ARKION
Ledger · Compliance Crosswalk · v.2026
For compliance officers & audit committees

Every framework. One mapping.

Regulators are starting to ask exactly which non-human identity controls you have in place. This page maps the controls auditors cite — DORA, NIS2, ISO 27001:2022, SEC, NIST, PCI, EU AI Act — to the specific Arkion capability that satisfies each one.

This page is informational. For audit-grade attestation language, contact compliance@arkion.ai.

§ · The Crosswalk

Frameworks in scope.

Framework 01

DORA

EU · Financial entities · Live since 2025
Article 9 · ICT risk management

Continuous identity oversight of all ICT systems, including third-party and machine-to-machine connections.

What Arkion does

Continuous discovery + cryptographically attested audit trail. Every non-human identity in scope is enumerated, owned, and logged in real time.

Framework 02

NIS2

EU member states · In enforcement
Annex II · Access management

Documented access management policies for non-human entities, including service accounts and machine credentials.

What Arkion does

Lifecycle authority + ownership mapping. Every machine identity has a named human owner, a rotation policy, and a revocation path.

Framework 03

ISO 27001:2022

Global · Standard reference
Control 5.16 · Identity management

Establishment, maintenance, and removal of identities — explicitly including non-human identities.

What Arkion does

Cryptographic identity for every NHI, issued at provision time, governed across the full lifecycle, archived on revocation.

Framework 04

SEC Cyber-Disclosure

US · Public companies · Active
Item 106 · 4-day material incident reporting

Material cybersecurity incident reporting within four business days, including identity-related breaches.

What Arkion does

Real-time event logging. Every lifecycle event is signed, timestamped, and queryable — incident scope answerable on demand, not after a forensic pass.

Framework 05

NIST CSF 2.0

US federal alignment · Voluntary global
PR.AA · Identity, Authentication, Access Control

Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, services, and software.

What Arkion does

End-to-end NHI lifecycle: issue, manage, verify, revoke, audit. The five Arkion stages map directly to PR.AA-1 through PR.AA-5.

Framework 06

PCI DSS 4.0

Global · Card-handling environments
Requirement 8.6 · Application and system accounts

Application and system account passwords are not used as the primary authentication method; service-account credentials are managed under access control.

What Arkion does

Certificate-based identity replaces shared service-account secrets. Cryptographic primitives that PCI 8.6 considers compliant by construction.

Framework 07

EU AI Act

EU · Phased enforcement 2025–2027
Article 14 · Human oversight of high-risk AI systems

High-risk AI systems must allow human operators to monitor, interpret, and intervene in their behaviour — including identifying which system performed which action.

What Arkion does

Every AI agent carries a verifiable cryptographic identity. Every action is attributable. Oversight is enforced at the identity layer, not retrofitted at the audit layer.

§ · Sample Attestation

The artifact every Arkion estate produces.

At the close of every reporting period, Arkion produces a cryptographically signed attestation that maps the lifecycle evidence in the underlying ledger to the controls in the crosswalk above. Board-presentable. Audit-grade. Accepted by cyber insurance carriers as renewal evidence.

ARKION COMPLIANCE ATTESTATION
Q1 2026
Estate Report · Production
REFERENCE
CR-Q1-2026
Estate
Acme Corp · production
Reporting period
Jan 1 – Mar 31, 2026
Identities governed
28,406
Rotations executed
14,228 · zero downtime
Revocations
412
Orphaned & archived
89
Owners assigned
100% of in-scope NHIs
Mean rotation cadence
27 days
CONTROL ATTESTATION
DORA · Article 9 · ICT risk management✓ satisfied
NIS2 · Annex II · Access management✓ satisfied
ISO 27001:2022 · A.5.16 · Identity management✓ satisfied
SEC · Item 106 · 4-day disclosure✓ satisfied
NIST CSF 2.0 · PR.AA-1 through PR.AA-5✓ satisfied
PCI DSS 4.0 · Requirement 8.6✓ satisfied
EU AI Act · Article 14 · Human oversight✓ satisfied
CRYPTOGRAPHICALLY SIGNED
sha256:0x4f2ab8d1e9c47a3f · ed25519
arkion.ai/proof/CR-Q1-2026Signed Apr 30 2026 · 14:08:22 UTC

Illustrative · not a customer record

Audience

Forwarded to the board, the auditor, and the cyber insurance carrier. One artifact, three audiences, no edits.

What it carries
  • Every lifecycle event for the period — issued, rotated, revoked, archived
  • Cryptographic signature against the underlying immutable ledger
  • Direct mapping to the framework crosswalk above
  • Estate-level metrics: ownership coverage, rotation cadence, exception count
  • Verifiable at arkion.ai/proof/<reference> — no API key needed
What it replaces

Screenshot decks. Quarterly spreadsheet exports. The week-of-audit scramble. The phrase “we’ll have to ask the team that owns it.”

Request a real sample attestation under NDA
§ · Cyber Insurance

Carriers are asking too.

Cyber insurance carriers increasingly require non-human identity governance for policy renewal — and refuse to cover breaches caused by orphaned credentials. Arkion produces the evidence carriers ask for: ownership for every identity, rotation cadence on every credential, signed event logs for every lifecycle change.

If your renewal questionnaire asks “how do you control machine identity?” — we wrote the answer for you.

Need this in an attestation document?

We provide framework-specific control mappings, evidence packages, and pre-answered questionnaires under NDA for active procurement evaluations.