Guides
Proving it, not just having it
EU security regulation increasingly asks for the same thing: not a policy document, but a record that the measure was actually operating over a period. These guides walk the articles that ask for it, what an assessor requests, and which evidence is externally observable.
Written by the SkyQon engineering team · Last verified 6 August 2026
NIS2
- NIS2 Article 21(2): what counts as evidence — All ten risk-management measures, what an assessor asks to see for each, and the honest split between what an outside-in monitor can evidence and what stays your own work.
DORA
- DORA: what counts as technical evidence — The articles that leave externally observable traces — Article 9 and the RTS on encryption, the Article 8 asset register, testing under Articles 24 and 25 — plus the Register of Information and concentration duties that reach ICT suppliers through their customers.
Cyber Resilience Act
- The Cyber Resilience Act: your product, not your estate — What the CRA regulates, why Article 14 reporting starts 11 September 2026 and reaches products already on the market, and the honest line between product conformity and anything an outside-in monitor can see.
Start somewhere smaller
If you are looking for a definition rather than a walkthrough, the glossary covers each individual trust signal — SPF, DMARC, DNSSEC, CAA, Certificate Transparency, QWAC and the rest — one page per term. The resources pages explain how to read and fix each finding in your own report.