep assistance and operator decisions distinct.
Framework workspace
Organization sections and per-system data feed progress and gap views. Generated policy text remains editable, while compliance reports reflect the stored framework record.
Calendar workflow
A task series defines cadence, owner, category, and framework links; dated occurrences carry due state, notes, and evidence for the period being reviewed.
Decision boundary
Assistance can suggest controls or frameworks. An operator explicitly accepts links, edits generated documents, and records applicability decisions and justification.
Evidence truth
Occurrence evidence and series artifact links support a task. A routine handoff begins as a draft, and none of these records is presented as independent certification.
What it includes
These parts participate in the workflow. The record shows what was used and why it mattered.
NIS2 workspace
Organization sections, shared context, per-system records, progress, gap summaries, editable generated policy documents, and compliance report payloads form the NIS2 working record.
NIS2 progress, organization sections, systems, gaps, documents, and reports
ISO 27001 workspace
The same working surfaces are joined by system classification and a control-level statement of applicability with summary and export.
ISO 27001 progress, metadata, gaps, documents, reports, and statement of applicability
Calendar
One-time and recurring task series produce year-based occurrences with category, owner, status, notes, timezone-aware cadence, and report filters.
Task series, occurrences, categories, and reports
Framework mapping
Operators can request suggested controls or frameworks and explicitly accept or remove the links attached to a task.
Suggestions and operator-managed framework links
Evidence and artifacts
Occurrence evidence and series artifact links can be added and removed without implying that an external link was independently verified.
Occurrence evidence and task artifact records
Routine handoff
A compliance task can create a routine draft for repetitive work; the draft remains separate from a completed or approved automation run.
Compliance task and routine draft
Control model
Integrations, AI assistance, routines, and agents use different permissions and records. The controls below describe this capability rather than a universal approval model.
Framework progress and gap views are calculated from stored organization and system records; they are not a certification claim.
Generated policy text remains editable and operator-owned, and assistance can be reprocessed without silently replacing an accepted decision.
Suggested control or framework mappings require an operator to add the link before it becomes part of a task.
Calendar evidence, artifacts, task state, framework links, and routine drafts are distinct records so one is not presented as proof of another.
The statement of applicability records the customer decision and justification; export preserves that recorded state for review.
Value over time
Record
Schedule
Attach
Next step
Book a walkthrough and I will map this workflow to the integrations and controls you already use.