Skip to content
Watchdog
Sign inSurvey a repo free

Compliance · the measurement capability

We measure the automatable slice. You declare the rest.

A tool can disprove a control, because a fired check is a real failure, but it can never prove conformance. Watchdog evidences the automatable slice, blocks you from passing a control it caught failing without a recorded reason, and leaves the rest with a named person who self-declares. We measure; you declare; we never certify.

A clean automated result is necessary, not sufficient. A green Watchdog score is never, by itself, a compliance claim.

Evaluation

How a control gets evaluated: what a tool can do, and where a human must.

Tool-automated

The automatable surface: a live CVE, a committed secret, a missing label. A failure here is real, so the control is pre-set to Fail and gates sign-off.

Evidence-assisted

Needs rendered runtime, assistive tech or operational evidence: contrast, focus order, access control, backups. You evaluate, and we record the basis.

Human judgement

Governance, incident handling, the resilience-testing programme, alt-text equivalence. You judge it, and it is recorded as your judgement, never dressed up as tool-evidence.

The catalog

Ten regimes, fourteen elements, one pattern.

Ten regulatory regimes, enabled per repository as fourteen separate elements. Pick the ones your repository answers to. Each is a catalog of controls plus what Watchdog can evidence, using the three-way split above applied to that catalog's controls. The failure-gate, the self-assessment lifecycle, the signed artifact and the optional contract clause are identical for all, and only the catalog and the regulation change.

The difference between ten and fourteen is this: four of the elements are reporting duties, the clock that starts once something has already gone wrong. Each is separately enableable from its parent regime, because what you must have and what you must do within hours are different obligations on different timetables. Nothing in them is tool-evidenced, because a notification is an act, and we record it as your attestation.

Accessibility

WCAG 2.2

The web accessibility standard (AA). Static checks tool-evidence what they can, a sandboxed rendered-axe pass adds runtime evidence, and a human judges meaning such as alt-text equivalence and clear errors.

The ACR page →

Accessibility

EN 301 549

The EU procurement accessibility standard the EAA points at, covering web plus non-web clauses. Web maps to WCAG, and the non-web slices are disclosed as human attestation.

The ACR page →

Cybersecurity

NIS2

The EU network-and-information-security directive. Watchdog tool-evidences the technical slice, meaning CVEs, secrets and the supply-chain trail, while governance and incident handling are organizational and stay human-declared.

Cybersecurity

NIS2 Art 23

NIS2's reporting clock: 24h early warning, 72h notification, final report within a month, to your CSIRT or competent authority. Article 21 is what you must have; this is what you must do, so every control is human attestation, because no scanner witnesses a notification.

Financial sector

DORA

Digital operational resilience for the EU financial sector, covering ICT risk and supplier oversight. Scheduled surveys and the SBOM feed the evidence, and the resilience programme is a human declaration.

Financial sector

DORA Art 19

The major-incident reporting duty: initial, intermediate and final reports on the Article 20 templates, plus what your clients must be told. DORA above asks whether you have the process; this one carries the obligations, and every control is yours to attest.

Cybersecurity

CRA

The EU Cyber Resilience Act for products with digital elements. The SBOM, CVE and secrets trail is the automatable slice CRA asks about; conformity claims stay with the manufacturer.

Cybersecurity

CRA Art 14

The manufacturer's reporting clock: 24h, 72h and 14 days to the coordinating CSIRT and ENISA on an actively exploited vulnerability. In force since 11 September 2026, ahead of Annex I on 11 December 2027, and every control is yours to attest.

Privacy

GDPR (technical)

The technical slice of GDPR: PII in code and config, data-flow signals, crypto posture. Lawfulness and process are organizational and stay human-declared.

Privacy

GDPR Art 33–34

The 72-hour breach clock: notify the supervisory authority, and the data subject when the risk is high. GDPR (technical) above is what a scanner can see; this is what a person must do, and it is recorded as your attestation.

Application security

OWASP ASVS

The application-security verification standard. SAST posture, secrets, injection guards tool-evidence part; architecture and design controls are evidence-assisted or human.

Supply-chain

SLSA

Supply-chain levels for software artifacts. Build-provenance and dependency signals tool-evidence a slice; the rest of the chain is declared.

Supply-chain

SSDF

NIST's secure software development framework. Process-heavy: Watchdog evidences the code-visible practices; the organizational practices are attested by a named person.

Security management

ISO 27001 (evidence)

Evidence toward an ISMS, covering the code-and-pipeline slice only. Watchdog never claims certification; it assembles what a machine can stand behind.

Each element is Automatic / On / Off per repository. Self-assess any of them on any plan. Signing and exporting the tamper-evident artifact is part of the compliance module, sold on Assay.

Integrity

The integrity keystone: we won't let you pass what we caught failing.

The failure-gate

A caught failure pre-sets the control to Fail and locks it. To mark it Pass you must record a written justification, reproduced in full in an Integrity section of the artifact. The override is always visible to whoever reads the artifact.

Provenance on every line

Each verdict states how it was reached, as tool-verified, evidence-assisted, AI-drafted-and-reviewed or human attestation, so a buyer, auditor or competent authority sees which claims a machine stands behind and which a person does.

What Watchdog will never claim

We do not certify and are not a notified body or competent authority. A Watchdog score is not a compliance claim. "Tool clean" means no automated failure, which is necessary, not sufficient. We never auto-pass a control on your behalf, and nothing is signed without a human. Organizational controls are recorded as human attestation, never dressed up as tool-evidenced. A compliance claim has to survive an auditor, a regulator and a court, which is why each one records how it was reached.

Buying, regulated, or need the signed pack? The compliance buyer hub and the signed Conformance Pack live on Assay. Watchdog measures the automatable slice; Assay turns it into an audit-defensible, signed artifact.

Measure the automatable slice. Declare the rest.

We measure; you declare; we never certify.