concept
Compliance Agent
The compliance loop end to end — select a framework, run the agent, read control states, upload or sync evidence, automate re-runs, and export a readiness report.
The Compliance Agent prepares you for an audit — it does not pass one for you. You pick the frameworks that matter, run a compliance assessment, and the agent maps every framework control to a status: passing, failing, needs action, not checked, or excluded. Where a control needs evidence you cannot prove by testing, you upload a document or sync it from a provider, then run the agent again to review it and update the control.
This page walks the whole loop end to end. If you own SOC 2, ISO 27001, NIST CSF, HIPAA, or PCI DSS readiness, read it once — the order of the steps matters, and the boundary between "readiness evidence" and "auditor opinion" matters more.
How compliance works, end to end
Compliance readiness is a loop, not a one-time scan. You give the agent a framework, it tells you where you stand control by control, you close the gaps it flags with evidence, and you run it again so it can confirm the evidence and move the controls. Repeat until the matrix reflects reality, then export the readiness report.
Step 1 — Select the framework
Framework selection happens per scope — during onboarding, or any time in scope settings. Pick the frameworks each environment genuinely needs to support: SOC 2, ISO 27001, NIST CSF, HIPAA, or PCI DSS. Adding more frameworks does not make you "more compliant"; it just enlarges the control surface you have to populate.
Step 2 — Start a compliance run
From the home launcher, switch the assessment type to Compliance, pick the framework to assess, and start the run. The agent expands the framework into its individual controls, tests what it can technically verify, reviews any evidence already in the library, and records a status for every control.
Step 3 — Read the control states
When the run finishes, every control carries one of five outcomes. Open any control to see exactly why it landed there — what must be true, the agent's verdict and reasoning, and, when it needs action, the specific evidence it is waiting for.
- Passing — the agent has evidence the control is satisfied.
- Failing — the agent found the control is not met.
- Needs action — the control cannot be decided yet; it is waiting on evidence you must provide.
- Not checked — not yet evaluated in a run.
- Excluded — you have marked the control out of scope for this environment.
Step 4 — Add the requested evidence
Where a control needs evidence you cannot prove by testing, provide it: upload a document, or sync it from a connected provider. Here is the catch people miss — uploading does not pass a control by itself. The evidence sits as "awaiting agent review" until you run the agent again, and that run reviews the evidence, records a control check that cites it, and updates the control. Reviewer, dates, and reasoning are preserved, so every status is traceable to the evidence and the run that credited it.
Step 5 — Connect an integration
Some evidence is better synced than uploaded. Connect a provider to pull configuration straight into the evidence library — Google Workspace 2-step verification and admin roles, Microsoft Entra MFA, GitHub branch protection. Synced evidence is read-only and, like an upload, stays advisory until a compliance run reviews it against the controls it maps to.
Step 6 — Automate to stay compliant
Readiness drifts as your environment changes and evidence goes stale. Instead of re-running by hand, schedule it: an automation re-assesses the framework and reviews newly synced or uploaded evidence on a cadence, so the matrix stays current and gaps surface early.
Step 7 — Export the readiness report
Once the matrix reflects your current evidence, export a readiness report. It summarizes the snapshot at a point in time, cites the evidence behind each control, lists remaining gaps, and recommends next steps — suitable for sharing internally or with an external advisor ahead of a real audit. Reports are reproducible; regenerate after evidence changes.
What readiness is not
Readiness is not certification, attestation, or auditor opinion
NullSquare produces supporting evidence and a written assessment of how well your environment is positioned to undergo audit. It does not certify, attest, or replace an independent auditor. Real audits are performed by accredited firms; readiness is the artifact set you bring to one.
Related articles
Last updated Jul 14, 2026
