Applications by Industry
01 / 05

Verifiable evidence.
By sector. By regulation.

Twelve regulated environments, eight regulatory frameworks, and a single evidence infrastructure. What varies by sector is the rule that requires the proof; the way to produce it is the same.

Sectors and Frameworks
02 / 05

Twelve sectors, eight frameworks, one evidence layer.

Critical High risk Regulated Applicable framework
Sector EU AI Act GDPR DORA NIS2 ENS eIDAS EU CRA Sectoral
Defense and Strategic Industry
Healthcare and Digital Health
AI and High-Risk Systems
Energy and Critical Infrastructure
Banking and Insurance
Pharmaceuticals and Biotechnology
Governments and Public Institutions
Law and Justice
Human Resources and Talent Acquisition
Automotive and Advanced Manufacturing
Industrial Manufacturing and ISO 9001
Media, Advertising, and Entertainment

For guidance only. “Sector-specific” encompasses MDR/IVDR, GxP, ISO 9001, and the DSM Directive. Applicability depends on the product, its intended use, and the specific legal framework.

Application Examples
03 / 05

Evidence applied to regulated environments.

Each case describes potential uses of technical evidence. Its applicability depends on the product, the purpose, and the specific legal framework.

01 Critical

Defense and Strategic Industry

Evidence related to the supply chain, versions, access, and critical decisions. The architecture must be evaluated based on classification, jurisdictions, and national security requirements.

Supply Chain · Jurisdiction · ISO Management
02 Critical

Healthcare and Digital Health

Evidence of versions, validations, human interventions, and assisted clinical decisions. The high-risk status depends on the intended use and the classification under the MDR.

MDR / IVDR · GDPR Art. 9 · ISO Management
03 Critical

AI and High-Risk Systems

Evidence of versions, logs, approvals, incidents, and human oversight. Supports the review of controls required for high-risk systems in accordance with Annex III.

Articles 9, 12, and 14
04 Critical

Energy and Critical Infrastructure

Evidence of incidents, containment measures, operational decisions, and configuration changes. NIS2 requires early warning within 24 hours and subsequent notification.

NIS2, Articles 21 and 23 · Business Continuity · ISO Management
05 High risk

Banking and Insurance

Evidence of ICT incidents, response decisions, critical changes, and controls over third parties. Strengthens the traceability of the DORA risk management framework.

DORA, Articles 5 and 28 · ICT Risk
06 High risk

Pharmaceuticals and Biotechnology

Evidence of changes, approvals, validations, and data provenance in regulated systems. Supports GxP inspections, clinical trials, and AI governance in healthcare.

GxP · System Validation · ISO Management
07 High risk

Governments and Public Institutions

Traceability of case files, automated decisions, approvals, and security controls. Enhances ENS audits and the management of electronic documents and services.

Automated decision
08 High risk

Law and Justice

Cryptographic fingerprints and timestamps for integrity, correspondence, and chronology. The evidentiary value also depends on the chain of custody and qualified services.

Integrity · Chain of Custody
09 High risk

Human Resources and Talent Acquisition

Recording of versions, criteria, human interventions, and exceptions in recruitment or workforce management systems. Classification as high risk depends on the use case.

Annex III · GDPR Art. 22
10 Regulated

Automotive and Advanced Manufacturing

Evidence of software versions, firmware, components, and vulnerabilities. Supports product lifecycle and security obligations related to digital assets.

GPSR 2023/988 · OTA / firmware · ISO management
11 Regulated

Industrial Manufacturing and ISO 9001

Product traceability, engineering changes, software versions, and approvals. Strengthens quality audits and CRA requirements for products with digital components.

CRA Art. 13 · ISO 9001 Management · SBOM
12 Regulated

Media, Advertising, and Entertainment

Evidence of declared provenance, licenses, rights reservations and versions. The AI Act establishes specific obligations for providers of general-purpose models.

DSM, Articles 3 and 4 · AI Act, Article 53

Is your organization listed in Annex III?

High-risk systems must be compliant by December 2, 2027. Executive session with an analysis of your architecture, a regulatory exposure map, and a prioritized roadmap. Deliverable within five business days.

Technical and strategic assessment. This does not constitute legal advice or certification.