ARKION
Ledger · Compliance Crosswalk · v.2026
For compliance officers & audit committees

Every framework. One mapping.

Regulators are starting to ask exactly which non-human identity controls you have in place. This page maps the controls auditors cite (DORA, NIS2, ISO 27001:2022, SEC, NIST, PCI, EU AI Act) to the specific Arkion capability that satisfies each one.

This page is informational. For audit-grade attestation language, contact compliance@arkion.ai.

§ · The Crosswalk

Frameworks in scope.

Framework 01

DORA

EU · Financial entities · Live since 2025
Article 9 · ICT risk management

Continuous identity oversight of all ICT systems, including third-party and machine-to-machine connections.

What Arkion does

Continuous discovery + cryptographically attested audit trail. Every non-human identity in scope is enumerated, owned, and logged in real time.

Framework 02

NIS2

EU member states · In enforcement
Annex II · Access management

Documented access management policies for non-human entities, including service accounts and machine credentials.

What Arkion does

Lifecycle authority + ownership mapping. Every machine identity has a named human owner, a rotation policy, and a revocation path.

Framework 03

ISO 27001:2022

Global · Standard reference
Control 5.16 · Identity management

Establishment, maintenance, and removal of identities, explicitly including non-human identities.

What Arkion does

Cryptographic identity for every NHI, issued at provision time, governed across the full lifecycle, archived on revocation.

Framework 04

SEC Cyber-Disclosure

US · Public companies · Active
Item 106 · 4-day material incident reporting

Material cybersecurity incident reporting within four business days, including identity-related breaches.

What Arkion does

Real-time event logging. Every lifecycle event is signed, timestamped, and queryable. Incident scope answerable on demand, not after a forensic pass.

Framework 05

NIST CSF 2.0

US federal alignment · Voluntary global
PR.AA · Identity, Authentication, Access Control

Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, services, and software.

What Arkion does

End-to-end NHI lifecycle: issue, manage, verify, revoke, audit. The five Arkion stages map directly to PR.AA-1 through PR.AA-5.

Framework 06

PCI DSS 4.0

Global · Card-handling environments
Requirement 8.6 · Application and system accounts

Application and system account passwords are not used as the primary authentication method; service-account credentials are managed under access control.

What Arkion does

Certificate-based identity replaces shared service-account secrets. Cryptographic primitives that PCI 8.6 considers compliant by construction.

Framework 07

EU AI Act

EU · Phased enforcement 2025 to 2027
Article 14 · Human oversight of high-risk AI systems

High-risk AI systems must allow human operators to monitor, interpret, and intervene in their behaviour, including identifying which system performed which action.

What Arkion does

Every AI agent carries a verifiable cryptographic identity. Every action is attributable. Oversight is enforced at the identity layer, not retrofitted at the audit layer.

§ · Sample Attestation

The artifact every Arkion estate produces.

At the close of every reporting period, Arkion produces a cryptographically signed attestation that maps the lifecycle evidence in the underlying ledger to the controls in the crosswalk above. Board-presentable. Audit-grade. Accepted by cyber insurance carriers as renewal evidence.

ARKION COMPLIANCE ATTESTATION
Q1 2026
Estate Report · Production
REFERENCE
CR-Q1-2026
Estate
Acme Corp · production
Reporting period
Jan 1 to Mar 31, 2026
Identities governed
28,406
Rotations executed
14,228 · zero downtime
Revocations
412
Orphaned & archived
89
Owners assigned
100% of in-scope NHIs
Mean rotation cadence
27 days
CONTROL ATTESTATION
DORA · Article 9 · ICT risk management✓ satisfied
NIS2 · Annex II · Access management✓ satisfied
ISO 27001:2022 · A.5.16 · Identity management✓ satisfied
SEC · Item 106 · 4-day disclosure✓ satisfied
NIST CSF 2.0 · PR.AA-1 through PR.AA-5✓ satisfied
PCI DSS 4.0 · Requirement 8.6✓ satisfied
EU AI Act · Article 14 · Human oversight✓ satisfied
CRYPTOGRAPHICALLY SIGNED
sha256:0x4f2ab8d1e9c47a3f · ed25519
arkion.ai/proof/CR-Q1-2026Signed Apr 30 2026 · 14:08:22 UTC

Illustrative · not a customer record

Audience

Forwarded to the board, the auditor, and the cyber insurance carrier. One artifact, three audiences, no edits.

What it carries
  • Every lifecycle event for the period: issued, rotated, revoked, archived
  • Cryptographic signature against the underlying immutable ledger
  • Direct mapping to the framework crosswalk above
  • Estate-level metrics: ownership coverage, rotation cadence, exception count
  • Verifiable at arkion.ai/proof/<reference>, no API key needed
What it replaces

Screenshot decks. Quarterly spreadsheet exports. The week-of-audit scramble. The phrase “we’ll have to ask the team that owns it.”

Request a real sample attestation under NDA
§ · Cyber Insurance

Carriers are asking too.

Cyber insurance carriers increasingly require non-human identity governance for policy renewal, and refuse to cover breaches caused by orphaned credentials. Arkion produces the evidence carriers ask for: ownership for every identity, rotation cadence on every credential, signed event logs for every lifecycle change.

If your renewal questionnaire asks “how do you control machine identity?” We wrote the answer for you.

Need this in an attestation document?

We provide framework-specific control mappings, evidence packages, and pre-answered questionnaires under NDA for active procurement evaluations.