Skip to content

Compliance: don't assert, prove

European cybersecurity and digital regulations no longer ask for promises: they ask for evidence — an exact software inventory, a controlled supply chain, conforming formats, documented tests.

AWA was built against the grain of today's web software: where an ordinary application assembles hundreds of downloaded packages that nobody reviews, AWA fits in a single repository, with no external dependency at all. The practical consequence: every regulatory requirement is verified in the code, not in a brochure.

This section maps each regulation to the corresponding verifiable artifacts. AWA is a component: certification, where it exists, is obtained by your final product — our role is to provide you with the evidence.

CRA NIS2 DORA eIDAS 2.0 Accessibility EAA/RGAA GDPR Sovereignty

Compliance pack — evidence rows, dated, in the open (being extended and updated).

Software bill of materials (SBOM)

The SBOM generator (SPDX 2.3 and CycloneDX 1.6) is delivered. Each lot 1 package release (2026-09-29) carries its SPDX and CycloneDX SBOM, listed in the release's signed digest manifest; the SBOM files themselves are not signed.

Vulnerability disclosure

Write to security@awacloud.com, an address open since 2026-09-11. Published fingerprint of its OpenPGP key: 8188 3C85 4B96 9B4F D698 5E5F 665D 620D 3F09 CA89. SECURITY.md is published at the root of the public repository (2026-09-29); security.txt goes live with the sites.

Information security management system (ISMS)

Internal ISMS inspired by ISO 27001: risk register, statement of applicability, periodic review — not certified, not audited.

Hosting hardening

Hosting hardening in progress against ANSSI-BP-028 v2.0 (enhanced profile), checked with OpenSCAP.

Compliance evidence pack — executive summary

CRA

Regulation (EU) 2024/2847

proven 6 partial 3 gap 0

NIS2

Directive (EU) 2022/2555

proven 4 partial 1 gap 0

DORA

Regulation (EU) 2022/2554

proven 2 partial 2 gap 1

GDPR (+ CLOUD-Act exposure)

Regulation (EU) 2016/679

proven 6 partial 0 gap 0

eIDAS 2.0 / EUDI

Reg. (EU) 910/2014 as amended by (EU) 2024/1183

proven 4 partial 0 gap 2

EAA / RGAA

Directive (EU) 2019/882; EN 301 549; RGAA 4.1

proven 2 partial 1 gap 2

ANSSI PQC 2027

ANSSI post-quantum migration position

proven 5 partial 2 gap 0

EN 16931 / e-invoicing

Directive 2014/55/EU; EN 16931; French CTC reform

proven 4 partial 11 gap 2

Pack generatedEvidence verified
2026-10-012026-10-01

See the technology sales@awacloud.com