Compliance and Audit Evidence
The compliance and evidence layer of the Cloud Gateway platform, generating audit-ready outputs aligned to CAF, DSPT, ITHC and more
Compliance and audit evidence,
built into the service
Assure is the compliance layer of the Cloud Gateway platform. It’s the part of the architecture that turns the platform’s operating data into evidence your governance team, your auditor, and your regulator can use. This is the layer that’s normally bought separately, as audit support engagements or compliance consultancy. Cloud Gateway delivers it as part of the platform.
Most organisations build compliance evidence the same way: a quarterly project. Pull data from connectivity, security, change management and incident systems. Reconcile it. Cross-reference it. Format it for the framework being assessed. The evidence is real, but assembling it is slow, expensive, and not what your team should be doing.
Assure changes that. The operating data the platform already produces (connection records, change logs, incident data, security policy enforcement, SLA delivery) is structured into evidence that lines up with the frameworks UK regulated organisations have to evidence against. The evidence is generated as a by-product of the service, available when you need it, in formats your governance team can actually use.
How evidence is generated
Assure draws on the platform’s operating data. Every service in your tenant produces evidence as it runs.
Operating data as evidence
Change records, incident logs, security policy enforcement, SLA delivery, telemetry. The data the platform already generates is the same data Assure structures into compliance outputs.
Aligned to audits
that matter
Outputs aligned to CAF, DSPT, ITHC. The frameworks UK regulated organisations actually have to evidence against, structured the way assessors expect to see them.
On the cadence your team needs
Evidence packs and reports generated to the schedule you set. Quarterly board reporting, annual DSPT submissions, ad-hoc audit support, all available without a separate engagement.
Sovereign by
design
The platform is operated in the UK, with full supply chain visibility. The evidence Assure produces reflects that, with provenance and chain of data custody traceable end to end.
What Assure does, and
where you stay in the driving seat
Assure is the evidence layer. It produces the operating data and the audit-ready outputs that support your compliance obligations. The submission, accreditation and audit relationship stay with you. Your CAF return is your return. Your DSPT submission is your submission. Your ITHC engagement is yours to commission.
What we do is make those obligations easier to meet. Pattern alignment, evidence packs, ITHC readiness data and audit support so when the next cycle comes around, the answers are already there.
Beyond evidence
are the services Assure draws evidence from. Every connection, change, policy decision and incident is captured automatically as it happens.
is the live view of the same data Assure structures into evidence. The same information, presented in real time for you and evidence packs for auditors.
keeps the evidence reliable. Governed change workflows mean every change is validated, captured and traceable as part of the service.
Common questions
about Assure
What is the Cyber Assessment Framework (CAF), and how does it relate to DSPT?
The Cyber Assessment Framework (CAF) is the National Cyber Security Centre’s framework for assessing cyber resilience in organisations responsible for essential services. From September 2024, the NHS Data Security and Protection Toolkit (DSPT) moved to align with CAF, meaning NHS organisations now report against CAF objectives, principles and outcomes rather than the previous checklist-style DSPT. NHS trusts, ICBs, ALBs and CSUs are now assessed under CAF-aligned DSPT.
What evidence does a managed service need to produce for an audit?
A managed connectivity or security service should produce evidence covering: change records (who changed what, when, why, with what approval), patch logs (firmware and security patches applied, with completion evidence), policy enforcement (firewall rules, blocks, exceptions), incident response (events, actions, resolution times), SLA delivery (against contracted service levels), and access governance (who has access to what, validated and reviewed). Cloud Gateway can provide all of these as part of the Assure layer.
What is ITHC, and how often do I need one?
An ITHC (IT Health Check) is an independent technical security assessment required for connection to public sector networks including HSCN and PSN, and for various other regulated services. It is typically required annually, or after material changes to the system being assessed. Cloud Gateway can provide reports and data to contribute to your ITHC readiness as part of the Assure layer, so customers approach their ITHC engagement with documented evidence rather than having to assemble it from scratch.
Does Cloud Gateway submit my CAF or DSPT return?
No. Submission and accreditation remain the customer’s responsibility. Cloud Gateway provides the underlying operating data and audit-ready evidence that support the customer’s submission, ITHC engagement and audit cycle, but the submission, the regulator relationship and the accountable role all stay with you.
Connect. Protect. Observe. Operated as one.
Get your regulated connectivity right first time.