Reports
Turn project state into a record somebody can actually read.
A report that only a machine can parse is not a report. OTReady renders each one as a document first, built server-side from the same canonical state everything else uses, and issues it as a version that stays what it was.
- Human-readable rendering first; technical payload is secondary
- Assembled from governed project state, not re-typed
- Issued versions keep their number, digest, issuer and time

Available today
Three report kinds.
- Full Project Report
- The project's overall position across the assessments that have been run, with priority actions and the architecture context behind them.
- NIS2 Audit Pack
- The NIS2 Full Readiness state as it was submitted, together with its evidence register and the review outcomes recorded against it.
- IEC 62443-3-2 report
- The detailed risk work: the system under consideration, the scenarios, the countermeasures and the residual risk left after them.
Issuance
Issuing is a decision, and it freezes something.
- Governed project state
- Server-side assembly
- Issue
- Version
- History
The browser asks for a report to be issued; it never says what the report contains. The payload, the version number, the digest, the issuer and the time are all determined server-side.
Version 1 stays version 1.
When the project moves on and version 2 is issued, version 1 is not recalculated to match. Reopening it reads the frozen payload rather than re-deriving anything from today's state; a document that quietly rewrites itself is worse than no document, because the reader has no way to tell.
An issued report is a record, not a certificate.
None of these reports is a certification, an audit opinion or a legal statement of compliance. They record what was assessed, what was found, what evidence was offered and what was decided. OTReady supports readiness and audit preparation; it is not a certification body.
The reports in detail
Full Project Report
What it brings together, section by section.
NIS2 Audit Pack
The submitted readiness state and its evidence register.
IEC 62443-3-2 report
The detailed risk process, preserved as an issued record.
See a report you would be willing to hand over.
Look at a rendered report from a real project, and at the version behind it.