NIS2 · DORA · CRA
Signed evidence for NIS2, DORA, and CRA
Stella Ops tracks framework readiness, signing trust, and evidence coverage across NIS2, DORA, and CRA — then exports the result as signed bundles a reviewer can verify. Every readiness figure links to the evidence behind it.
Claim boundary
Enabling starts evidence collection in conservative evidence-only mode; it does not claim regulatory compliance.
Stella Ops helps an obligated operator or manufacturer assemble and sign the artefacts a regulator wants. It never files, never certifies, and never makes you compliant — the operator always remains the regulated decision-maker.

Four packs, one evidence base
Each pack is an opt-in mapping from framework obligations to evidence Stella Ops already collects. The ownership label on each pack names who holds the regulatory obligation — enabling a pack never makes Stella Ops the obligated party.
NIS2 Evidence Pack
operator-support
Maps NIS2 risk-management and incident-evidence obligations to custody records, verdicts, and signed exports for an obligated essential or important entity.
Known limits: The incident-report write path to national authorities is in progress. Today the pack assembles incident evidence for the operator to submit.
NIS2 Evidence Pack details →DORA Operational Resilience Pack
operator-support
Maps DORA ICT-risk and incident-evidence obligations for financial entities: Register of Information exports, incident timelines, and TLPT evidence retention.
Known limits: Major-incident XBRL conformance is not claimed — no valid upstream EBA taxonomy exists to validate against.
DORA pack details →CRA Product Security Pack
manufacturer-self
Evidence for a manufacturer's own product-security obligations under the CRA: per-product SBOMs, vulnerability-handling records, and support-period security evidence.
Known limits: ENISA auto-submit transport is pending the official reporting schema. Today submissions are written to an operator-controlled filesystem drop.
CRA pack details →CRA Technical Documentation Pack
manufacturer-customer-support
Assembles the Annex VII technical documentation dossier from collected evidence: risk assessment, SBOM, and vulnerability-handling records, ready for the manufacturer's review.
Known limits: The EU Declaration of Conformity is the manufacturer's own legal act. Stella Ops assembles the dossier; it never signs the DoC.
CRA pack details →Regulatory dates
NIS2
Measures apply since 18 October 2024
DORA
Applies since 17 January 2025
CRA — reporting
Reporting obligations from 11 September 2026
CRA — full application
Applies in full from 11 December 2027
Dates are set by the regulations. Whether a given obligation applies to your organisation is a determination for your counsel.
Retention defaults
Packs apply retention to the evidence they collect. These are product defaults; each is operator-configurable.
| Artefact | Default retention |
|---|---|
| DORA Register of Information | 7 years |
| DORA incident report | 7 years |
| TLPT pack | 10 years |
| Standards mapping | 7 years |
What every pack builds on
Packs are opt-in mappings, not a separate compliance product. All four read the same evidence primitives that release control already produces.
Source → Build → Scan → Verdict → Decision → Deploy → Watch
Every stage of the custody spine carries one of three states: MISSING, RECORDED, or SIGNED. MISSING is a state a supervisor can read, not a blank cell.
Custody spine
The seven-stage record behind every release decision, from source to continuous watch of the running digest.
Evidence Locker
Content-addressed storage for everything a decision touched: SBOMs, verdicts, approvals, incident timelines.
ExportCenter signed bundles
Pack exports are sealed and signed, so a recipient can verify integrity independently of your Stella Ops instance.
Notify timelines
Notification and incident timelines recorded as ordered evidence, exportable into pack bundles.
SBOMSoftware Bill of Materials - a complete list of all packages and dependencies in your software · VEXVulnerability Exploitability eXchange - machine-readable statements about whether vulnerabilities are actually exploitable in your context · DSSEDead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures · Decision CapsuleA signed, exportable evidence bundle that seals every input and output of a release decision for offline audit and deterministic replay
Where your evidence lives
Stella Ops is developed in Europe and operated by a company registered in Bulgaria; our own services are hosted in Switzerland, which holds an EU adequacy decision for data protection. You deploy Stella Ops on infrastructure you control — the vendor never holds your evidence.
Enable a pack on your own estate
Start on the free tier and enable a pack in evidence-only mode, or bring your assurance requirements to sales.
Stella Ops is v1.0-RC1, a release candidate.
