Focus

Provability: what your system can prove when it matters

Auditors, enterprise buyers and regulators do not ask whether you work carefully. They ask for evidence: who changed what and when, how tenants are isolated, what can be reconstructed.

Provability is not a compliance layer you add at the end. It is created in the architecture — or not at all. An audit trail assembled afterwards from log files rarely survives the first critical follow-up question.

This page collects what belongs to the topic: the regulatory triggers (NIS2, the Cyber Resilience Act, the EU AI Act), a self-check for your current state, and the articles where we describe concrete patterns and real cases.

Regulation is not a project but a permanent condition

The duties arrive in stages — and they keep coming. Build provability into the architecture once, and every new stage is answered by the same foundation instead of fresh reaction per directive.

  1. NIS2since Oct 2024Ongoing evidence and reporting duties; management is personally accountable for oversight.
  2. DORAsince Jan 2025Financial sector: evidence on ICT risk and incidents. Indirectly relevant for software houses — via banking customers in the supply chain.
  3. EU AI Actstaged 2025–2027Logging and transparency duties for high-risk systems; records across the lifecycle.
  4. CRA: reporting dutiesfrom 11 Sep 2026Report actively exploited vulnerabilities and severe incidents within 24 to 72 hours.
  5. CRA: fully applicablefrom 11 Dec 2027Security by design, technical documentation and conformity assessment for products with digital elements.

The common denominator of every stage: evidence must come from the system — dated, immutable, queryable without developer help.

When this becomes relevant

  • An enterprise deal depends on a security questionnaire you cannot answer cleanly.
  • An audit left a finding on traceability — with a deadline.
  • NIS2 applies to you directly or through the supply chain, and the software has to carry the evidence.
  • Your product falls under the Cyber Resilience Act — and the reporting deadlines from September 2026 are not covered today.
  • AI features are in the product, and logging duties now hit the architecture.
  • After an incident, nobody could reconstruct what actually happened.

Articles on this topic

Patterns, decision guides and field notes — extended continuously.

See all insights

Not sure where evidence is missing?

Ten questions from real audits and security questionnaires. No sign-up, no data stored, evaluated right in your browser.