Regulatory alignment Technical evidence for NIS2, DORA, the EU AI Act and GDPR.

European regulation increasingly asks organizations to prove — not just claim — how critical processes run, who authorized them and how they recover. Nitrotick produces that technical execution evidence as a by-product of running the process.

Scope, stated honestly. Nitrotick contributes technical controls and evidence. It complements — and does not replace — your organizational measures, risk assessments, legal advice, audits and certifications.

At a glance

One execution layer, many obligations

Regulations and Nitrotick contribution overview
FrameworkFocusNitrotick contribution
NIS2Cybersecurity risk management, incidents, supply chainDurable recovery, tamper-evident logs, supplier revocation
DORADigital operational resilience in financeReconstructable execution, ICT third-party containment
EU AI ActLogging, traceability, human oversightBounded AI actors, approval gates, decision evidence
GDPRData minimisation, integrity, erasurePII stays at source; proofs without personal data
eIDAS 2.0Qualified trust servicesNitrotick Qualified Anchor
ESPR / DPPDigital Product PassportsVersioned, verifiable digital assets
NIS2 · Directive (EU) 2022/2555

NIS2: provable resilience and supply-chain security

NIS2 requires essential and important entities to manage cybersecurity risk across their operations and suppliers — and to report significant incidents quickly and accurately.

What it requires

  • Cybersecurity risk-management measures, including business continuity and supply-chain security (Article 21)
  • Incident handling with early warning, notification and final reporting (Article 23)
  • Management accountability for the measures taken
DORA · Regulation (EU) 2022/2554

DORA: digital operational resilience for financial entities

Since 17 January 2025, DORA requires banks, insurers, investment firms and their critical ICT providers to prove operational resilience.

What it requires

  • ICT risk-management framework and recovery capabilities
  • Classification and reporting of major ICT-related incidents
  • Management of ICT third-party risk
EU AI Act · Regulation (EU) 2024/1689

EU AI Act: logging, traceability and human oversight

The AI Act phases in obligations for high-risk AI systems, including automatic record-keeping and effective human oversight.

What it requires

  • Automatic logging of events over the lifetime of high-risk systems (Article 12)
  • Human oversight, including the ability to intervene (Article 14)
  • Deployers keep the logs generated by the system (Article 26)
GDPR · Regulation (EU) 2016/679

GDPR: proof without exposing personal data

Verifiability and privacy are often seen as a trade-off. Nitrotick keeps personal data where it belongs and still makes processes provable.

What it requires

  • Data minimisation, integrity and confidentiality (Article 5)
  • Right to erasure (Article 17)
  • Data protection by design and by default (Article 25)
eIDAS 2.0 · Regulation (EU) 2024/1183

eIDAS 2.0: qualified trust for legally sensitive evidence

Some processes need more than technical proof — they need evidence with qualified legal standing.

What it requires

  • Qualified trust services such as electronic seals and time stamps
  • Legal presumptions attached to qualified trust services
ESPR · Regulation (EU) 2024/1781

ESPR and the Digital Product Passport

The Ecodesign for Sustainable Products Regulation introduces Digital Product Passports product group by product group, starting with the battery passport under the EU Battery Regulation from February 2027.

What it requires

  • Product information that is accurate, traceable and accessible across the value chain
  • Lifecycle updates by different economic operators
FAQ

Frequently asked questions

Does Nitrotick make us NIS2 or DORA compliant?

No software alone makes an organization compliant. Nitrotick provides technical controls and execution evidence that support your NIS2, DORA and AI Act obligations; organizational measures, risk assessments and audits remain your responsibility.

Can Nitrotick evidence be used for incident reporting?

Nitrotick records every step, approval and state transition as tamper-evident evidence, which helps reconstruct accurate incident timelines for regulatory notifications.

How does Nitrotick support human oversight under the EU AI Act?

Workflows declare which steps need human approval, from whom and under which conditions. Held or rejected steps are never committed, and every decision is recorded with its context.

Where is personal data stored?

In your own systems of record. Nitrotick federates signals, claims and proofs that do not contain personal data.

Technical presentation

Talk to the architect behind Nitrotick

Describe your industry, your systems and the process you need to make provable. Message the founder on LinkedIn for a technical presentation or a tailored offer.