All guides

Managers and administration

Evidence for your auditor

What the manager console's exports contain, what they show under the NIS2 Directive, the AI Act, GDPR and ISO 27001, and what they don't.

The manager console gives you dated evidence of your training: who completed which lesson and when, and which requirement the lesson is mapped to. This guide explains what each export holds and how you can use it in an audit.

The exports are part of the manager console, which comes with Platform + manager console + audit and with Enterprise.

The exports

The exports only ever cover your own organisation.

Training log (CSV)

On the Compliance page. One row for each lesson each person has completed: the person, their email, department, the date it was completed, path, module, lesson, competency, the frameworks and clauses the lesson is mapped to, and the number of questions. The rows are grouped by person, in date order. The dates come from the server's records.

It answers: who was trained, when, and on what.

Evidence pack (CSV)

On the Compliance page. One row per person per control: the framework, the control, how many lessons it needs and how many were completed, coverage as a percentage, and a status. The status is current (up to date: at least 80% of the control's lessons), in progress, or not started. Each row also has the person's average quiz score and retention figure.

It answers: how fully each person has been trained on each control.

Server log (CSV)

On the Compliance page. The training log exactly as the server recorded it: the person, their role and status, the lesson's identifier, the times of the first and latest completion, the best result, the number of attempts and when it was exported. It is the source data, for an auditor who wants the records without Cyberact's calculations on top.

People: Export CSV

On the People page. One row per person: role, status, department, when they were last active, lessons completed and the share of all lessons, and their status on each requirement.

The management summary and the board summary

The Management summary page can be printed or saved as a PDF. It shows each member of your management body's progress on the management path, with their dated completions. Board summary on the Compliance page prints a report for the whole organisation. See The manager console.

The access log

The Users and access page has an Access log. Every sign-in, invitation and access change is recorded in it with who made it, and the page shows the latest events. It tells you who has had access and when. Access log entries are kept for 24 months.

What the exports show

  • Who: the completion belongs to a named person who signed in with their own work email and a one-time code.
  • What: which lesson, and which framework clauses Cyberact has mapped it to.
  • When: the date recorded by the server.
  • How well: the quiz result and the retention figure, that is, how review questions go weeks later.
  • That it is ongoing: the completions are spread over time, so they show continuous training rather than a one-off.

What the exports don't show

  • They don't show that your organisation meets the requirements of any law or standard. Training is one measure among others.
  • They don't say whether the training is enough for your risks, or for each person's job. That is for you to judge.
  • They don't prove that people act on what they learned.
  • The mapping of lessons to framework clauses is Cyberact's own. Your auditor may see it differently.
  • They are not a certificate.

By regulation

The NIS2 Directive

NIS2, Directive (EU) 2022/2555, applies through each member state's national law, to the entities that law brings into scope. Article 21(2)(g) names basic cyber hygiene practices and cybersecurity training among the risk-management measures. Under Article 20, the management body approves those measures and oversees their implementation, and its members are required to follow training. Your country's NIS2 law sets out the details, so check its wording.

In Finland the Directive was transposed by the Cybersecurity Act (kyberturvallisuuslaki, 124/2025). Section 9(2)(6) of the Act requires risk management to include, among other things, cybersecurity training. Under section 10, management approves the cybersecurity risk-management model and oversees its implementation, and management must be sufficiently familiar with cybersecurity risk management.

Neither the Directive nor the Finnish Act sets a form for showing that training or familiarity. Dated completions by members of your management body are evidence that supports showing it. On their own they do not show that the requirement is met. The training log and the evidence pack show who among your staff has been trained, when and on what.

The AI Act, Article 4

Providers and deployers of AI systems must take measures to support the development of AI literacy among their staff and others using AI systems on their behalf. No set level is required. According to the European Commission's questions and answers, no certificate is needed, and an internal record of the measures can be kept.

The training log is such a record: it shows who completed the lessons on AI, and when. It doesn't say whether the measures are enough for the way your organisation uses AI.

GDPR

GDPR does not require any particular training of everyone. Staff training can be part of the appropriate technical and organisational measures Article 32 requires to ensure the security of processing. If you have a data protection officer, their tasks include monitoring compliance, including awareness-raising and training of the staff involved in processing (Article 39(1)(b)).

The training log and the evidence pack show who completed the lessons on data protection, and when.

ISO 27001

Annex A control 6.3 (information security awareness, education and training) requires that personnel and relevant interested parties receive appropriate information security awareness, education and training, and regular updates of the information security policy, topic-specific policies and procedures, as relevant for their job function. Annex A controls apply to your organisation once you have selected them in your Statement of Applicability. The evidence pack's rows for control A.6.3 and the training log show who has been trained and when. In a certification audit, the auditor also looks at how the training was planned and targeted.

Tips for an audit

  • Run all the exports on the same day, so their figures agree. Every file carries the date it was exported.
  • Give your auditor the training log and the evidence pack. If they want the source data, give them the server log too.
  • Disable, rather than delete, anyone whose completions you still need as evidence. See Inviting people, and seats.
  • Download the exports before your access ends. See Cancelling your subscription.