Compliance documentation that exists before the auditor asks
Most organisations only produce reports when the authority calls – and then discover the data is missing. See how scheduled reports, signed PDFs with SHA-256 and fixed cadences make documentation an automatic part of operations.
There are two ways to produce compliance documentation.
One is to wait until somebody asks for it, then spend three weeks assembling spreadsheets. The other is to let it accumulate while operations run.
The difference rarely shows up in the quality of the document. It shows up in what you discover along the way.
The trouble with the reactive model
When an organisation first exports its data in the week supervision announces a visit, four things typically happen:
The gaps surface now
March is missing because an integration sat idle for two weeks. You find out here – where it can no longer be fixed.
Nothing to compare against
A single export shows a state. NIS2 expects continuous monitoring – which means a trend.
✍️ The document cannot be verified
A spreadsheet exported last week does not prove what reality looked like in March.
It costs time you do not have
Three weeks of manual work, every time somebody asks.
Five report types covering the questions that get asked
| Report | Answers | Recommended cadence |
|---|---|---|
| Lock activity | Who accessed which locks, when, and with what result | Monthly |
| Person access | All accesses by selected people, plus the keys they hold | Monthly |
| Key inventory | Every key: holder, last use, and which are dormant | Annually |
| Incidents and sign-off | Incidents and access sign-offs with response times | Quarterly |
| Guest history | Who has been here and why – guests and purpose check-ins combined | Monthly |
The cadences are not arbitrary. Monthly for activity reflects the NIS2 expectation of continuous monitoring. Annually for key inventory matches an inventory reconciliation. Quarterly for incidents fits management oversight — and management has to be able to document that it exercised that oversight.
Key inventory is the one that surprises people
Most organisations believe they know how many keys are in circulation. They usually do not.
The report shows dormant keys — keys that have not been used in a long time. Each one is a question: has the person left? Has the site been decommissioned? Or is it an access nobody is watching any more? That is exactly the material a risk assessment should be built on.
Signed PDF with SHA-256
Each report can be generated in two formats:
- Signed PDF – for evidence towards supervision and management
- CSV export – for further analysis
The signed PDF carries a SHA-256 checksum that can be copied and verified later.
Why this matters: a PDF without a checksum only proves that somebody once made a PDF. A PDF with one can be tested — change a single character and the checksum no longer matches.
That is the difference between a document that describes your controls and a document that is a control.
Schedule them so they arrive on their own
A report you have to remember is a report that gets forgotten. So each report type can be put on a schedule:
New schedule
├─ Report type ──► e.g. Lock activity
├─ Scope ──► entire location, or selected locks/people
├─ Frequency ──► monthly · quarterly · annually
└─ Recipients ──► up to 10 email addresses
│
└──► The report is generated and sent automatically
Next run and last run are shown on the schedule
When the schedule runs, the report lands with the recipients without anyone lifting a finger. After a year you have twelve monthly reports showing a trend — instead of one snapshot taken under pressure.
Delete a schedule and future reports stop, but already generated reports are kept. History does not disappear because somebody tidied up the schedules.
When a report fails
Reports are generated in the background and carry a status: generating, ready or failed. A failed report can be retried directly from the overview.
That sounds like a detail. But a failed monthly report nobody notices is precisely the gap that shows up a year later when somebody asks for March.
What it gives you when supervision arrives
| Question from supervision | Answer |
|---|---|
| How do you monitor access on an ongoing basis? | Monthly lock activity report – here are the last twelve |
| How many keys are in circulation? | Annual key inventory with dormant keys flagged |
| How does management exercise oversight? | Quarterly incidents and sign-off report sent to management |
| Can we trust this document? | Signed PDF with a verifiable SHA-256 checksum |
FAQ
What is the difference between a signed PDF and a CSV export?
The signed PDF is evidence that can be verified through its SHA-256 checksum and is intended for supervision and management. The CSV export is raw data for further analysis in your own tools.
What happens to old reports if we delete a schedule?
They are kept. Only the future automatic reports stop.
Why is key inventory recommended annually rather than more often?
Because it is a reconciliation, not a monitoring activity. Activity is monitored continuously month by month, while the inventory is reviewed as a full count – typically once a year alongside the rest of the risk assessment.
How many people can receive a scheduled report?
Up to ten email addresses per schedule.
Can a report be limited to certain locks or people?
Yes. A report can cover the entire location or only selected locks or people, and always for a chosen period.
Contact us
Should your documentation be ready before anyone asks? Contact SnapKey.
Related articles
NIS2 in Denmark 2026 – 6,000 companies and active supervision
Denmark's NIS2 law has been in force since 1 July 2025, and supervision has begun. See how many companies are covered, what inspectors ask for, and which documentation you need to be able to produce.
Energy Legislation and Access Control – Requirements for Critical Infrastructure
Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.
From incident to regulatory report in 24 hours – without guessing
NIS2 gives you 24 hours for an early warning. See how an access incident is recorded automatically, escalated into a regulatory case and filed on time – with countdowns, PDFs and an unbroken chain of evidence.