Focus
Provability: what your system can prove when it matters
Auditors, enterprise buyers and regulators do not ask whether you work carefully. They ask for evidence: who changed what and when, how tenants are isolated, what can be reconstructed.
Provability is not a compliance layer you add at the end. It is created in the architecture — or not at all. An audit trail assembled afterwards from log files rarely survives the first critical follow-up question.
This page collects what belongs to the topic: the regulatory triggers (NIS2, the Cyber Resilience Act, the EU AI Act), a self-check for your current state, and the articles where we describe concrete patterns and real cases.
Where to start
NIS2-ready software
Which evidence an audit actually asks for — and what of it is architecture work.
OpenEU AI Act
Logging and transparency duties the system itself has to meet.
OpenCyber Resilience Act
Reporting duties from 11 Sep 2026 — and what the system must be able to do.
OpenProvability check
Ten questions, answered in five minutes: where is evidence missing today?
OpenRegulation is not a project but a permanent condition
The duties arrive in stages — and they keep coming. Build provability into the architecture once, and every new stage is answered by the same foundation instead of fresh reaction per directive.
- NIS2since Oct 2024Ongoing evidence and reporting duties; management is personally accountable for oversight.
- DORAsince Jan 2025Financial sector: evidence on ICT risk and incidents. Indirectly relevant for software houses — via banking customers in the supply chain.
- EU AI Actstaged 2025–2027Logging and transparency duties for high-risk systems; records across the lifecycle.
- CRA: reporting dutiesfrom 11 Sep 2026Report actively exploited vulnerabilities and severe incidents within 24 to 72 hours.
- CRA: fully applicablefrom 11 Dec 2027Security by design, technical documentation and conformity assessment for products with digital elements.
The common denominator of every stage: evidence must come from the system — dated, immutable, queryable without developer help.
When this becomes relevant
- An enterprise deal depends on a security questionnaire you cannot answer cleanly.
- An audit left a finding on traceability — with a deadline.
- NIS2 applies to you directly or through the supply chain, and the software has to carry the evidence.
- Your product falls under the Cyber Resilience Act — and the reporting deadlines from September 2026 are not covered today.
- AI features are in the product, and logging duties now hit the architecture.
- After an incident, nobody could reconstruct what actually happened.
Articles on this topic
Patterns, decision guides and field notes — extended continuously.
Engineering & deliveryField notes
Tamper-proof logging: why database logs do not count in an audit
Almost every system logs. Audits still fail on the question of who changed what and when. The difference between a log and evidence — and what creates it.
Engineering & deliveryFoundation
Tenant separation that survives the security questionnaire
One forgotten filter is a reportable incident. Why isolation in application code is not evidence — and which models enterprise buyers accept.
Engineering & deliveryField notes
Who skipped the credit check? Order fulfilment across five systems
One wrong delivery, five systems, three hours of searching — and a simple new approval rule costs eight weeks. A worked example from B2B distribution: how an event foundation solves traceability and changeability at once.
Engineering & deliveryField notes
Who promised what? When nobody can reconstruct what happened
A customer asks about a commitment made months ago. Five people spend two and a half hours across six tools — and the results contradict each other. A worked example of how a single source of truth makes that question answerable.
Engineering & deliveryField notes
Multi-tenancy with Keycloak: what belongs in the token and what doesn't
Multi-tenancy rarely fails at the login screen — it fails at the model behind it. A practical guide to realms, roles, token design and migrating existing users.
Engineering & deliveryField notes
Production readiness in the AI factory: what to check when agents write the code
Requirements are agent-readable, the arc42 is maintained, the pipeline is green. The old question — does it run? — has become trivial. The new one: how do we know a change is right when nobody read every line?
Engineering & deliveryField notes
Event sourcing without fear: when it pays off and when it doesn't
Event sourcing is often seen as a risk. In reality it is a tool with a very specific use case: wherever the history of data matters more than its current state.
People & cultureNote
Twelve roles become three: what Gartner's team shapes mean for provability
Gartner expects smaller engineering teams. The role map behind it mostly removes translation roles — and with them the places where decisions used to get written down as a side effect.
Not sure where evidence is missing?
Ten questions from real audits and security questionnaires. No sign-up, no data stored, evaluated right in your browser.