Your result, crosswalked to the rules that are arriving.
A Provael report maps each finding to the frameworks buyers and regulators cite. Dates verified against EUR-Lex and ISO on 6 Jul 2026 — always confirm the current legal text.
Running Provael does not make a system compliant or certified — it generates measurements you can put into a conformity or assurance file.
Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.
Framework crosswalk
| Framework | What Provael maps to it | Timing |
|---|---|---|
| EU AI Act · Article 15lead hook | Accuracy, robustness & cybersecurity evidence for high-risk AI. | 2 Aug 2027 (Annex I high-risk) · 2 Aug 2028 proposed (Digital Omnibus) |
| EU Machinery Regulation 2023/1230 | Robustness evidence for AI-driven machinery safety functions. | Applies 20 Jan 2027 |
| ISO 10218-1/-2:2025 | Cybersecurity clauses for industrial robots & integration. | Published 5 Feb 2025 |
| NIST AI RMF | Measure & Manage functions for AI risk. | Referenced by auditors |
| ISO/IEC 42001:2023 | AI management system: red-teaming as an operational control. | Published Dec 2023 |
| IEC 62443 | Industrial security levels for automation & control systems. | Referenced by auditors |
| EU Cyber Resilience Act 2024/2847 | Software security posture: SBOM, vulnerability handling, secure-by-default, support period. | Reporting 11 Sep 2026 · full 11 Dec 2027 |
Not legal advice; verify the live EUR-Lex/ISO text before relying on these dates. The EU Machinery Regulation 2023/1230 applies 20 January 2027 (Art. 54, as corrected by the Corrigendum of 4 July 2023). The 2 August 2028 AI-Act date is the Digital Omnibus proposal (provisional agreement May 2026), not yet adopted; the current statutory date for Annex I high-risk AI is 2 August 2027.
How to read every row
Each mapping carries the same three caveats. Read them before you cite a clause.
Provael measures adversarial robustness — susceptibility to manipulation — not general accuracy, reliability, or functional safety.
The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility — a behavioural lower bound, not a certified worst-case bound.
Clause references are indicative; a wrong clause citation is worse than a missing one.
What an assessment emits
Every output is an open, tool-ingestible format — the evidence you file, not a certificate.
| Output | Format | What it is | Standard |
|---|---|---|---|
| SARIF report | SARIF 2.1.0 | Findings that drop straight into GitHub code scanning; each is tagged with its EAIxx ruleId. | OASIS SARIF 2.1.0 · GitHub code scanning |
| OSCAL assessment-results | OSCAL JSON | Machine-readable assessment results for GRC / ATO tooling. | NIST OSCAL |
| ML-BOM | CycloneDX ML-BOM 1.6 | A machine-learning bill of materials for the policy under test; ingests into OWASP Dependency-Track. | CycloneDX 1.6 · maps to EU AI Act Art. 11 / Annex IV |
| AVID record | AVID record | An AI Vulnerability Database record. Submission is gated and manual — never auto-submitted. | avidml.org |
| Attestation | DSSE-style envelope | A statement over the run: SHA-256 always, plus an optional Ed25519 signature that verifies offline. Our own DSSE-style envelope, not in-toto conformance. | DSSE-style · SHA-256 + optional Ed25519 |
| Scorecard | One-page PDF / HTML | A PASS/FAIL summary against your ASR threshold, an EAI heatmap, and per-attack 95% confidence intervals. | Provael scorecard |
| certify dossier | OSCAL + print-to-PDF HTML | The conformity-assessment evidence dossier for an ML-based safety component, built by the provael certify command. | OSCAL assessment-results + self-contained HTML |
Need this mapped to your system?
Book an Embodied-AI Red-Team Assessment and receive an audit-ready evidence pack with the crosswalk filled in for your policy.