Compliance & Legal

CERTavia in the AI Act Audit Dossier

The CERTavia PDF report delivers technical infrastructure evidence for the technical documentation section of the Conformity Assessment Dossier under the EU AI Act. This page shows which scan cluster thematically covers which article and how the document is correctly embedded.

Target audience: compliance teams, legal departments, auditors, notified bodies and internal auditors.

Foundation

What is the Conformity Assessment Dossier?

The Conformity Assessment Dossier (CAD) is the central documentation with which providers of high-risk AI systems demonstrate their conformity with the EU AI Act. It is a living evidence package that is continuously maintained.

Technical documentation

Description of the system, the architecture, the data sources, the testing methods and the risk assessment. CERTavia delivers the infrastructure layer of this documentation.

Declaration of conformity

Formal declaration by the provider that the system meets all applicable requirements of the EU AI Act. Must be supported by the technical documentation.

Ongoing monitoring

Post-market monitoring under Art. 72. Re-scans document infrastructure changes and demonstrate continuous conformity to supervisory authorities.

Cluster mapping

Which cluster covers which article?

CERTavia checks 80+ parameters across 6 clusters. Each cluster delivers technical evidence signals thematically related to selected regulatory requirements — not a conclusive legal assessment.

Cluster What is checked EU AI Act DORA / NIS2
A Digital infrastructure DNSSEC, TLS 1.3, SPF, DKIM, DMARC, HTTP security headers, HSTS DORA Art. 9: ICT security. NIS2 Art. 21: security measures for essential entities.
B Machine readability llms.txt / llms-full.txt, JSON-LD SoftwareApplication, API catalog (Link header), sitemap.xml consistency, agents.md Art. 13 (thematic relevance): machine-readability and discoverability signals, no direct proof of fulfilment — Art. 13 is a contractual document between provider and deployer, not a signal scannable from outside.
C Legal compliance Schema.org Organization/Person/FAQPage markup, canonical consistency, meta robots & language markup, internal link integrity Art. 13 (thematic relevance): identity and discoverability signals, no direct proof of fulfilment.
D Transparency & consent Consent granularity, consistency and coverage (cookie consent management, GDPR)
E Agentic readiness MCP endpoint reachability, API catalog signal, agents.md presence, llms.txt base signal for agent access, robots.txt access control for AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot) Art. 13 (thematic relevance): structured, machine-readable endpoints for downstream AI agents, no direct proof of fulfilment. Art. 53 (thematic relevance): Art. 53 obligates providers of general-purpose AI models, not the scanned website — robots.txt access control for AI crawlers is not proof of Art. 53 compliance, and is at most relevant to the TDM opt-out under Art. 4(3) of the DSM Directive.
F AI governance hard gate AI policy URL/system disclosure, human oversight evidence, Annex III use-case categorization, data governance documentation, technical documentation, incident reporting mechanism Art. 14: evidence of human oversight mechanisms. Art. 50(2) (providers only): machine-readable labeling of AI-generated content. Art. 73 EU AI Act / Art. 19 DORA: evidence of a documented incident reporting mechanism for major incidents.
How to use the report

Correctly embedding the CERTavia PDF report

The PDF audit report is a technical evidence document with a cryptographic signature and machine-readable verification URL, not a marketing document.

Step 1: Position in the dossier

Add the CERTavia report as an attachment in the "Technical documentation" section of your CAD. Recommended label: "Infrastructure evidence – issued by CERTavia / Litzki Systems LLC, [date]".

Step 2: Reference the signature

The report contains an Ed25519 signature (RFC 8032) and a Sovereign Vault link. In your declaration of conformity, explicitly reference the Vault link as permanently verifiable point-in-time evidence.

Step 3: Machine-readable URL

Pro reports include a machine-readable verification URL. This URL can be verified directly by auditors, notified bodies and automated compliance systems against the Sovereign Vault.

Step 4: Document the re-scan cycle

For DORA conformity and continuous post-market monitoring under Art. 72 EU AI Act: document each re-scan as its own dated attachment. The signature chain provides the infrastructure history.

Legal basis

The relevant articles at a glance

Art. 13 EU AI Act: transparency

Providers of high-risk AI systems must ensure the systems are transparent enough for users to appropriately interpret the output. This is a contractual instruction for use from provider to deployer — not a signal scannable from outside. CERTavia clusters B/C check thematically related machine-readability and discoverability signals, not direct proof of fulfilment.

Art. 72 EU AI Act: post-market monitoring

Providers must continuously monitor the conformity of their AI systems after placing them on the market. Re-scans document infrastructure changes and demonstrate continuous conformity to supervisory authorities.

Art. 50 EU AI Act: transparency obligations

For AI systems interacting with natural persons: disclosure of the AI nature; machine-readable labeling of AI-generated content (providers). CERTavia cluster F (AI governance) checks the technical evidence points for this: ai-disclosure.json, AI policy page, deepfake disclaimer.

DORA Art. 28: ICT third-party risk

Financial entities must continuously monitor essential ICT third-party providers. CERTavia delivers the verifiable infrastructure status of third parties as an embeddable evidence document in ICT third-party contracts.

Frequently asked questions

Questions from compliance teams and auditors

Is the CERTavia report alone enough for the CAD?

CERTavia delivers the infrastructure layer, but not the complete CAD. The dossier additionally requires: system description, risk analysis, test protocols, declaration of conformity and, where applicable, notified body review. CERTavia is a cryptographically verifiable component within this package.

How long is a CERTavia report usable for the CAD?

The Pro report has no automatic expiration date. The Sovereign Vault permanently documents the infrastructure state at the time of issuance. For post-market monitoring, we recommend re-scans every 90 days, especially when infrastructure parameters (DNS, TLS, endpoints) change.

Which product do I need for the CAD?

Pro (EUR 1,490) or higher: includes the Sovereign Vault without an expiration date, machine-readable verification URL and API output. Basic (EUR 490) has a 90-day Vault term and is sufficient for one-time snapshots. Annual plans are designed for continuous monitoring (DORA/NIS2).

Can a notified body or auditor verify the report directly?

Yes. Verification happens via the machine-readable verification URL in the report or directly via the Sovereign Vault link. Auditors can verify the Ed25519 signature against the public key of Litzki Systems LLC without needing to contact CERTavia.

Infrastructure evidence for your audit dossier.

Self-service: scan the domain, buy the Pro report, embed it in the CAD. Delivery time 90-120 seconds.

For enterprise inquiries, procurement and auditor onboarding: Get in touch →