Guides
Proving it, not just having it
EU security regulation increasingly asks for the same thing: not a policy document, but a record that the measure was actually operating over a period. These guides walk the articles that ask for it, what an assessor requests, and which evidence is externally observable.
Written by the SkyQon engineering team · Last verified 5 August 2026
NIS2
- NIS2 Article 21(2): what counts as evidence — All ten risk-management measures, what an assessor asks to see for each, and the honest split between what an outside-in monitor can evidence and what stays your own work.
Start somewhere smaller
If you are looking for a definition rather than a walkthrough, the glossary covers each individual trust signal — SPF, DMARC, DNSSEC, CAA, Certificate Transparency, QWAC and the rest — one page per term. The resources pages explain how to read and fix each finding in your own report.