Compliance Evidence Mapping
QNSI evidence areas for ISO/IEC 27001:2022, ISO/IEC 42001:2023, and ISO/IEC 19790:2025.
HEOSSI (PTE.) LTD owns and administers the company compliance programme and is the prospective certificate holder. QNSI is a HEOSSI product that may be included within the documented scope; it is not a separate certificate holder. QNSI exposes readiness evidence for the three HEOSSI compliance frameworks:
- ISO/IEC 27001:2022 - information security management.
- ISO/IEC 42001:2023 - AI governance and safety.
- ISO/IEC 19790:2025 - cryptographic module security.
The mappings are internal assessment aids. They are not accredited certification, independent conformity assessment, legal advice, or proof that a control is effective.
ISO/IEC 19790 applies only to specifically identified cryptographic modules or components, not to HEOSSI or QNSI generally.
Evidence boundaries
Audit events, service telemetry, signed attestations, configuration records, and
cryptographic test results have different evidentiary value. A report must state
which source supports each assessment and must use NOT VERIFIED when the
available evidence does not independently test the claim.
Service-health responses are liveness observations only. They do not establish framework conformity or control effectiveness.
Report endpoints
Generate or download readiness reports using one of the supported identifiers:
iso27001iso42001iso19790
The tentative programme target is Q4 2026 or Q1 2027, subject to funding. This target is planning information, not a certification promise.