The technical foundation for your compliance documentation.
Compliance teams face a concrete task: documenting the technical infrastructure integrity of AI systems before the transparency obligations of Art. 50 took effect on August 2, 2026. CERTavia delivers the structured evidence document for this. Cryptographically signed, DNS-anchored, deterministically reproducible.
Art. 50 needs technical evidence
Art. 50 Regulation (EU) 2024/1689 – Official Journal of the European Union defines transparency obligations for AI systems that interact with natural persons or generate content — the machine-readable labeling of AI-generated content (para. 2) applies only to providers, not to operators of third-party AI tools. The requirements concern the technical infrastructure layer on which AI systems deliver content and document its provenance. The BSI QUAIDAL: quality assurance of AI training data addresses, as a national complement, specifically the quality assurance of AI training data — a central parameter of the technical evidence chain.
Compliance teams need an audit-ready document for this layer. CERTavia checks 80+ deterministic parameters across 6 clusters and produces a PDF audit report with cluster-based infrastructure assessment referencing infrastructure-relevant aspects of Art. 50. The result is binary: SOVP-CERTIFIED or SOVP-FAILED.
Structured documentation for every audit step
PDF audit report
The report contains a cluster-based infrastructure assessment referencing infrastructure-relevant aspects of Art. 50 EU AI Act. Structured into four strategic assessment areas with verdict labels and concrete action items. Ready for internal distribution to the board, legal department and external auditors.
Cryptographic signature with timestamp
Every certificate carries a cryptographic signature that documents the verification time and result in a tamper-evident way. Revisions and re-scans each produce an independent, signature-bearing document. The signature chain is fully traceable.
Sovereign Vault link
The certificate is stored in the Sovereign Vault as an evidence record retrievable at any time. The link can be forwarded to external auditors, notified bodies and authorities. In the Pro tier, the vault entry is stored with no automatic expiry date.
Machine-readable verification URL
In the Pro tier, CERTavia delivers a machine-readable endpoint. External audit systems and auditors can query the compliance status automatically. The endpoint is suitable as a technical building block for the conformity assessment dossier.
Quarterly re-scans
In the Annual Subscription tier, CERTavia automatically runs quarterly re-scans and notifies on infrastructure changes. The compliance documentation is extended with a new verified timestamp on every re-scan.
EU AI Act, NIS2 and DORA in one process
Compliance teams in regulated industries often work with several overlapping regulatory frameworks. CERTavia addresses the technical infrastructure layer relevant to all three frameworks.
EU AI Act Art. 50
Transparency obligations and technical evidence for AI systems; machine-readable labeling (para. 2) applies only to providers. CERTavia delivers the technical building block for the conformity documentation.
NIS2
Security requirements for critical infrastructure and digital services. CERTavia checks the infrastructure parameters that overlap with NIS2 requirements on system integrity and resilience.
DORA
Requirements for the digital operational resilience of financial entities. In the Enterprise tier, CERTavia bundles the Layer-0 evidence as consolidated infrastructure evidence with Art.-50 reference and mapping to NIS2- and DORA-relevant signals — not DORA reporting in the sense of incident reports or the register of information.
From first check to ongoing documentation
First scan
The Full Scan of a domain takes 90 to 120 seconds. The result appears as SOVP-CERTIFIED or SOVP-FAILED with a full PDF audit report, cryptographic signature and Sovereign Vault link.
Documentation for the dossier
The PDF report provides the structured foundation for the conformity assessment dossier. Compliance teams receive a document that documents the technical infrastructure check as an independent, traceable process step.
Ongoing monitoring
Infrastructure changes. Deployments, DNS changes and new AI governance requirements affect the compliance status. Annual Subscription secures continuous documentation with quarterly re-scans and change notifications for up to 25 domains.
Portfolio overview
For compliance teams with multiple domains, a consolidated portfolio report with an overview of all checked domains is available on request.
Prepared for external audit processes
CERTavia is designed as a technical building block for audit processes by external auditors and notified bodies. For audit organizations such as TÜV, DEKRA and auditing firms, API access for bulk validation is available on request.
Compliance teams working with an external auditor provide them with the Sovereign Vault link. The auditor retrieves the verifiable evidence directly. This allows the infrastructure documentation to move seamlessly from the internal compliance process into the external audit process.
Pricing for compliance teams
Full PDF audit report, Sovereign Vault with no automatic expiry date, machine-readable verification URL, API output. Suitable as a technical building block for the conformity assessment dossier.
Quarterly re-scans, annual evidence, change notifications, up to 25 domains. Suitable for ongoing compliance documentation across the full audit cycle.
Unlimited domains, monthly re-scans, 99.9% SLA, consolidated infrastructure evidence with Art.-50 reference and NIS2/DORA mapping, API access. Suitable for compliance departments with portfolio-wide audit needs.
Art. 50 always in view
Compliance-Barometer delivers current interpretations of Art. 50, notified body updates and practical dossier tips every two weeks — directly for compliance teams. Currently published in German only.
Further reading
Risk classes, enforcement phases and technical infrastructure implications at a glance.
Annex III — high-risk AI in detail →High-risk classification and technical evidence requirements explained in detail.
How CERTavia works →The deterministic verification process and validation procedure explained.
Plans and pricing →All tiers at a glance, from the Pro report to Annual Subscription.
For compliance managers and GRC teams →Specifically for integration into GRC systems (ServiceNow, MetricStream, Archer) and the conformity assessment dossier.
For data protection officers →Technical cross-check between the privacy notice and the actual AI governance configuration.
NIS2 and high-risk AI: who is affected? (Blog, DE) →Target groups, scope and regulatory framework of the NIS2 directive for high-risk AI operators.
NIS2 obligations and implementation (Blog, DE) →4-step implementation plan, technical requirements and prioritized action items for Germany.
Start your infrastructure evidence now
Enter your domain, wait 90 seconds, get a machine-readable result. No form, no registration. For enterprise inquiries, use the contact form.
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, contact an accredited conformity assessment body.