Compliance · the measurement capability
We measure the automatable slice. You declare the rest.
A tool can disprove a control, because a fired check is a real failure, but it can never prove conformance. Watchdog evidences the automatable slice, blocks you from passing a control it caught failing without a recorded reason, and leaves the rest with a named person who self-declares. We measure; you declare; we never certify.
A clean automated result is necessary, not sufficient. A green Watchdog score is never, by itself, a compliance claim.
Evaluation
How a control gets evaluated: what a tool can do, and where a human must.
Tool-automated
The automatable surface: a live CVE, a committed secret, a missing label. A failure here is real, so the control is pre-set to Fail and gates sign-off.
Evidence-assisted
Needs rendered runtime, assistive tech or operational evidence: contrast, focus order, access control, backups. You evaluate, and we record the basis.
Human judgement
Governance, incident handling, the resilience-testing programme, alt-text equivalence. You judge it, and it is recorded as your judgement, never dressed up as tool-evidence.
The catalog
Ten regimes, fourteen elements, one pattern.
Ten regulatory regimes, enabled per repository as fourteen separate elements. Pick the ones your repository answers to. Each is a catalog of controls plus what Watchdog can evidence, using the three-way split above applied to that catalog's controls. The failure-gate, the self-assessment lifecycle, the signed artifact and the optional contract clause are identical for all, and only the catalog and the regulation change.
The difference between ten and fourteen is this: four of the elements are reporting duties, the clock that starts once something has already gone wrong. Each is separately enableable from its parent regime, because what you must have and what you must do within hours are different obligations on different timetables. Nothing in them is tool-evidenced, because a notification is an act, and we record it as your attestation.
Accessibility
WCAG 2.2
The web accessibility standard (AA). Static checks tool-evidence what they can, a sandboxed rendered-axe pass adds runtime evidence, and a human judges meaning such as alt-text equivalence and clear errors.
Accessibility
EN 301 549
The EU procurement accessibility standard the EAA points at, covering web plus non-web clauses. Web maps to WCAG, and the non-web slices are disclosed as human attestation.
Cybersecurity
NIS2
The EU network-and-information-security directive. Watchdog tool-evidences the technical slice, meaning CVEs, secrets and the supply-chain trail, while governance and incident handling are organizational and stay human-declared.
Cybersecurity
NIS2 Art 23
NIS2's reporting clock: 24h early warning, 72h notification, final report within a month, to your CSIRT or competent authority. Article 21 is what you must have; this is what you must do, so every control is human attestation, because no scanner witnesses a notification.
Financial sector
DORA
Digital operational resilience for the EU financial sector, covering ICT risk and supplier oversight. Scheduled surveys and the SBOM feed the evidence, and the resilience programme is a human declaration.
Financial sector
DORA Art 19
The major-incident reporting duty: initial, intermediate and final reports on the Article 20 templates, plus what your clients must be told. DORA above asks whether you have the process; this one carries the obligations, and every control is yours to attest.
Cybersecurity
CRA
The EU Cyber Resilience Act for products with digital elements. The SBOM, CVE and secrets trail is the automatable slice CRA asks about; conformity claims stay with the manufacturer.
Cybersecurity
CRA Art 14
The manufacturer's reporting clock: 24h, 72h and 14 days to the coordinating CSIRT and ENISA on an actively exploited vulnerability. In force since 11 September 2026, ahead of Annex I on 11 December 2027, and every control is yours to attest.
Privacy
GDPR (technical)
The technical slice of GDPR: PII in code and config, data-flow signals, crypto posture. Lawfulness and process are organizational and stay human-declared.
Privacy
GDPR Art 33–34
The 72-hour breach clock: notify the supervisory authority, and the data subject when the risk is high. GDPR (technical) above is what a scanner can see; this is what a person must do, and it is recorded as your attestation.
Application security
OWASP ASVS
The application-security verification standard. SAST posture, secrets, injection guards tool-evidence part; architecture and design controls are evidence-assisted or human.
Supply-chain
SLSA
Supply-chain levels for software artifacts. Build-provenance and dependency signals tool-evidence a slice; the rest of the chain is declared.
Supply-chain
SSDF
NIST's secure software development framework. Process-heavy: Watchdog evidences the code-visible practices; the organizational practices are attested by a named person.
Security management
ISO 27001 (evidence)
Evidence toward an ISMS, covering the code-and-pipeline slice only. Watchdog never claims certification; it assembles what a machine can stand behind.
Each element is Automatic / On / Off per repository. Self-assess any of them on any plan. Signing and exporting the tamper-evident artifact is part of the compliance module, sold on Assay.
Integrity
The integrity keystone: we won't let you pass what we caught failing.
The failure-gate
A caught failure pre-sets the control to Fail and locks it. To mark it Pass you must record a written justification, reproduced in full in an Integrity section of the artifact. The override is always visible to whoever reads the artifact.
Provenance on every line
Each verdict states how it was reached, as tool-verified, evidence-assisted, AI-drafted-and-reviewed or human attestation, so a buyer, auditor or competent authority sees which claims a machine stands behind and which a person does.
What Watchdog will never claim
We do not certify and are not a notified body or competent authority. A Watchdog score is not a compliance claim. "Tool clean" means no automated failure, which is necessary, not sufficient. We never auto-pass a control on your behalf, and nothing is signed without a human. Organizational controls are recorded as human attestation, never dressed up as tool-evidenced. A compliance claim has to survive an auditor, a regulator and a court, which is why each one records how it was reached.
Buying, regulated, or need the signed pack? The compliance buyer hub and the signed Conformance Pack live on Assay. Watchdog measures the automatable slice; Assay turns it into an audit-defensible, signed artifact.
Measure the automatable slice. Declare the rest.
We measure; you declare; we never certify.