Automatic reports and evidence for auditors

QROS turns every scan and assessment into automatic reports and per-control evidence packages — an executive LaTeX/PDF document with the per-system quantum-risk score and migration priority bands, plus the underlying control-by-control evidence that DORA, PCI-DSS and ISO 27001 auditors ask for. No manual assembly: the report is regenerated from the live inventory, so the version an auditor sees always matches the version you operate.

Executive report · Q1PDF
58
Quantum-readiness score
42 / 100 systems · 0–100
Immediate · 712m · 19LP · 16
Evidence package · DORAaudit-ready
Art. 6 ICT riskspass
Art. 9 TLSfail · 3
Art. 8 cryptopartial
artifacttls-cve-scan.json
artifactcis-debian12.html

What the reports include

Evidence ready for auditors

Each evidence package bundles the raw scanner output (testssl.sh, OpenSCAP, ansible-lockdown) with the control mapping, so an auditor can trace any “pass” or “fail” back to the command that produced it. Reports regenerate from the live inventory on demand, so the audit version and the operational version are never out of sync.

Generate a guided-assessment report →

FAQ

What format are the reports?

Executive reports are generated as LaTeX and rendered to PDF, with the quantum-readiness score, priority bands and per-system detail. The underlying per-control evidence is exported as JSON/CSV with the raw scanner artifacts attached.

Can the evidence be exported for DORA and PCI?

Yes. Every control maps to the relevant DORA article, PCI-DSS 4.4 requirement and ISO 27001 A.8.24 control, and the package bundles the exact testssl.sh / OpenSCAP / ansible-lockdown output behind each pass or fail, so it drops straight into a DORA or PCI audit.

Try this service with QROS

Explore now →