Insights & Reports
Market data, regulation and digital infrastructure
CERTavia publishes analyses of the digital infrastructure of regulated companies – based on real SOVP scans. The articles are aimed at compliance officers, IT security officers and decision-makers who need infrastructure evidence for audits and regulatory filings.
Focus areas: EU AI Act (Art. 50 transparency), DORA ICT risk management, NIS2 requirements for critical infrastructure, and benchmark reports from the German and European market. All published scan data is based on the Sovereign Validation Protocol (SOVP) – cryptographically signed, DNS-anchored, independently verifiable via the Sovereign Vault.
Four new sectors in the CES comparison: B2B, digital economy and publishers – 0 of 269 CERTIFIED
B2B-ECOMMERCE30, BVDW100 and DACH-PUBLISHER40 scanned for the first time. Cluster A = 0.0 for B2B and publishers: no robots.txt AI directives, no LLM structured data. The market is invisible to AI agents.
Read more →
DORA and infrastructure evidence: the documentation obligation nobody takes seriously yet
DORA has applied since January 2025 to more than 22,000 financial firms. Art. 28 to 30 require complete ICT third-party monitoring with technical evidence. The BaFin50 scan shows: 0 of 50 CERTIFIED.
Read more →
0 of 100: what the first ECOM100-DE compliance scan reveals about German e-commerce
CERTavia scanned the 100 highest-revenue German online retailers. 100 of 100: FAILED. Avg. CES 21.5. Cluster D dominates, all others fall below 20. SOVP cross-comparison: 0/100 CERTIFIED.
Read more →
The evidence gap: what CERTavia delivers for banks under Art. 50 EU AI Act
Deterministic infrastructure evidence, the danger of false precision, and the risk matrix for banks. What CERTavia delivers under Art. 50 — and where the limit lies. Part 1 of 2.
Read more →
200+ location rollout: scaling, liability and recommendations for the association
Operational entropy, 90-day validity, the liability demarcation line under MaRisk and DORA, and five prioritized steps for a safe association-wide rollout. Part 2 of 2.
Read more →
SOVP vs. ISO 27001: why classic certificates don't cover the EU AI Act
ISO 27001 attests processes. The EU AI Act demands infrastructure evidence. What SOVP delivers, what ISO 27001 cannot provide, and why the two complement rather than replace each other.
Read more →
EU AI Act checklist: infrastructure requirements for high-risk AI systems
A practical checklist: which infrastructure requirements does the EU AI Act place on high-risk AI under Annex III? Art. 9, 17, 43, 50 explained concisely with concrete check points.
Read more →
NIS2 and high-risk AI: obligations, implementation and recommendations
What specific obligations does NIS2 impose on companies with high-risk AI? Implementation strategies, technological challenges and prioritized steps for compliance teams in Germany.
Read more →
NIS2 directive and high-risk AI: who is affected and why?
NIS2, the EU AI Act and sector regulation converge on the same infrastructure. Who is affected by high-risk AI, which target groups fall under NIS2, and what the directive fundamentally requires.
Read more →
DACH Enterprise Readiness Report 2026: 0 of 288 domains CERTIFIED
CERTavia scanned 288 European enterprise domains across six sectors. Not a single company from the DAX 40, financial sector, healthcare, critical infrastructure, federal authorities or automotive reaches the CERTIFIED threshold.
Read more →How does your domain compare across the DACH region?
Scan your domain for free and see where you stand in the benchmark.
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43.