NIS2 · DORA · CRA

Signed evidence for NIS2, DORA, and CRA

Stella Ops tracks framework readiness, signing trust, and evidence coverage across NIS2, DORA, and CRA — then exports the result as signed bundles a reviewer can verify. Every readiness figure links to the evidence behind it.

Claim boundary

Enabling starts evidence collection in conservative evidence-only mode; it does not claim regulatory compliance.

Stella Ops helps an obligated operator or manufacturer assemble and sign the artefacts a regulator wants. It never files, never certifies, and never makes you compliant — the operator always remains the regulated decision-maker.

Stella Ops Compliance workspace listing NIS2, DORA, and CRA evidence packs with retention defaults and a priority queue.
The Compliance workspace in the Stella Ops console, shown with demo data. Packs run in evidence-only mode — they collect and map evidence; they do not claim regulatory compliance.

Four packs, one evidence base

Each pack is an opt-in mapping from framework obligations to evidence Stella Ops already collects. The ownership label on each pack names who holds the regulatory obligation — enabling a pack never makes Stella Ops the obligated party.

NIS2 Evidence Pack

operator-support

Maps NIS2 risk-management and incident-evidence obligations to custody records, verdicts, and signed exports for an obligated essential or important entity.

Known limits: The incident-report write path to national authorities is in progress. Today the pack assembles incident evidence for the operator to submit.

NIS2 Evidence Pack details →

DORA Operational Resilience Pack

operator-support

Maps DORA ICT-risk and incident-evidence obligations for financial entities: Register of Information exports, incident timelines, and TLPT evidence retention.

Known limits: Major-incident XBRL conformance is not claimed — no valid upstream EBA taxonomy exists to validate against.

DORA pack details →

CRA Product Security Pack

manufacturer-self

Evidence for a manufacturer's own product-security obligations under the CRA: per-product SBOMs, vulnerability-handling records, and support-period security evidence.

Known limits: ENISA auto-submit transport is pending the official reporting schema. Today submissions are written to an operator-controlled filesystem drop.

CRA pack details →

CRA Technical Documentation Pack

manufacturer-customer-support

Assembles the Annex VII technical documentation dossier from collected evidence: risk assessment, SBOM, and vulnerability-handling records, ready for the manufacturer's review.

Known limits: The EU Declaration of Conformity is the manufacturer's own legal act. Stella Ops assembles the dossier; it never signs the DoC.

CRA pack details →

Regulatory dates

NIS2

Measures apply since 18 October 2024

DORA

Applies since 17 January 2025

CRA — reporting

Reporting obligations from 11 September 2026

CRA — full application

Applies in full from 11 December 2027

Dates are set by the regulations. Whether a given obligation applies to your organisation is a determination for your counsel.

Retention defaults

Packs apply retention to the evidence they collect. These are product defaults; each is operator-configurable.

ArtefactDefault retention
DORA Register of Information7 years
DORA incident report7 years
TLPT pack10 years
Standards mapping7 years

What every pack builds on

Packs are opt-in mappings, not a separate compliance product. All four read the same evidence primitives that release control already produces.

Source → Build → Scan → Verdict → Decision → Deploy → Watch

Every stage of the custody spine carries one of three states: MISSING, RECORDED, or SIGNED. MISSING is a state a supervisor can read, not a blank cell.

Custody spine

The seven-stage record behind every release decision, from source to continuous watch of the running digest.

Evidence Locker

Content-addressed storage for everything a decision touched: SBOMs, verdicts, approvals, incident timelines.

ExportCenter signed bundles

Pack exports are sealed and signed, so a recipient can verify integrity independently of your Stella Ops instance.

Notify timelines

Notification and incident timelines recorded as ordered evidence, exportable into pack bundles.

SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software · VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context · DSSEDead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures · Decision CapsuleA signed, exportable evidence bundle that seals every input and output of a release decision for offline audit and deterministic replay

How evidence and audit exports work

Where your evidence lives

Developed in Europe Swiss-hosted infrastructure Self-hosted & air-gap capable

Stella Ops is developed in Europe and operated by a company registered in Bulgaria; our own services are hosted in Switzerland, which holds an EU adequacy decision for data protection. You deploy Stella Ops on infrastructure you control — the vendor never holds your evidence.

Sovereign and air-gap deployment details

Enable a pack on your own estate

Start on the free tier and enable a pack in evidence-only mode, or bring your assurance requirements to sales.

Stella Ops is v1.0-RC1, a release candidate.

Read technical docs