Compliance Evidence Mapping

QNSI evidence areas for ISO/IEC 27001:2022, ISO/IEC 42001:2023, and ISO/IEC 19790:2025.

HEOSSI (PTE.) LTD owns and administers the company compliance programme and is the prospective certificate holder. QNSI is a HEOSSI product that may be included within the documented scope; it is not a separate certificate holder. QNSI exposes readiness evidence for the three HEOSSI compliance frameworks:

  • ISO/IEC 27001:2022 - information security management.
  • ISO/IEC 42001:2023 - AI governance and safety.
  • ISO/IEC 19790:2025 - cryptographic module security.

The mappings are internal assessment aids. They are not accredited certification, independent conformity assessment, legal advice, or proof that a control is effective.

ISO/IEC 19790 applies only to specifically identified cryptographic modules or components, not to HEOSSI or QNSI generally.

Evidence boundaries

Audit events, service telemetry, signed attestations, configuration records, and cryptographic test results have different evidentiary value. A report must state which source supports each assessment and must use NOT VERIFIED when the available evidence does not independently test the claim.

Service-health responses are liveness observations only. They do not establish framework conformity or control effectiveness.

Report endpoints

Generate or download readiness reports using one of the supported identifiers:

  • iso27001
  • iso42001
  • iso19790

The tentative programme target is Q4 2026 or Q1 2027, subject to funding. This target is planning information, not a certification promise.