ProductEvidenceTop 10ComplianceDocsStar on GitHubQuickstart
EVIDENCE, MAPPED · lead hook: EU AI Act Article 15

Your result, crosswalked to the rules that are arriving.

A Provael report maps each finding to the frameworks buyers and regulators cite. Dates verified against EUR-Lex and ISO on 6 Jul 2026 — always confirm the current legal text.

Evidence, not certification.Independent · not affiliated with ISO, the EU, NIST, IEC, OWASP or MITRE
Evidence, not certification

Running Provael does not make a system compliant or certified — it generates measurements you can put into a conformity or assurance file.

Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

Framework crosswalk

Framework crosswalk · each framework links to its detail page
FrameworkWhat Provael maps to itTiming
EU AI Act · Article 15lead hookAccuracy, robustness & cybersecurity evidence for high-risk AI.2 Aug 2027 (Annex I high-risk)
· 2 Aug 2028 proposed (Digital Omnibus)
EU Machinery Regulation 2023/1230Robustness evidence for AI-driven machinery safety functions.Applies 20 Jan 2027
ISO 10218-1/-2:2025Cybersecurity clauses for industrial robots & integration.Published 5 Feb 2025
NIST AI RMFMeasure & Manage functions for AI risk.Referenced by auditors
ISO/IEC 42001:2023AI management system: red-teaming as an operational control.Published Dec 2023
IEC 62443Industrial security levels for automation & control systems.Referenced by auditors
EU Cyber Resilience Act 2024/2847Software security posture: SBOM, vulnerability handling, secure-by-default, support period.Reporting 11 Sep 2026 · full 11 Dec 2027

How to read every row

Each mapping carries the same three caveats. Read them before you cite a clause.

adversarial-only

Provael measures adversarial robustness — susceptibility to manipulation — not general accuracy, reliability, or functional safety.

evidence-not-certification

The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.

behavioural-not-worst-case

Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility — a behavioural lower bound, not a certified worst-case bound.

What an assessment emits

Every output is an open, tool-ingestible format — the evidence you file, not a certificate.

Evidence outputs · open formats, ingestible by standard GRC and code-scanning tools
OutputFormatWhat it isStandard
SARIF reportSARIF 2.1.0Findings that drop straight into GitHub code scanning; each is tagged with its EAIxx ruleId.OASIS SARIF 2.1.0 · GitHub code scanning
OSCAL assessment-resultsOSCAL JSONMachine-readable assessment results for GRC / ATO tooling.NIST OSCAL
ML-BOMCycloneDX ML-BOM 1.6A machine-learning bill of materials for the policy under test; ingests into OWASP Dependency-Track.CycloneDX 1.6 · maps to EU AI Act Art. 11 / Annex IV
AVID recordAVID recordAn AI Vulnerability Database record. Submission is gated and manual — never auto-submitted.avidml.org
AttestationDSSE-style envelopeA statement over the run: SHA-256 always, plus an optional Ed25519 signature that verifies offline. Our own DSSE-style envelope, not in-toto conformance.DSSE-style · SHA-256 + optional Ed25519
ScorecardOne-page PDF / HTMLA PASS/FAIL summary against your ASR threshold, an EAI heatmap, and per-attack 95% confidence intervals.Provael scorecard
certify dossierOSCAL + print-to-PDF HTMLThe conformity-assessment evidence dossier for an ML-based safety component, built by the provael certify command.OSCAL assessment-results + self-contained HTML
Redacted sample evidence pack
SARIF 2.1.0 + summary · the artifact an assessment delivers · redacted for public use

Need this mapped to your system?

Book an Embodied-AI Red-Team Assessment and receive an audit-ready evidence pack with the crosswalk filled in for your policy.