Guides

Proving it, not just having it

EU security regulation increasingly asks for the same thing: not a policy document, but a record that the measure was actually operating over a period. These guides walk the articles that ask for it, what an assessor requests, and which evidence is externally observable.

Written by the SkyQon engineering team · Last verified 6 August 2026

NIS2

  • NIS2 Article 21(2): what counts as evidenceAll ten risk-management measures, what an assessor asks to see for each, and the honest split between what an outside-in monitor can evidence and what stays your own work.

DORA

  • DORA: what counts as technical evidenceThe articles that leave externally observable traces — Article 9 and the RTS on encryption, the Article 8 asset register, testing under Articles 24 and 25 — plus the Register of Information and concentration duties that reach ICT suppliers through their customers.

Cyber Resilience Act

Start somewhere smaller

If you are looking for a definition rather than a walkthrough, the glossary covers each individual trust signal — SPF, DMARC, DNSSEC, CAA, Certificate Transparency, QWAC and the rest — one page per term. The resources pages explain how to read and fix each finding in your own report.