This is an info Alert.
SnapKey Logo
  • Solutions
      • Solutions
      • SnapKey Residential
      • SnapKey Utility
      • SnapKey Public
      • SnapKey Logistics
      • SnapKey Sensors
      • Guest Check-in
      • Reactivatable Keys
      • Self-service Rentals
  • Industries
      • Industries
      • Utility companies
      • Residential buildings
      • Office buildings & Coworking spaces
      • Logistics
      • Holiday homes
      • Public restrooms
      • Construction sites
      • Unmanned stores
      • Temporary lockers
      • Virtual Keybox
  • Resources
      • Resources
      • Knowledge
      • Videos
      • API documentation
      • Trust & Security
      • System status
  • Partners
  • Company
      • Company
      • About us
      • Why SnapKey
      • Contact
auth.sign_inBook a demo

Compliance documentation that exists before the auditor asks

Most organisations only produce reports when the authority calls – and then discover the data is missing. See how scheduled reports, signed PDFs with SHA-256 and fixed cadences make documentation an automatic part of operations.
10. September 2026
5 min

There are two ways to produce compliance documentation.

One is to wait until somebody asks for it, then spend three weeks assembling spreadsheets. The other is to let it accumulate while operations run.

The difference rarely shows up in the quality of the document. It shows up in what you discover along the way.


The trouble with the reactive model

When an organisation first exports its data in the week supervision announces a visit, four things typically happen:

The gaps surface now

March is missing because an integration sat idle for two weeks. You find out here – where it can no longer be fixed.

Nothing to compare against

A single export shows a state. NIS2 expects continuous monitoring – which means a trend.

✍️ The document cannot be verified

A spreadsheet exported last week does not prove what reality looked like in March.

It costs time you do not have

Three weeks of manual work, every time somebody asks.


Five report types covering the questions that get asked

Report Answers Recommended cadence
Lock activity Who accessed which locks, when, and with what result Monthly
Person access All accesses by selected people, plus the keys they hold Monthly
Key inventory Every key: holder, last use, and which are dormant Annually
Incidents and sign-off Incidents and access sign-offs with response times Quarterly
Guest history Who has been here and why – guests and purpose check-ins combined Monthly

The cadences are not arbitrary. Monthly for activity reflects the NIS2 expectation of continuous monitoring. Annually for key inventory matches an inventory reconciliation. Quarterly for incidents fits management oversight — and management has to be able to document that it exercised that oversight.

Key inventory is the one that surprises people

Most organisations believe they know how many keys are in circulation. They usually do not.

The report shows dormant keys — keys that have not been used in a long time. Each one is a question: has the person left? Has the site been decommissioned? Or is it an access nobody is watching any more? That is exactly the material a risk assessment should be built on.


Signed PDF with SHA-256

Each report can be generated in two formats:

  • Signed PDF – for evidence towards supervision and management
  • CSV export – for further analysis

The signed PDF carries a SHA-256 checksum that can be copied and verified later.

Why this matters: a PDF without a checksum only proves that somebody once made a PDF. A PDF with one can be tested — change a single character and the checksum no longer matches.

That is the difference between a document that describes your controls and a document that is a control.


Schedule them so they arrive on their own

A report you have to remember is a report that gets forgotten. So each report type can be put on a schedule:

New schedule
   ├─ Report type    ──► e.g. Lock activity
   ├─ Scope          ──► entire location, or selected locks/people
   ├─ Frequency      ──► monthly · quarterly · annually
   └─ Recipients     ──► up to 10 email addresses
          │
          └──► The report is generated and sent automatically
               Next run and last run are shown on the schedule

When the schedule runs, the report lands with the recipients without anyone lifting a finger. After a year you have twelve monthly reports showing a trend — instead of one snapshot taken under pressure.

Delete a schedule and future reports stop, but already generated reports are kept. History does not disappear because somebody tidied up the schedules.


When a report fails

Reports are generated in the background and carry a status: generating, ready or failed. A failed report can be retried directly from the overview.

That sounds like a detail. But a failed monthly report nobody notices is precisely the gap that shows up a year later when somebody asks for March.


What it gives you when supervision arrives

Question from supervision Answer
How do you monitor access on an ongoing basis? Monthly lock activity report – here are the last twelve
How many keys are in circulation? Annual key inventory with dormant keys flagged
How does management exercise oversight? Quarterly incidents and sign-off report sent to management
Can we trust this document? Signed PDF with a verifiable SHA-256 checksum

FAQ

What is the difference between a signed PDF and a CSV export?

The signed PDF is evidence that can be verified through its SHA-256 checksum and is intended for supervision and management. The CSV export is raw data for further analysis in your own tools.

What happens to old reports if we delete a schedule?

They are kept. Only the future automatic reports stop.

Why is key inventory recommended annually rather than more often?

Because it is a reconciliation, not a monitoring activity. Activity is monitored continuously month by month, while the inventory is reviewed as a full count – typically once a year alongside the rest of the risk assessment.

How many people can receive a scheduled report?

Up to ten email addresses per schedule.

Can a report be limited to certain locks or people?

Yes. A report can cover the entire location or only selected locks or people, and always for a chosen period.


Contact us

Should your documentation be ready before anyone asks? Contact SnapKey.

Contact us
Related articles
NIS2 in Denmark 2026 – 6,000 companies and active supervision

Denmark's NIS2 law has been in force since 1 July 2025, and supervision has begun. See how many companies are covered, what inspectors ask for, and which documentation you need to be able to produce.

Energy Legislation and Access Control – Requirements for Critical Infrastructure

Understand energy legislation requirements for physical security and access control. Learn how SnapKey helps energy companies achieve compliance.

From incident to regulatory report in 24 hours – without guessing

NIS2 gives you 24 hours for an early warning. See how an access incident is recorded automatically, escalated into a regulatory case and filed on time – with countdowns, PDFs and an unbroken chain of evidence.


SnapKey Logo

SnapKey is your digital key for all types of locks. Easily open doors and locks directly from your smartphone, and enjoy fast, secure and flexible access without physical keys or extra apps. Perfect for private homes, businesses and shared spaces.

Solutions
SnapKey ResidentialSnapKey UtilitySnapKey PublicSnapKey LogisticsGuest Check-in
Developers
API documentationAPI referenceWebhooksChangelogSystem status
Company
About usWhy SnapKeyBecome a partnerKnowledgeVideosContact us
Legal
Terms & ConditionsPrivacy PolicyTrust & Security
Contact
SnapKey ApS+45 3242 9050info@snapkey.dk

© All rights reserved.