Compliance Reports
Open Reports > Compliance Reports to review evidence against selected security frameworks, inspect individual controls, and prepare evidence bundles.
Telovix reports the evidence available from the monitored environment. It does not certify compliance or replace the organizational, legal, and technical assessments required by a framework.
Choose a framework
Control Evidence offers:
| Framework | Review focus |
|---|---|
| CIS Controls v8 | Asset, configuration, logging, and monitoring evidence. This is not a CIS operating-system Benchmark scan. |
| NIS2 | Evidence relevant to cybersecurity risk-management and incident review. |
| NIST CSF 2.0 | Evidence organized around cybersecurity outcomes. |
| ETSI NFV-SEC | Security evidence for network-function virtualization environments. |
| O-RAN WG11 | O-RAN interface and runtime security evidence, available in telecom mode. |
Telecom reporting also includes 3GPP and telecom-specific assessments where supported. A framework's presence does not mean every requirement can be assessed from sensor data.
Select a reporting period
Choose Last 7 days, Last 30 days, or Last 90 days. Thirty days is the default.
Confirm the selected scope and evaluation time. A reporting window cannot recover evidence outside your configured retention period.
Understand evidence status
| Status | Meaning |
|---|---|
| Evidence check met | The available evidence meets this Telovix check. It does not establish full compliance with the standard. |
| Partial evidence | Some supporting evidence exists, but further review is needed. |
| Needs review | The check found a condition that requires investigation or remediation. |
| Not assessed | The available evidence does not support an assessment. |
The Evidence score gives full credit to checks met and half credit to partial evidence. Unassessed controls are excluded. When all controls are unassessed, the report shows Not assessed, not a zero score.
A healthy sensor or an absence of detected attacks does not establish compliance. Open the underlying control to understand what was assessed.
Review controls
- Open Control Evidence.
- Choose the framework and period.
- Select a control.
- Read its evidence summary and available observations.
- Record any organizational or manual evidence required outside Telovix.
- Recheck after remediation.
The Summary tab provides an overview and available score history. Compare like-for-like scopes and periods when assessing changes.
Create an evidence bundle
Evidence bundles capture a point-in-time report. They do not update automatically when the fleet changes.
- Open Evidence Bundles.
- Select Generate Bundle.
- Choose Framework and Date range in the form.
- Select the form's Generate Bundle button and wait for completion.
- Use Download on the completed bundle.
Generation and download require Operator or Admin access with unrestricted fleet scope. Bundle review requires Analyst or higher with unrestricted fleet scope.
NIS2-labelled bundles organize evidence for incident review. Their 24-hour, 72-hour, and 30-day windows are evidence lookbacks, not a calculation of your notification deadlines. Telovix does not determine legal entity classification or whether an event is a legally significant incident.
A bundle's signature helps check whether its contents changed. Establish the signer's trusted identity separately before relying on it as external evidence.
Reporting schedules
Use the reporting schedule controls when regular reports are needed. Review the selected framework, period, and delivery configuration before enabling a schedule. Schedule management requires unrestricted fleet scope.
Verify a completed report and delivery result rather than relying only on the schedule's enabled setting.
Troubleshooting
| Symptom | What to check |
|---|---|
| A framework has no score | Open its unassessed controls and review missing coverage or evidence. |
| A control needs review | Inspect its supporting observations and required follow-up. |
| A telecom framework is missing | Check that telecom mode and the relevant sensor coverage are enabled. |
| A period contains little evidence | Check retention, selected scope, and sensor observation times. |
| A bundle action is unavailable | Check your role and fleet scope. |
| A report differs from the current fleet | Compare its evaluation time with current reports; generated bundles are snapshots. |