Under the NIS2 directive, an auditor no longer asks "are you compliant?" but "show me". Proof of compliance: a continuously sealed journal, eIDAS-timestamped and anchored on a public ledger — verifiable by a third party, without taking your word for it.
NIS2 compliance proof is the continuous demonstration — not a one-off declaration — that Article 21 measures are met. Every event is sealed (SHA-256 hash), eIDAS-timestamped and anchored on a public ledger: an auditor, insurer or business partner can verify it without trusting your word or the vendor's.
Every event is chained to the previous one (Merkle SHA-256). Any past alteration breaks the chain and becomes detectable.
A stamp from a qualified trust provider, with a legal presumption of date accuracy and integrity (Art. 41 eIDAS).
The SHA-256 hash is published on a public ledger (Hedera). Integrity is verifiable by anyone, without an account.
Inventory + journal + anchoring, assembled into a signed dossier you can hand to any auditor.