For compliance teams

The technical foundation for your compliance documentation.

Compliance teams face a concrete task: documenting the technical infrastructure integrity of AI systems before the transparency obligations of Art. 50 took effect on August 2, 2026. CERTavia delivers the structured evidence document for this. Cryptographically signed, DNS-anchored, deterministically reproducible.

The compliance task

Art. 50 needs technical evidence

Art. 50 Regulation (EU) 2024/1689 – Official Journal of the European Union defines transparency obligations for AI systems that interact with natural persons or generate content — the machine-readable labeling of AI-generated content (para. 2) applies only to providers, not to operators of third-party AI tools. The requirements concern the technical infrastructure layer on which AI systems deliver content and document its provenance. The BSI QUAIDAL: quality assurance of AI training data addresses, as a national complement, specifically the quality assurance of AI training data — a central parameter of the technical evidence chain.

Compliance teams need an audit-ready document for this layer. CERTavia checks 80+ deterministic parameters across 6 clusters and produces a PDF audit report with cluster-based infrastructure assessment referencing infrastructure-relevant aspects of Art. 50. The result is binary: SOVP-CERTIFIED or SOVP-FAILED.

What CERTavia delivers for compliance teams

Structured documentation for every audit step

PDF audit report

The report contains a cluster-based infrastructure assessment referencing infrastructure-relevant aspects of Art. 50 EU AI Act. Structured into four strategic assessment areas with verdict labels and concrete action items. Ready for internal distribution to the board, legal department and external auditors.

Cryptographic signature with timestamp

Every certificate carries a cryptographic signature that documents the verification time and result in a tamper-evident way. Revisions and re-scans each produce an independent, signature-bearing document. The signature chain is fully traceable.

Sovereign Vault link

The certificate is stored in the Sovereign Vault as an evidence record retrievable at any time. The link can be forwarded to external auditors, notified bodies and authorities. In the Pro tier, the vault entry is stored with no automatic expiry date.

Machine-readable verification URL

In the Pro tier, CERTavia delivers a machine-readable endpoint. External audit systems and auditors can query the compliance status automatically. The endpoint is suitable as a technical building block for the conformity assessment dossier.

Quarterly re-scans

In the Annual Subscription tier, CERTavia automatically runs quarterly re-scans and notifies on infrastructure changes. The compliance documentation is extended with a new verified timestamp on every re-scan.

The regulatory frameworks

EU AI Act, NIS2 and DORA in one process

Compliance teams in regulated industries often work with several overlapping regulatory frameworks. CERTavia addresses the technical infrastructure layer relevant to all three frameworks.

EU AI Act Art. 50

Transparency obligations and technical evidence for AI systems; machine-readable labeling (para. 2) applies only to providers. CERTavia delivers the technical building block for the conformity documentation.

NIS2

Security requirements for critical infrastructure and digital services. CERTavia checks the infrastructure parameters that overlap with NIS2 requirements on system integrity and resilience.

DORA

Requirements for the digital operational resilience of financial entities. In the Enterprise tier, CERTavia bundles the Layer-0 evidence as consolidated infrastructure evidence with Art.-50 reference and mapping to NIS2- and DORA-relevant signals — not DORA reporting in the sense of incident reports or the register of information.

The audit process

From first check to ongoing documentation

1

First scan

The Full Scan of a domain takes 90 to 120 seconds. The result appears as SOVP-CERTIFIED or SOVP-FAILED with a full PDF audit report, cryptographic signature and Sovereign Vault link.

2

Documentation for the dossier

The PDF report provides the structured foundation for the conformity assessment dossier. Compliance teams receive a document that documents the technical infrastructure check as an independent, traceable process step.

3

Ongoing monitoring

Infrastructure changes. Deployments, DNS changes and new AI governance requirements affect the compliance status. Annual Subscription secures continuous documentation with quarterly re-scans and change notifications for up to 25 domains.

4

Portfolio overview

For compliance teams with multiple domains, a consolidated portfolio report with an overview of all checked domains is available on request.

Working with auditors and notified bodies

Prepared for external audit processes

CERTavia is designed as a technical building block for audit processes by external auditors and notified bodies. For audit organizations such as TÜV, DEKRA and auditing firms, API access for bulk validation is available on request.

Compliance teams working with an external auditor provide them with the Sovereign Vault link. The auditor retrieves the verifiable evidence directly. This allows the infrastructure documentation to move seamlessly from the internal compliance process into the external audit process.

The right tier for every audit scope

Pricing for compliance teams

Pro EUR 1,490

Full PDF audit report, Sovereign Vault with no automatic expiry date, machine-readable verification URL, API output. Suitable as a technical building block for the conformity assessment dossier.

Annual Subscription EUR 9,900 / year

Quarterly re-scans, annual evidence, change notifications, up to 25 domains. Suitable for ongoing compliance documentation across the full audit cycle.

Enterprise from EUR 24,900 / year

Unlimited domains, monthly re-scans, 99.9% SLA, consolidated infrastructure evidence with Art.-50 reference and NIS2/DORA mapping, API access. Suitable for compliance departments with portfolio-wide audit needs.

Stay informed

Art. 50 always in view

Compliance-Barometer delivers current interpretations of Art. 50, notified body updates and practical dossier tips every two weeks — directly for compliance teams. Currently published in German only.

Get started

Start your infrastructure evidence now

Enter your domain, wait 90 seconds, get a machine-readable result. No form, no registration. For enterprise inquiries, use the contact form.