June 14, 2026 Technology

SOVP vs. ISO 27001: Why Classic Certificates Don't Cover the EU AI Act

By Thorsten Litzki · Litzki Systems LLC

tl;dr

Key takeaways

  • •  ISO 27001 certifies that you have established a process. SOVP proves what your infrastructure actually does.
  • •  EU AI Act Art. 50 requires evidence — not proof of process. An ISO certificate alone does not satisfy this requirement.
  • •  SOVP is deterministic infrastructure validation: no discretion, no room for interpretation, no auditor judgment.
  • •  Both instruments are complementary: ISO 27001 covers governance, SOVP covers technical infrastructure evidence.

The Problem with Process Certificates

ISO 27001 is an excellent tool. It helps organizations establish an Information Security Management System (ISMS), documents risk management processes, and shows third parties that information security is taken seriously. For many regulatory contexts, ISO 27001 is a sensible foundation.

The problem is what ISO 27001 does not prove: the actual state of the infrastructure at the time of an audit.

A company can be ISO 27001-certified and, at the same time:

  • Serve TLS certificates with outdated cipher suites
  • Not have implemented DNSSEC
  • Run production endpoints without required HTTP security headers
  • Provide no cryptographic verifiability for external auditors

The ISO certificate says: "We have committed to following processes." SOVP validation says: "Here is the cryptographically signed infrastructure state as of today, 14:37 UTC."

What Art. 50 EU AI Act Actually Requires

Art. 50 EU AI Act requires providers to disclose the use of AI and to label AI-generated content. Art. 50(2) specifies: outputs of AI systems that generate synthetic audio, image, video, or text content must be marked and detectable as artificially generated or manipulated in a machine-readable format.

That is not a process requirement. It is an infrastructure requirement.

Conformity assessment bodies under Art. 43 will ask: "Can you prove that your infrastructure met these requirements at time X?" An ISO certificate that is 12 months old and confirms general ISMS maturity does not answer that question.

How SOVP Works

The Sovereign Validation Protocol is a deterministic infrastructure validation method. "Deterministic" means: given the same infrastructure, every conformant implementation arrives at the same result. No auditor discretion, no room for interpretation.

SOVP checks 6 clusters with a total of 80+ parameters:

  • Cluster A — Digital Infrastructure: DNS, TLS, security headers
  • Cluster B — Machine Readability: llms.txt, JSON-LD, agents.md, API catalog
  • Cluster C — Legal Compliance: schema, metadata, legal consistency
  • Cluster D — Transparency & Consent: bot access policy, consent management
  • Cluster E — Agentic Readiness: API catalog, agent interfaces
  • Cluster F — AI Governance Hard Gate: ai-disclosure.json; must reach ≥ 40 for CERTIFIED

The result is a Compliance Evidence Score (CES) from 0–100. CERTIFIED is awarded when CES ≥ 75 AND Cluster F ≥ 40. That is binary, traceable, machine-readable.

The Key Difference: Verification vs. Certification

ISO 27001 relies on trust in the certification process: an accredited auditor has verified that processes are documented and followed. That is valuable — but it is a subjective judgment at a specific point in time that quickly becomes outdated.

SOVP evidence is cryptographically signed and anchored in the Sovereign Vault. Any auditor, any conformity assessment body, any AI authority can independently verify the evidence — without CERTavia, without third parties, purely via the DNS-anchored signature chain.

That is the difference between "we have a certificate" and "here is the cryptographic proof."

When Do I Need What?

Use case ISO 27001 SOVP / CERTavia
ISMS evidence for customers / partners
Infrastructure evidence under Art. 50 EU AI Act
Third-party risk assessment (DORA Art. 28) limited
Conformity assessment dossier (Art. 43) supplementary
Cryptographically verifiable point-in-time evidence
Governance & policy framework

Conclusion: Complement, Not Competition

ISO 27001 and SOVP solve different problems. ISO 27001 answers the question: "Do we have a functioning security management system?" SOVP answers: "Is our infrastructure demonstrably compliant at time X?"

For companies operating high-risk AI under the EU AI Act, both are relevant. ISO 27001 covers the organizational level. SOVP covers the technical infrastructure level with cryptographic verification — exactly what conformity assessment bodies under Art. 43 need as proof of Art. 50 transparency obligations in the CAD dossier.

An ISO certificate is no substitute for infrastructure evidence. But with SOVP evidence in the dossier, you have both.

Infrastructure evidence

Your SOVP evidence in 90 seconds

Free scan — no account required. CERTIFIED or FAILED with a complete cluster report.