AEP-012 / PUBLIC EVIDENCE INFRASTRUCTUREsource-bound profiles · canonical receipts · local verificationbounded claim: no legal certification · no supervisory approval
Catalogue / Profile registry / Source-bound acts

A public register of machine profiles.

The catalogue shows which regulated acts have machine-readable evidence profiles and what each profile is allowed to claim.

Implemented profiles are separated from planned or experimental workpapers. That distinction should remain visible.

01 / Implemented

Profiles already under the sheath.

These are treated as public evidence objects: not legal advice, not certification, not a proprietary compliance ontology.

ProfileRegulatory sourceSource stateEvidence boundaryPublic artefact
DORA ICT incident initial notificationRegulation (EU) 2022/2554, Article 19(4)Official artefacts pinned by SHA-256Source-binding and field declaration onlyField browser · Generated view · JSON profile
EUDR due diligence statement preparationRegulation (EU) 2023/1115Profile catalogue entry available in repositoryPreparation record, not legal clearanceGitHub
ActProof software release recordProject governance / release evidenceImplemented as reusable profileRelease evidence, not security certificationGitHub
Standards engagement recordPublic standards participation evidenceImplemented as reusable profileEngagement record, not endorsementGitHub
02 / Planned

NIS2 Article 23 enters as an incident profile, not as a claim of compliance.

NIS2 Article 23 enters as a source-bound incident reporting profile. It supports evidence preparation and verification boundaries, not regulatory approval, and that distinction stays explicit in the profile itself.

NEXT-02DORA final report

Complexity and maturity workpaper.

Useful for evaluating which reporting fields are worth measuring, how mature they are, and where implementation risk concentrates.

NEXT-03Cross-act portfolio

One architecture, many profiles.

DORA, NIS2, EUDR, CSRD and GDPR can share evidence architecture while preserving source-specific boundaries.

03 / Registry fields

Every catalogue row should be auditable.

The catalogue should not only list names. It should list maturity, source authority, artefact binding, field profile, evidence labels, signature policy and refusal boundary.

01Act typeID
02Sourceauthority
03Fieldsrequired
04Evidencelabels
05Witnessroles
06Refusalboundary