Why you export Confluence to PDF for an audit
If your policies, procedures and evidence live in Confluence, the easiest thing for an auditor is often to read them there. But many auditors still ask for files: a PDF of each policy, a bundle of evidence for a sampled period, or a copy of a whole section to keep in their workpapers.
Knowing how to export Confluence to PDF (or Word) cleanly saves you a lot of last-minute work. The mechanics are simple. The parts people get wrong are the details around them: who is allowed to export, what silently drops out of the file, and whether you can prove later exactly which version of which page you sent.
This guide covers Confluence Cloud. Menus move over time, so check Atlassian's current documentation if yours differ.
Export a single page to PDF or Word
For one page, use the page's own export menu:
- Open the page.
- Select More actions (the
•••menu at the top of the page). - Hover over Export, then choose Export to PDF or Export to Word.
A few things to know before you send the result:
- You export what you can see, if you're allowed to. Anyone who can view a page can usually export it. On sites using Confluence's newer space roles this is a separate permission (export individual content), so a space admin may have to grant it.
- Only the published version is exported. If someone has unpublished changes in progress, they are not in the file.
- Word files are for Microsoft Word. Atlassian notes that the exported Word files open in Microsoft Word and aren't compatible with other word processors. If your auditor works in something else, send a PDF.
- Comments are not included in PDF exports. If a reviewer's sign-off lives in a comment, the PDF won't show it.
- Space PDF styling doesn't apply. Customizations to a space's PDF layout (covered below) apply to space exports, not to a single page exported from its menu.
Export a page tree or a whole Confluence space
When the auditor wants a whole section, such as every policy, use the space export. It also lets you pick specific pages, which is how you export one branch of the page tree instead of everything.
- In the sidebar, select More actions (
•••) next to the space name, then Space settings. - Open the General menu and select Export space.
- Choose a format. For PDF, choose whether to include all the content you can view or only specific pages, then select them.
- Start the export and download the file when it finishes.
Atlassian says a typical export of around 100 pages should finish within a few minutes. Very large exports take longer and may use an older export engine.
Who can export a space
Exporting a space needs the Export space permission, which space admins have by default. If you don't see Export space in space settings, you don't have it.
Your organization can also turn exports off. With a data security policy (an Atlassian Guard feature), an organization admin can block page exports to PDF and Word and space exports for the spaces it covers.
Restricted pages and attachments
An export contains only the content you can view. If a page in the tree is restricted and you aren't on its restrictions, it is left out of the file. The exception is a site admin exporting to CSV or XML, which includes all content. Before you send an export, compare its contents against the page tree so nothing is missing by accident.
The formats differ in what they carry:
| Format | What you get | Attachments | Good for |
|---|---|---|---|
| One PDF file of the selected pages | Not as separate files | Sending readable copies to an auditor | |
| HTML | A zip of HTML pages | Included in the zip | A browsable offline copy with attached files |
| CSV | A zip of data files | Included by default | Data, not reading |
There is also an XML export, meant for moving a space into Confluence Data Center rather than for auditors. Blog posts aren't included in space exports to PDF or HTML. If evidence lives in blog posts, export those individually.
Customize the space PDF export
A space export can carry a title page, headers and footers, which makes a bundle look like a deliberate submission instead of a printout. Space admins (with the right permission) can set this up under Space settings > Look and Feel > PDF export. Confluence admins can set a site-wide default as well.
The customization uses HTML for the title page, header and footer, and CSS for page size, orientation, margins, fonts, the table of contents and page numbering. Useful additions for audit bundles:
- A title page naming the company, the audit period and the request it answers.
- A footer with page numbers, so the auditor can cite "page 14" in a follow-up question.
- Landscape orientation for spaces with wide tables.
Atlassian's support for custom PDF HTML and CSS is limited, so keep the changes small and test them on a few pages first.
What doesn't export well
An export is a flattened snapshot. Check each file before it leaves your hands.
- Comments. Not included in PDF exports. Move any decision that matters into the page body, or record it somewhere the export will capture.
- Wide tables. PDF pages are narrower than your screen, and a table row can't be split, so wide tables can be cut off. Narrow the table, swap rows and columns, or export in landscape.
- Dynamic content. Macros and embedded content that pull information in live, such as lists of other pages or content from other tools, are captured as they render at export time, if they render at all. Pages heavy with macros, large embeds or many attachments can also be slow to export or fail. Open the PDF and look.
- Page history. The export shows the current published page only. It doesn't show who changed what, or when, which is often exactly what an auditor wants to see.
- Links. Links in the PDF still point to your Confluence site. An auditor without access to the site can't follow them.
- Restrictions. Page restrictions don't travel with the file. Once exported, anyone who has the PDF can read it, so treat it with the same care as the restricted page.
Name, date and log every export
Months later, someone will ask "what exactly did we give the auditor for the access review in March?" A naming convention and an export log let you answer in a minute.
Name files so they explain themselves
Put the export date first, then the subject, then the page version from the page history. For example:
2026-10-01_Access-Control-Policy_v8.pdf2026-10-01_Policies-section_space-export.pdf
The version number lets anyone match the file to the exact version in Confluence's page history.
Keep an export log
Keep a simple table, in Confluence or a spreadsheet, with one row per file sent. An example:
| Date | File | Pages and versions | Exported by | Sent to | Request |
|---|---|---|---|---|---|
| 2026-10-01 | 2026-10-01_Access-Control-Policy_v8.pdf | Access Control Policy, v8 | Jordan (IT lead) | Audit firm portal | Request 12: current access policy |
| 2026-10-01 | 2026-10-01_Policies-section_space-export.pdf | 9 policy pages (versions listed in file) | Jordan (IT lead) | Audit firm portal | Request 3: all security policies |
Keep a copy of every file exactly as you sent it, in a folder only the compliance team can open. If you want to be thorough, record a checksum of each file too, so you can show later that the copy you kept is the one you sent. The point is to answer two questions without guessing: what did the auditor see, and when.
Tip: Re-export instead of editing. If a file was wrong, fix the page, export again under a new name, and log both rows. A corrected file with a clear trail is far easier to explain than a quietly replaced one.
When not to export
Exports are snapshots, and snapshots go stale. Every follow-up question ("can I see the previous version?", "who approved this?") means another export. Often the better option is live, view-only access: a Confluence group for the auditors with view permission on the compliance space, and nothing more. The auditor reads the pages, follows the links and browses the page history themselves. Many will take both: live access during fieldwork, plus exports of the items they sample for their workpapers.
Whatever you choose, organize the evidence so it is easy to find in the first place. Building an audit-ready evidence library covers filing by control and period, and running a SOC 2 program in Confluence covers the space structure.
Exporting audit reports from Compliance in a Box
Exporting individual pages proves what a page said. It doesn't prove who approved it, which employees acknowledged it, or whether a quarterly review ran on time. Those records are what auditors sample, and they are tedious to assemble by hand.
Compliance in a Box is an Atlassian Forge app that runs a SOC 2 program in a Confluence space. It writes its records into ordinary Confluence pages in that space, so you export them with Confluence's own export, as described above:
- Policy Approval Log: every policy with its approved version, approvers and next review date, plus one page per year listing each submission and each approver's decision.
- Policy Acknowledgement Report: each policy's acknowledgement campaign, and per year, every person asked, their status and the page version they acknowledged.
- Activity Completion Report: every recurring activity, and per year, each period's status, submissions, approvals and skips.
- Audit Log pages: one page per month of the app's append-only audit log.
- Controls Matrix: every SOC 2 criterion in your selected categories with its mapped policies and activities and a status of Covered, Attention or Gap.
The reports link to exact page versions. Each version link opens that version from the page history, even if the page has changed since, and the links are full addresses, so they still work in an exported PDF for anyone with access to your site. That answers the "which version did they approve?" question that a plain page export can't. (For why that matters, see policy version control and approvals.)
Before exporting, open Compliance in a Box, go to Settings, and click Refresh now in the Evidence & Reports section so the pages are current. The app also refreshes them once a day. Each page says when its data is from, and yearly pages follow calendar years in UTC, so if your audit period crosses a year boundary, export both years. On paid Confluence plans the report pages are view-restricted to Compliance Admins and an optional Auditors group, and an export only includes what you can view, so run it as one of them. The audit preparation checklist in the user guide walks through the full routine.
FAQ
Can I export a page and all its child pages in one go?
Yes, through the space export: in Space settings > General > Export space, choose PDF and select only the pages you want. This needs the Export space permission. A single page's own export menu covers that page only.
Do Confluence exports include restricted pages?
Only the ones you can view. Pages restricted away from you are left out. A site admin exporting to CSV or XML is the exception and gets all content.
Are attachments included when I export Confluence to PDF?
Not as separate files. A PDF export is a single document. HTML and CSV space exports include attachments in their zip archives, or you can download the attached files from the page and send them alongside the PDF.
Can I export an older version of a page?
Confluence's export menus work on the page as currently published. If the auditor needs an earlier version, the better route is to point them to it in the page history, where it is shown with who changed it and when.