Compliance Reports Overview
Audit-ready evidence packages for engineering change management across CMMC, SOC 2, ISO 27001, PCI-DSS, ITIL CAB, and FedRAMP.
Overview
Koalr generates auditor-ready compliance evidence packages for engineering change management across six frameworks. Every pull request, code review, risk assessment, and CODEOWNERS check is continuously captured from your connected repositories and mapped to the control language of each framework.
Reports are generated on demand — pick any date range, pick a framework, and Koalr produces a fully formatted PDF cover page, executive summary, per-control evidence detail, and complete change log, plus a machine-readable CSV for GRC tooling.
Supported frameworks
| Framework | Audience | Key Controls |
|---|---|---|
| CMMC Level 2 | DoD contractors, Defense Industrial Base | CM.L2-3.4.9, CA.L2-3.12.3, SI.L2-3.14.1, CA.L2-3.12.1 |
| SOC 2 Type II | SaaS companies, cloud service providers | CC8.1 Change Management, CC6.1 Logical Access, CC9.2 Risk Assessment |
| ISO/IEC 27001:2022 | Global enterprises, EMEA companies | A.8.32 Change Management, A.8.25 Secure Dev Lifecycle, A.8.34 Audit Protection |
| PCI-DSS v4.0 | Fintech, e-commerce, payment processors | Req 6.5.1, 6.5.2, 6.5.3, 6.5.4 |
| ITIL 4 — CAB | Enterprise IT, ITSM teams | CHG.01 Authorization, CHG.02 Risk, CHG.03 Emergency, CHG.04 Audit Trail |
| FedRAMP Moderate | Federal contractors, civilian agencies | NIST SP 800-53 CM-3, CM-4, CA-7, SA-11 |
How evidence is collected
All six framework reports pull from the same underlying signal set captured from your Git, CI, and CODEOWNERS data:
- Merged pull requests — number, title, author, merged timestamp, repository
- Code reviews — reviewer identity, review state (APPROVED / COMMENTED / CHANGES_REQUESTED), submission timestamp
- Approval evidence — whether each PR received a required approval before merge
- Deploy risk score — 0–100 risk score from Koalr's 36-signal model (covers CC9.2, CM-4, CHG.02)
- Risk signals — DDL migration detection, blast radius, CODEOWNERS violations, coverage delta, file entropy
- Rubber-stamp detection — approvals given in under 2 minutes with zero review comments
- CODEOWNERS enforcement — whether protected-path changes had authorized reviewer sign-off
Each framework then maps these signals to its own control language. For example, "PR approved before merge" counts as evidence for CMMC CM.L2-3.4.9, SOC 2 CC8.1, ISO A.8.32, PCI-DSS 6.5.1, ITIL CHG.01, and FedRAMP CM-3 — one captured event, six frameworks served.
Report structure
Every compliance PDF contains the same sections for consistency across frameworks:
Cover page
- Koalr wordmark and Deployment Intelligence™ Platform branding
- Compliance Evidence Report badge
- Framework name and subtitle
- Metadata block: organization name, report period, generation timestamp, intended audience (C3PAO, CPA firm, QSA, 3PAO, CAB)
- Control coverage badges listing every control in scope
- Confidentiality footer
Executive summary
- Six KPI tiles: total changes, approved before merge, risk-scored, CODEOWNERS violations, high/critical risk, average risk score
- Per-control evidence blocks with status badge (EVIDENCED / PARTIAL / NOT_COVERED) and evidence count
Change log
- Table of the first 50 pull requests in the period
- Columns: PR #, repository, author, merge date, approval status, CODEOWNERS status, risk score
- Full list available in CSV export
Page footer
- Page number, report name, CONFIDENTIAL marking on every page
- Automatically added at PDF generation time
Status badge meanings
| Badge | Meaning |
|---|---|
| EVIDENCED | 95%+ of in-scope changes satisfy the control |
| PARTIAL | 50–95% coverage — some gaps require remediation |
| NOT_COVERED | No in-scope changes in the period, or fewer than 50% pass |
Generating a report
- Navigate to Compliance in the Koalr sidebar
- Select your framework from the hub page (or go directly to
/compliance/<framework>) - Choose a report period using the date picker (default: last 90 days)
- Click Download evidence package to generate the PDF
- Click Export CSV to get the raw change log as a spreadsheet
Reports are generated in real time — there is no cache, no nightly batch job, and no manual data entry. The evidence you see is always the evidence your auditor will see.
Important disclaimer
Koalr compliance reports are designed to support audit evidence collection. They do not constitute a formal audit opinion or attestation. For official certification, always engage a qualified assessor:
- CMMC: certified Third-Party Assessment Organization (C3PAO)
- SOC 2: licensed CPA firm with SOC 2 examination experience
- ISO 27001: accredited certification body
- PCI-DSS: Qualified Security Assessor (QSA)
- FedRAMP: Third-Party Assessment Organization (3PAO)
Related features
- CODEOWNERS governance — powers CC6.1, PCI-DSS 6.5.3, ISO A.8.34 evidence
- Deploy risk scoring — powers CC9.2, CM-4, CHG.02 risk assessment evidence
- Coverage integration — informs CA.L2-3.12.1 review quality assessment
Deployments
Track every deployment across your repositories — frequency, success rate, and correlation with incidents.
CMMC Level 2 Evidence Report
Generate CMMC Level 2 / NIST SP 800-171 compliance evidence for your C3PAO assessment — covering change management, CODEOWNERS enforcement, risk identification, and review quality.