CERTavia in the AI Act Audit Dossier
The CERTavia PDF report delivers technical infrastructure evidence for the technical documentation section of the Conformity Assessment Dossier under the EU AI Act. This page shows which scan cluster thematically covers which article and how the document is correctly embedded.
Target audience: compliance teams, legal departments, auditors, notified bodies and internal auditors.
What is the Conformity Assessment Dossier?
The Conformity Assessment Dossier (CAD) is the central documentation with which providers of high-risk AI systems demonstrate their conformity with the EU AI Act. It is a living evidence package that is continuously maintained.
Technical documentation
Description of the system, the architecture, the data sources, the testing methods and the risk assessment. CERTavia delivers the infrastructure layer of this documentation.
Declaration of conformity
Formal declaration by the provider that the system meets all applicable requirements of the EU AI Act. Must be supported by the technical documentation.
Ongoing monitoring
Post-market monitoring under Art. 72. Re-scans document infrastructure changes and demonstrate continuous conformity to supervisory authorities.
Which cluster covers which article?
CERTavia checks 80+ parameters across 6 clusters. Each cluster delivers technical evidence signals thematically related to selected regulatory requirements — not a conclusive legal assessment.
| Cluster | What is checked | EU AI Act | DORA / NIS2 |
|---|---|---|---|
| A Digital infrastructure | DNSSEC, TLS 1.3, SPF, DKIM, DMARC, HTTP security headers, HSTS | — | DORA Art. 9: ICT security. NIS2 Art. 21: security measures for essential entities. |
| B Machine readability | llms.txt / llms-full.txt, JSON-LD SoftwareApplication, API catalog (Link header), sitemap.xml consistency, agents.md | Art. 13 (thematic relevance): machine-readability and discoverability signals, no direct proof of fulfilment — Art. 13 is a contractual document between provider and deployer, not a signal scannable from outside. | — |
| C Legal compliance | Schema.org Organization/Person/FAQPage markup, canonical consistency, meta robots & language markup, internal link integrity | Art. 13 (thematic relevance): identity and discoverability signals, no direct proof of fulfilment. | — |
| D Transparency & consent | Consent granularity, consistency and coverage (cookie consent management, GDPR) | — | — |
| E Agentic readiness | MCP endpoint reachability, API catalog signal, agents.md presence, llms.txt base signal for agent access, robots.txt access control for AI crawlers (GPTBot, ClaudeBot, PerplexityBot, Google-Extended, CCBot) | Art. 13 (thematic relevance): structured, machine-readable endpoints for downstream AI agents, no direct proof of fulfilment. Art. 53 (thematic relevance): Art. 53 obligates providers of general-purpose AI models, not the scanned website — robots.txt access control for AI crawlers is not proof of Art. 53 compliance, and is at most relevant to the TDM opt-out under Art. 4(3) of the DSM Directive. | — |
| F AI governance hard gate | AI policy URL/system disclosure, human oversight evidence, Annex III use-case categorization, data governance documentation, technical documentation, incident reporting mechanism | Art. 14: evidence of human oversight mechanisms. Art. 50(2) (providers only): machine-readable labeling of AI-generated content. | Art. 73 EU AI Act / Art. 19 DORA: evidence of a documented incident reporting mechanism for major incidents. |
Correctly embedding the CERTavia PDF report
The PDF audit report is a technical evidence document with a cryptographic signature and machine-readable verification URL, not a marketing document.
Step 1: Position in the dossier
Add the CERTavia report as an attachment in the "Technical documentation" section of your CAD. Recommended label: "Infrastructure evidence – issued by CERTavia / Litzki Systems LLC, [date]".
Step 2: Reference the signature
The report contains an Ed25519 signature (RFC 8032) and a Sovereign Vault link. In your declaration of conformity, explicitly reference the Vault link as permanently verifiable point-in-time evidence.
Step 3: Machine-readable URL
Pro reports include a machine-readable verification URL. This URL can be verified directly by auditors, notified bodies and automated compliance systems against the Sovereign Vault.
Step 4: Document the re-scan cycle
For DORA conformity and continuous post-market monitoring under Art. 72 EU AI Act: document each re-scan as its own dated attachment. The signature chain provides the infrastructure history.
The relevant articles at a glance
Art. 13 EU AI Act: transparency
Providers of high-risk AI systems must ensure the systems are transparent enough for users to appropriately interpret the output. This is a contractual instruction for use from provider to deployer — not a signal scannable from outside. CERTavia clusters B/C check thematically related machine-readability and discoverability signals, not direct proof of fulfilment.
Art. 72 EU AI Act: post-market monitoring
Providers must continuously monitor the conformity of their AI systems after placing them on the market. Re-scans document infrastructure changes and demonstrate continuous conformity to supervisory authorities.
Art. 50 EU AI Act: transparency obligations
For AI systems interacting with natural persons: disclosure of the AI nature; machine-readable labeling of AI-generated content (providers). CERTavia cluster F (AI governance) checks the technical evidence points for this: ai-disclosure.json, AI policy page, deepfake disclaimer.
DORA Art. 28: ICT third-party risk
Financial entities must continuously monitor essential ICT third-party providers. CERTavia delivers the verifiable infrastructure status of third parties as an embeddable evidence document in ICT third-party contracts.
Questions from compliance teams and auditors
Is the CERTavia report alone enough for the CAD?
CERTavia delivers the infrastructure layer, but not the complete CAD. The dossier additionally requires: system description, risk analysis, test protocols, declaration of conformity and, where applicable, notified body review. CERTavia is a cryptographically verifiable component within this package.
How long is a CERTavia report usable for the CAD?
The Pro report has no automatic expiration date. The Sovereign Vault permanently documents the infrastructure state at the time of issuance. For post-market monitoring, we recommend re-scans every 90 days, especially when infrastructure parameters (DNS, TLS, endpoints) change.
Which product do I need for the CAD?
Pro (EUR 1,490) or higher: includes the Sovereign Vault without an expiration date, machine-readable verification URL and API output. Basic (EUR 490) has a 90-day Vault term and is sufficient for one-time snapshots. Annual plans are designed for continuous monitoring (DORA/NIS2).
Can a notified body or auditor verify the report directly?
Yes. Verification happens via the machine-readable verification URL in the report or directly via the Sovereign Vault link. Auditors can verify the Ed25519 signature against the public key of Litzki Systems LLC without needing to contact CERTavia.
Infrastructure evidence for your audit dossier.
Self-service: scan the domain, buy the Pro report, embed it in the CAD. Delivery time 90-120 seconds.
For enterprise inquiries, procurement and auditor onboarding: Get in touch →