Guides

Proving it, not just having it

EU security regulation increasingly asks for the same thing: not a policy document, but a record that the measure was actually operating over a period. These guides walk the articles that ask for it, what an assessor requests, and which evidence is externally observable.

Written by the SkyQon engineering team · Last verified 5 August 2026

NIS2

  • NIS2 Article 21(2): what counts as evidenceAll ten risk-management measures, what an assessor asks to see for each, and the honest split between what an outside-in monitor can evidence and what stays your own work.

Start somewhere smaller

If you are looking for a definition rather than a walkthrough, the glossary covers each individual trust signal — SPF, DMARC, DNSSEC, CAA, Certificate Transparency, QWAC and the rest — one page per term. The resources pages explain how to read and fix each finding in your own report.