EU GDPR readiness
99 distinct evidence review items; supporting tests are partial evidence
All available frameworksWhat the app checks
Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.
Explicit requirement-to-test mappings
| Requirement | Collector / test | What it checks or supports |
|---|---|---|
| ART-32 | STORAGE / STOR-AT-REST-ENCRYPTION-001 | Partial supporting observation for authorized in-scope systems only. Verify required populations, operation, timing, exceptions and reviewer conclusions independently. MFA registration does not prove enforcement; repository configuration does not prove restoration; patch age does not prove legal deadlines; device encryption does not prove all data or backup copies are encrypted. |
| ART-32 | CERTTLS / CERTTLS-POSTURE-001 | Partial supporting observation for authorized in-scope systems only. Verify required populations, operation, timing, exceptions and reviewer conclusions independently. MFA registration does not prove enforcement; repository configuration does not prove restoration; patch age does not prove legal deadlines; device encryption does not prove all data or backup copies are encrypted. |
| ART-32 | BACKUP / VEEAM-REPO-001 | Partial supporting observation for authorized in-scope systems only. Verify required populations, operation, timing, exceptions and reviewer conclusions independently. MFA registration does not prove enforcement; repository configuration does not prove restoration; patch age does not prove legal deadlines; device encryption does not prove all data or backup copies are encrypted. |
What requires manual review
Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.
Evidence preparation only; this profile does not establish certification, legal compliance or complete automated coverage. Scope, applicability and current source amendments require reviewer verification. Article-level base-act review; annexes are retained with the final source article. Delegated acts, current amendments and national implementing law must be assessed separately; no automatic legal applicability or deadline decisions. Original IT Audit Factory workpapers; public official sources linked. No government endorsement.
Where it is available
This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.
Coverage shown here comes from the application’s C32 requirement and mapping catalogs.