Guide
Generate and hand off reports
Generate framework reports and preserve their scope, source records, review decisions, and known gaps.
Last reviewed September 12, 2026
Generate a PCI DSS report
On the PCI DSS page, select Generate PCI Report, wait for the generating state to complete, and download the report when SiteWall marks it ready. Confirm project, payment-page scope, source data, generation time, unresolved actions, and reviewer before handing it off.
Procedure
- 1.
Open the correct project and page
Use the project selector to choose the website you intend to review, then open Legal & Compliance in the left navigation. Confirm the organization, project, and monitored domain before interpreting a record or changing a control.
- 2.
Define the review scope
Record the project, monitored pages, observation period, source records, reviewer, and current readiness or generation state before interpreting or exporting evidence.
- 3.
Click
Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion.
- 4.
Generation status
Read the state together with its timestamps and owner action; a workflow state does not erase the original observation.
- 5.
Cross-check the evidence set
Follow readiness and coverage indicators to their source records, confirm the project and observation period, and inspect the generated artifact before treating it as ready for review.
- 6.
Preserve provenance and review responsibility
Store the project, monitored scope, source links, observation and generation times, reviewer, decisions, gaps, and organizational records still required.
Generate a GDPR report
On the GDPR page, generate the report and wait for the ready state before downloading. Review project, monitored scope, evidence freshness, third-party and resource context, actions, gaps, and generation time, then combine it with the privacy owner’s organizational records.
Generate an ISO report
On the ISO/IEC 27001 page, generate and download the report, then verify project, applicable client-side scope, source records, timestamps, open actions, and evidence gaps. Preserve it with the organization’s ISMS evidence and review metadata.
Prepare an evidence handoff
An evidence handoff should name the organization and project, monitored pages, observation and report period, included requirements or controls, source records and exports, recorded decisions, known gaps, owner, reviewer, generation time, and follow-up actions. Share only the minimum data required by the recipient.