Compliance: don't assert, prove
European cybersecurity and digital regulations no longer ask for promises: they ask for evidence — an exact software inventory, a controlled supply chain, conforming formats, documented tests.
AWA was built against the grain of today's web software: where an ordinary application assembles hundreds of downloaded packages that nobody reviews, AWA fits in a single repository, with no external dependency at all. The practical consequence: every regulatory requirement is verified in the code, not in a brochure.
This section maps each regulation to the corresponding verifiable artifacts. AWA is a component: certification, where it exists, is obtained by your final product — our role is to provide you with the evidence.
CRA NIS2 DORA eIDAS 2.0 Accessibility EAA/RGAA GDPR Sovereignty
Compliance pack — evidence rows, dated, in the open (being extended and updated).
Software bill of materials (SBOM)
The SBOM generator (SPDX 2.3 and CycloneDX 1.6) is delivered. Each lot 1 package release (2026-09-29) carries its SPDX and CycloneDX SBOM, listed in the release's signed digest manifest; the SBOM files themselves are not signed.
Vulnerability disclosure
Write to security@awacloud.com, an address open since 2026-09-11. Published fingerprint of its OpenPGP key: 8188 3C85 4B96 9B4F D698 5E5F 665D 620D 3F09 CA89. SECURITY.md is published at the root of the public repository (2026-09-29); security.txt goes live with the sites.
Information security management system (ISMS)
Internal ISMS inspired by ISO 27001: risk register, statement of applicability, periodic review — not certified, not audited.
Hosting hardening
Hosting hardening in progress against ANSSI-BP-028 v2.0 (enhanced profile), checked with OpenSCAP.
Compliance evidence pack — executive summary
CRA
Regulation (EU) 2024/2847
proven 6 partial 3 gap 0
NIS2
Directive (EU) 2022/2555
proven 4 partial 1 gap 0
DORA
Regulation (EU) 2022/2554
proven 2 partial 2 gap 1
GDPR (+ CLOUD-Act exposure)
Regulation (EU) 2016/679
proven 6 partial 0 gap 0
eIDAS 2.0 / EUDI
Reg. (EU) 910/2014 as amended by (EU) 2024/1183
proven 4 partial 0 gap 2
EAA / RGAA
Directive (EU) 2019/882; EN 301 549; RGAA 4.1
proven 2 partial 1 gap 2
ANSSI PQC 2027
ANSSI post-quantum migration position
proven 5 partial 2 gap 0
EN 16931 / e-invoicing
Directive 2014/55/EU; EN 16931; French CTC reform
proven 4 partial 11 gap 2
| Pack generated | Evidence verified |
|---|---|
| 2026-10-01 | 2026-10-01 |