Skip to main content
Many compliance frameworks — including SOC 2, ISO 27001, and HIPAA — require evidence that access to sensitive systems is regularly reviewed and that least-privilege is enforced. Satisfying these requirements means more than having the right policies on paper; auditors expect a documented trail showing that controls are operating continuously and that access decisions are recorded. Nexus provides the controls, documentation, and audit trail you need to satisfy these requirements and walk into any audit with confidence.

Compliance-relevant features

Nexus maps directly onto the access control and monitoring requirements found in major compliance frameworks. The table below shows which features support which compliance needs.

Access Reviews

Nexus’s access review workflows generate the periodic access certifications required by frameworks such as SOC 2 CC6.3 and ISO 27001 Annex A.9.2. Every review captures reviewer decisions, justifications, and timestamps, giving auditors a complete and tamper-evident record of who certified what — and when.

Posture Insights

Continuous monitoring against zero-trust benchmarks demonstrates that your organization enforces access policies on an ongoing basis, not just at point-in-time assessments. The posture score and findings history provide auditors with evidence of active policy oversight.

Automation Rules

Automated enforcement of access policies — such as removing stale accounts or revoking excessive permissions — shows auditors that your controls operate independently of manual intervention, reducing the risk of human error and demonstrating consistent policy application.

Audit Logs

Nexus maintains a tamper-evident log of every identity change and every action taken within the platform. This log captures the who, what, when, and why of access changes across your Entra estate, supporting both internal investigations and external audit evidence requests.

Generating audit reports

Nexus lets you generate formatted audit reports on demand, covering the time range and scope that your auditor requires. You can produce a report in seconds without exporting raw data or building a spreadsheet manually.
1

Go to Reports

In the Nexus left navigation, select Reports. You will see a list of any previously generated reports and a button to create a new one.
2

Select the report type

Choose the report that matches your audit evidence request:
  • Access Review Summary — a complete record of all access reviews in the selected period, including completion rates, reviewer decisions, and outstanding items.
  • User Access Report — a snapshot of every user’s group memberships, role assignments, and application access as of a specific date.
  • Privileged Access Report — a focused view of all privileged role assignments, PIM activations, and standing admin accounts detected during the period.
  • Posture History — your posture score trend, findings opened and closed, and remediation actions taken over the selected date range.
3

Set the date range and scope

Select the start and end dates for the report. Then set the scope: you can report across your entire tenant, limit the report to specific groups, or narrow it to one or more applications. Narrowing scope is useful when an auditor is reviewing a specific system or department rather than your entire environment.
4

Generate and download the report

Click Generate. Nexus processes the report and makes it available for download as a PDF or CSV within a few seconds. PDF format is suitable for sharing directly with auditors; CSV format lets you import the data into your GRC platform or compliance tracking system.

Access certification records

Every access review you complete in Nexus is permanently stored as a certification record. The record includes the full list of access items that were reviewed, each reviewer’s decision (approve, revoke, or not reviewed), any justification notes the reviewer entered, and the date and time of every decision. These records cannot be edited after the review closes, ensuring they provide a reliable audit trail. When an auditor asks for evidence that access to a sensitive application was reviewed during a specific quarter, you can produce the corresponding certification record in seconds from the Access Reviews history page. Records are retained in accordance with your organization’s data retention settings, which you can configure under Settings → Data Retention.

Supported frameworks

Nexus is designed to support the access control, least-privilege, and monitoring requirements found across a range of widely adopted compliance and security frameworks. The controls Nexus provides are directly relevant to the following frameworks:

SOC 2 Type II

Supports CC6.2, CC6.3, and CC7.2 controls around logical access, access reviews, and continuous monitoring.

ISO 27001

Supports Annex A.9 (Access Control) and Annex A.12.4 (Logging and Monitoring) requirements.

NIST 800-53

Maps to AC (Access Control), AU (Audit and Accountability), and IA (Identification and Authentication) control families.

CIS Controls

Supports CIS Control 5 (Account Management), Control 6 (Access Control Management), and Control 8 (Audit Log Management).

HIPAA Security Rule

Supports the Access Control standard (§164.312(a)(1)) and the Audit Controls standard (§164.312(b)) under the Technical Safeguards.
Nexus does not hold compliance certifications on your behalf. Always work with your compliance team to validate that controls meet your specific audit requirements.