# Provael compliance crosswalk

> How a Provael red-team result maps to the frameworks buyers and regulators cite. Dates
> verified against EUR-Lex and ISO on 6 Jul 2026. Not legal advice.

**Evidence, not certification.** Running Provael does not make a system compliant or certified — it generates measurements you can put into a conformity or assurance file. Independent project. Not affiliated with or endorsed by ISO, the EU, NIST, IEC, OWASP, or MITRE. Not legal advice.

- [EU AI Act · Article 15](https://www.provael.com/compliance/eu-ai-act-article-15): Accuracy, robustness & cybersecurity evidence for high-risk AI. — Annex I high-risk obligations apply 2 August 2027 (statutory).
- [EU Machinery Regulation 2023/1230](https://www.provael.com/compliance/eu-machinery-regulation): Robustness evidence for AI-driven machinery safety functions. — Applies 20 January 2027 (Art. 54, as corrected by the Corrigendum of 4 July 2023).
- [ISO 10218-1/-2:2025](https://www.provael.com/compliance/iso-10218): Cybersecurity clauses for industrial robots & integration. — ISO 10218-1:2025 and ISO 10218-2:2025 were published 5 February 2025.
- [NIST AI RMF](https://www.provael.com/compliance/nist-ai-rmf): Measure & Manage functions for AI risk. — Voluntary framework; widely referenced by auditors and procurement.
- [ISO/IEC 42001:2023](https://www.provael.com/compliance/iso-42001): AI management system: red-teaming as an operational control. — Published December 2023 — the first certifiable AI management-system standard.
- [IEC 62443](https://www.provael.com/compliance/iec-62443): Industrial security levels for automation & control systems. — Series of standards; referenced by industrial-security assessors.
- [EU Cyber Resilience Act 2024/2847](https://www.provael.com/compliance/eu-cyber-resilience-act): Software security posture: SBOM, vulnerability handling, secure-by-default, support period. — Reporting obligations (Art. 14) apply 11 September 2026; full application 11 December 2027.

## Evidence Provael emits

- **SARIF report** (SARIF 2.1.0) — Findings that drop straight into GitHub code scanning; each is tagged with its EAIxx ruleId. [OASIS SARIF 2.1.0 · GitHub code scanning]
- **OSCAL assessment-results** (OSCAL JSON) — Machine-readable assessment results for GRC / ATO tooling. [NIST OSCAL]
- **ML-BOM** (CycloneDX ML-BOM 1.6) — A machine-learning bill of materials for the policy under test; ingests into OWASP Dependency-Track. [CycloneDX 1.6 · maps to EU AI Act Art. 11 / Annex IV]
- **AVID record** (AVID record) — An AI Vulnerability Database record. Submission is gated and manual — never auto-submitted. [avidml.org]
- **Attestation** (DSSE-style envelope) — A statement over the run: SHA-256 always, plus an optional Ed25519 signature that verifies offline. Our own DSSE-style envelope, not in-toto conformance. [DSSE-style · SHA-256 + optional Ed25519]
- **Scorecard** (One-page PDF / HTML) — A PASS/FAIL summary against your ASR threshold, an EAI heatmap, and per-attack 95% confidence intervals. [Provael scorecard]
- **certify dossier** (OSCAL + print-to-PDF HTML) — The conformity-assessment evidence dossier for an ML-based safety component, built by the provael certify command. [OSCAL assessment-results + self-contained HTML]

## How to read every mapping (caveats on every control)

- **adversarial-only** — Provael measures adversarial robustness — susceptibility to manipulation — not general accuracy, reliability, or functional safety.
- **evidence-not-certification** — The output is evidence you file, not a certificate. Provael is not a notified body, a lab, or a certification scheme.
- **behavioural-not-worst-case** — Attacks are templated and auditable, not gradient- or search-optimised. Results are a floor on susceptibility — a behavioural lower bound, not a certified worst-case bound.

## Verified dates (do not paraphrase incorrectly)

- EU AI Act Art. 15 high-risk (Annex I): 2 August 2027 statutory; 2 August 2028 is the Digital Omnibus PROPOSAL (not yet adopted).
- EU Machinery Regulation 2023/1230: applies 20 January 2027 (Art. 54, Corrigendum of 4 July 2023).
- ISO 10218-1:2025 / -2:2025: published 5 February 2025.
- EU Cyber Resilience Act 2024/2847: reporting 11 September 2026; full application 11 December 2027.

---
Provael · Prove it. Prevail. · Apache-2.0 · https://github.com/provael/provael
Not legal advice; verify regulatory dates against the primary source.
