The infrastructure evidence that fits your dossier.
Art. 50 EU AI Act requires transparency about AI use; the machine-readable labeling of AI output (para. 2) applies only to providers who develop or offer a generative AI system under their own brand. CERTavia supplies the infrastructure evidence for your conformity assessment dossier: machine-readable, cryptographically signed, importable into existing GRC systems — ready for external auditors and notified bodies.
What Art. 50 specifically requires from you
Art. 50 EU AI Act obliges providers and deployers of AI systems to disclose AI use, label AI output in a machine-readable way, and document its provenance verifiably. This evidence must be available to external auditors and notified bodies — as part of the conformity assessment dossier under Art. 43.
CERTavia delivers the infrastructure building block for this evidence: a deterministic, cryptographically signed finding on your domain's technical infrastructure. The result complements the legal conformity assessment under Art. 43 as a technical layer-0 record that can be handed directly to auditors.
Four deliverables for the dossier
PDF audit report for the dossier
Structured finding with cluster-based Art. 50 relevance rating (Critical / Relevant / Informational). Includes executive summary, strategic assessment and Sovereign Vault link. Ready for internal filing and direct handover to external auditors and notified bodies.
Machine-readable verification URL
External auditors and notified bodies can query the compliance status automatically — without system access, timestamped, tamper-evident. The stable endpoint follows the Sovereign Vault Protocol (Pro and above: permanently retrievable via token).
JSON + CSV for GRC systems
The structured output imports into ServiceNow, MetricStream, Archer and comparable GRC platforms. All 80+ parameter values with cluster scores, verdict and Art. 50 reference — no manual reformatting.
Sovereign Vault permanently retrievable via token
The audit record is cryptographically secured with no automatic expiry (Pro and above). Remains evidentiary even after an audit period — the state at the time of the check is documented immutably.
Three steps to a dossier building block
Quick Scan — free, 90 seconds
Enter a domain, the scan runs automatically. Initial assessment: CES score, cluster overview, SOVP-CERTIFIED or SOVP-FAILED. No login, no registration.
Order Pro or Annual Subscription
For the full Art. 50 evidence with cryptographic signature, Sovereign Vault permanently retrievable via token, and machine-readable verification URL. PDF report, JSON output and CSV available directly after the scan completes.
Export and filing
PDF into the conformity assessment dossier, JSON/CSV into the GRC system, Sovereign Vault link to external auditors. Annual Subscription customers receive automatic re-scans and change notifications.
What CERTavia delivers — and what it doesn't
What CERTavia delivers
The infrastructure layer-0 evidence under Art. 50: a deterministic finding on technical infrastructure integrity, cryptographically signed, machine-readable, audit-ready. Complementary to GRC processes, ISO certifications and legal counsel — as a technical building block in the conformity assessment dossier.
What CERTavia does not replace
CERTavia is not a legal opinion and not a conformity assessment under Art. 43. For legally binding conformity assessments, contact an accredited notified body (TÜV, DEKRA, BSI-accredited bodies). CERTavia addresses the infrastructure layer — not the legal, organizational or content compliance assessment.
For the dossier: The CERTavia Pro report can be documented in the conformity assessment dossier as "infrastructure evidence under Art. 50 EU AI Act." The Sovereign Vault link enables external auditors to verify independently — timestamped, without system access.
FAQ for compliance managers
Will a notified body / conformity assessment body accept this report?
The EU AI Act does not prescribe a specific evidence format — it requires that Art. 50 requirements (transparency, machine-readable labeling, provenance) are demonstrably met. The CERTavia report is a cryptographically signed, deterministic finding with an Ed25519 signature and DNS-anchored timestamp, independently verifiable of CERTavia. Accredited conformity assessment bodies (TÜV, DEKRA, BSI-accredited bodies) can perform verification via the machine-readable verification URL or the Sovereign Vault link — without system access and without needing to contact CERTavia. The report can be submitted in the conformity assessment dossier as "infrastructure evidence under Art. 50 EU AI Act."
Is a CERTavia report sufficient for the complete conformity assessment dossier?
CERTavia delivers the infrastructure layer (Art. 50), but not the complete CAD. The dossier additionally requires: system description, risk analysis, test protocols, declaration of conformity and, where applicable, notified-body review. CERTavia is a cryptographically verifiable building block within this package — specifically for the technical infrastructure evidence.
How long is a CERTavia report usable in the dossier?
The PDF audit report, the Ed25519 signature and the DNS-anchored timestamp remain permanently valid and document the infrastructure state at the time of the scan. The Sovereign Vault link (Pro and above: permanent; Basic: 90 days) enables external auditors to verify online. For post-market monitoring we recommend re-scans every 90 days or upon infrastructure changes.
How do I get access to the customer portal?
With Annual Starter, Annual Subscription and Enterprise, portal access is unlocked automatically upon purchase — no separate account setup needed, login via email link to your purchase address (no password required). With Basic and Pro, the report is delivered directly by email via the scan access code; portal access here is available on request through our contact form.
Pricing for compliance managers and GRC teams
PDF audit report, cryptographic signature, Sovereign Vault available for 90 days (local archiving required afterward). Suitable for an initial assessment and dossier baseline.
Sovereign Vault permanently retrievable via token, machine-readable verification URL, JSON + CSV export. Recommended as a dossier building block and for GRC system integration.
Quarterly re-scans, annual evidence, change notifications, up to 25 domains. Suitable for ongoing audit requirements with continuous dossier maintenance.
Further reading
What Art. 50 specifically requires from compliance teams and how the CERTavia report is used. (DE)
How CERTavia works →The deterministic verification process, validation procedure and technical deliverables explained.
Plans and pricing →All packages from Basic to Enterprise at a glance.
Whitepaper: EU AI Act infrastructure compliance →A deeper look at Art. 50, DORA overlap and the infrastructure evidence approach. (DE)
For compliance teams in general →Broader overview for compliance teams without a GRC-system focus — including NIS2 and DORA context.
References →Verified scan results from real deployments — cryptographically signed and verifiable via the Sovereign Vault. (DE)
Founding Partner program →For auditors and GRC consultancies: early-stage terms and a co-branding option for reports. (DE)
Determine your infrastructure status now.
The free domain scan checks 80+ parameters against SOVP and delivers a CERTIFIED / FAILED result in 90 seconds — ready to attach to your conformity assessment dossier.
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, contact an accredited conformity assessment body.