Evidence for the risk register, before the incident happens.
CISOs need an external, independently verifiable evidence base for risk registers, third-party assessment and board reporting — not only after an incident, but on an ongoing basis. CERTavia delivers exactly this evidence: deterministic, cryptographically signed, in 90 to 120 seconds.
Infrastructure gaps are risk register entries
An incomplete DNS configuration, missing AI governance declarations, or inconsistent crawler directives are not merely technical footnotes — they are risk positions that belong in the risk register, third-party assessment and NIS2 documentation. CISOs need a method to capture these gaps systematically, repeatably and without manual audit effort.
CERTavia delivers exactly this method: a deterministic verification process across 80+ parameters in 6 clusters, with a binary result — SOVP-CERTIFIED or SOVP-FAILED — and a cryptographic signature as the evidence anchor.
Where the evidence is used in practice
Risk register evidence
Every scan documents the infrastructure state at a point in time — suitable as objective, external evidence for risk register entries on infrastructure and supply-chain risk, instead of relying on IT's self-reporting.
Third-party and vendor risk
For vendor risk assessments, the external infrastructure of suppliers and service providers can be checked independently — no cooperation required, since only publicly observable parameters are checked.
Board reporting
The PDF audit report with executive summary and cluster assessment can be used directly for reporting to the board and supervisory board — a robust document instead of an internal self-assessment.
Incident readiness and evidence preservation
Re-scans in the Annual Subscription cycle produce an ongoing, cryptographically signed evidence chain of the infrastructure state — an evidence trail that already exists before a security incident, instead of being reconstructed after the fact.
Demonstrate risk management measures technically
Art. 21 NIS2 requires operators of essential and important entities to implement technical and organizational risk management measures — including network and information security, supply chain security and crisis management. CERTavia delivers the infrastructural building block for demonstrating these measures: a deterministic, signed finding on technical infrastructure integrity.
The regulatory overlaps between NIS2, DORA and the EU AI Act are described in detail on the regulatory context page.
SOVP clusters → ISO 27001 / TISAX
CERTavia parameters map directly to ISO 27001:2022 Annex A controls and TISAX requirements — for CISOs running both frameworks in parallel.
| SOVP cluster | Checked parameters (selection) | ISO 27001:2022 Annex A | TISAX |
|---|---|---|---|
| A — Digital infrastructure | DNSSEC, TLS certificate chain, CAA record, HSTS, SPF, DKIM, DMARC | A.8.20 Network security, A.8.23 Web filtering, A.8.24 Cryptography, A.5.14 Information transfer | VDA ISA 5.2.5, 5.2.6 (network and transmission security) |
| B — Machine readability | llms.txt / llms-full.txt, JSON-LD SoftwareApplication, API catalog (link header), sitemap.xml consistency, agents.md | A.5.9 Inventory of information, A.5.12 Classification, A.5.14 Information transfer | VDA ISA 1.1.3 (information classification) |
| C — Legal compliance | Schema.org Organization/Person markup, canonical consistency, meta-robots & language markup, internal link integrity | A.8.9 Configuration management, A.8.11 Data masking, A.5.12 Classification | VDA ISA 2.1.1 (data quality and integrity) |
| D — Transparency & consent | robots.txt access control for AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot), consent granularity, consistency and coverage | A.8.22 Segmentation, A.8.20 Network security, A.5.23 Security in cloud usage | VDA ISA 5.2.4 (access control for external systems) |
| E — Agentic readiness | MCP endpoint reachability, API catalog signal, agents.md presence, llms.txt baseline signal for agent access | A.8.6 Capacity management, A.8.14 Redundancy, A.8.15 Logging, A.5.30 ICT readiness | VDA ISA 5.1.3 (availability), VDA ISA 6.1.2 (business continuity) |
| F — AI governance hard gate ✓/✗ | AI policy URL, deepfake disclaimer, AI training opt-out, AI contact point, EU AI Act Art. 50 conformity | A.5.36 Compliance with policies, A.5.31 Legal requirements, A.6.4 Disciplinary process | VDA ISA 1.4.1 (legal compliance), VDA ISA 1.1.1 (IS policy) |
Note on mapping depth: The mapping covers the primary relevant controls. The full SOVP parameter set (80+) addresses further controls in the A.8 (technological controls) and A.5 (organizational controls) areas. The Pro tier includes a structured JSON output that supports automated mapping into GRC systems (e.g. ISMS.online, Vanta, Drata).
80+ parameters, read as risk posture
The same deterministic parameters that IT leaders view as implementation details can be read from a CISO perspective as risk indicators.
DNS and cryptographic baseline integrity
DNSSEC, CAA records, TLS certificate chain, HTTP security headers, SPF and DKIM. Gaps here are classic attack surfaces — spoofing, certificate misuse, missing transport security.
Privacy & consent
Inconsistencies between declared and actually respected AI crawler access rules, as well as missing consent granularity, are a risk for uncontrolled data leakage to AI systems — a vector rarely captured in classic pentests.
Machine-readable identity
Missing or inconsistent authorship and entity declarations increase the risk of identity confusion and brand misuse toward automated systems.
AI governance hard gate
AI policy URL, deepfake disclaimer, AI training opt-out status and contact point for AI inquiries. Gaps here are reputational and compliance risks directly tied to Art. 50 EU AI Act.
Note on parameter basis: CERTavia distinguishes between regulatorily anchored parameters (EU AI Act Art. 50, DORA, NIS2) and SOVP governance parameters. The report lists both categories separately — with reference to the respective regulatory context.
Pricing for CISOs
Full JSON and PDF output, Sovereign Vault with no automatic expiry date, machine-readable verification URL, API output. Suitable as risk register evidence and for third-party assessments.
Quarterly re-scans, annual evidence, change notifications, up to 25 domains. Suitable for ongoing risk monitoring across your own portfolio and critical third parties.
Unlimited domains, monthly re-scans, 99.9% SLA, consolidated infrastructure evidence with Art.-50 reference and NIS2/DORA mapping, full API access. Suitable for portfolio-wide risk monitoring with SIEM integration.
With Annual Subscription and Enterprise, customer portal access is enabled automatically (login via email link, no account needed); with Pro, customer portal access is available on request.
Further reading
Verification process, validation procedure and technical deliverables explained.
Plans and pricing →Pro, Annual Subscription and Enterprise at a glance.
References →Verified real-world scan results — cryptographically signed and verifiable via the Sovereign Vault.
Whitepaper: Machine-Readable Compliance →Why the EU AI Act, DORA and NIS2 create new evidence obligations — and what machine-readable, cryptographically signed infrastructure evidence means for the ISMS.
Whitepaper: AI Agents and Trust →How autonomous AI systems verify infrastructure trust automatically — and the role of deterministic verification in the agentic web.
Risk register entry in 90 seconds
The Quick Scan delivers the Layer-0 result for your domain in 90 to 120 seconds. Free of charge, with immediately available JSON output in the Full Scan.
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, contact an accredited conformity assessment body.