---
title: "KYE Protocol™ — Compliance, conformance & certification | EU AI Act + 249 frameworks"
description: "KYE Protocol™ compliance, conformance, certification overview. EU AI Act profile (10 controls)"
url: https://kyeprotocol.com/compliance/
lang: en
source: "KYE Protocol"
---

> KYE Protocol™ compliance, conformance, certification overview. EU AI Act profile (10 controls)

Compliance

# From runtime decision to framework control — one rail.

Auditors spend weeks digging through logs. KYE™ exports signed proof in minutes. Fetch a URL, verify offline, map to your controls — 266 mappings across 249 frameworks, automated. The KYE™ Compliance Mapping Rail™ binds every runtime control to the obligation it satisfies; the 5-tier KYE™ Conformant™ / KYE™ Certified™ badge ladder makes the claim public.

Out-of-the-box coverage · live

## 249 frameworks, six categories, bijection-checked.

Every framework below has a per-requirement bijection map to the KYE™ runtime artefacts that enforce it. Pages regenerate from `coverage-registry.json` — the registry is the source of truth, the badge grid is the index.

[SecuritySOC 2](https://kyeprotocol.com/regulatory-coverage/#soc2) [SecurityISO 27001](https://kyeprotocol.com/regulatory-coverage/#iso-27001) [SecurityNIST 800-207](https://kyeprotocol.com/regulatory-coverage/#nist-800-207) [SecurityNIST CSF](https://kyeprotocol.com/regulatory-coverage/#nist-csf) [SecurityFedRAMP](https://kyeprotocol.com/regulatory-coverage/#fedramp) [SecurityNIS2](https://kyeprotocol.com/regulatory-coverage/#nis2) [FinServPCI DSS](https://kyeprotocol.com/regulatory-coverage/#pci-dss) [FinServPSD2 / PSD3](https://kyeprotocol.com/regulatory-coverage/#psd2-psd3) [FinServDORA](https://kyeprotocol.com/regulatory-coverage/#dora) [AI GovEU AI Act](https://kyeprotocol.com/regulatory-coverage/#eu-ai-act) [AI GovISO 42001](https://kyeprotocol.com/regulatory-coverage/#iso-42001) [AI GovNIST AI RMF](https://kyeprotocol.com/regulatory-coverage/#nist-ai-rmf) [AI GovUK AI](https://kyeprotocol.com/regulatory-coverage/#uk-ai-framework) [AI GovUK AI Assurance](https://kyeprotocol.com/regulatory-coverage/#uk-ai-assurance) [DataGDPR / UK GDPR](https://kyeprotocol.com/regulatory-coverage/#gdpr) [HealthcareHAARF v1.0](https://kyeprotocol.com/compliance/haarf/) [HealthcareMHRA MDR 2002](https://kyeprotocol.com/compliance/mhra-mdr-2002/) [HealthcareMHRA PMS 2025](https://kyeprotocol.com/compliance/mhra-pms-2025/) [HealthcareMHRA SaMD & AI](https://kyeprotocol.com/compliance/mhra-samd-change-programme/)

Click any badge for the per-requirement bijection map. Coverage refreshes from the registry on every deploy — [live dashboard →](https://kyeprotocol.com/compliance/coverage/)

Compliance frameworks

## From AI governance to sector-grade authority control.

KYE Protocol™ provides a protocol-level evidence layer for regulated AI and automation. Use **KYE™ Compliance Mapping Rail™** profiles to bind runtime controls and signed evidence packs to the specific obligations every framework imposes. KYE™ does not replace these frameworks — it produces the evidence they consume.

EU AI Act

### KYE™ EU AI Act Profile™

EU AI Act Maps KYE™ entity, authority, capability, state, human oversight, and audit controls to EU AI Act obligations (Art. 9–18, 26, 50, 72, 73, 79).

- `KYE-EUAIACT-001` Entity accountability mapping
- `KYE-EUAIACT-002` AI system & AI agent registry
- `KYE-EUAIACT-003` Capability manifest + risk classification
- `KYE-EUAIACT-004` Human oversight decision gates
- `KYE-EUAIACT-005` Runtime authority decision logs
- `KYE-EUAIACT-006` Technical documentation evidence pack
- `KYE-EUAIACT-007` Corrective action & revocation trail
- `KYE-EUAIACT-008` Provider / deployer / operator role mapping
- `KYE-EUAIACT-009` High-risk workflow profile
- `KYE-EUAIACT-010` Post-market monitoring evidence hooks

Horizontal frameworks

### 10 horizontal frameworks. One evidence model.

Horizontal frameworks All ten exposed via the **KYE™ Compliance Mapping Rail™** schema (`schemas/compliance-mapping.json`) — one document binds a control to the KYE™ runtime events that produce its evidence.

- **ISO/IEC 42001** — AI management system inventory, responsibility mapping, risk/impact, lifecycle controls, oversight logs.
- **NIST AI RMF** — Govern / Map / Measure / Manage evidence around actors, risks, controls, decisions, lifecycle.
- **ISO 27001:2022** — Access control, asset/entity inventory, privileged access, logging, incident evidence.
- **SOC 2** — Security, availability, confidentiality, change management, access reviews, audit evidence.
- **GDPR / UK GDPR** — Role mapping, lawful authority trail, data access, automated decision governance, audit.
- **DORA** — ICT third-party authority, operational resilience, incident response, auditability.
- **NIS2** — Cybersecurity governance, incident traceability, supply-chain controls, access authority.
- **PCI DSS 4.0** — Payment capability restrictions, credential state, wallet/payment authority, audit logs.
- **HIPAA** — Healthcare entity access, minimum-necessary, emergency/break-glass, audit trails.
- **NIST 800-207** — Zero-Trust Architecture: identity, device, network, application, data telemetry.

KYE™ produces evidence; certifications remain the customer’s. KYE™ does not replace legal counsel, regulatory filings, conformity assessments, or notified-body involvement.

Conformance & Certification

## Trust, but verify.

KYE™ implementations can be tested against open conformance suites and verified through the public KYE™ Certification Registry. Earn badges that prove protocol alignment across entity authority, state, delegation, decisions, audit trails, and evidence packs — with annual renewal, signed records, and public-key verification.

### KYE™ Self-Tested™

Run the open conformance pack locally. Free, vendor-published. **Backed by a passing run** of `conformance-run.json`.

### KYE™ Self-Attested™

Sign + publish a declaration of conformance. Self-audit + signed `self-attestation.json`. Quarterly renewal. **Not equivalent to certified.**

### KYE™ Conformant™

Program-verified test run. Variants: **Core / Authority / Capability / Evidence / Recovery / Payments / Healthcare / EU AI Act**. Annual renewal.

### KYE™ Certified™

Reviewed by KYE™ program + listed in registry. Signed `certification-record.json` · public verification URL · revocation tracking · 12-month renewal.

**Govern the governance layer.** KYE™ Self-Audit & Attestation Profile lets implementations continuously verify their own engines, decisions, audit trails, and Evidence Packs™. Five checks: Engine Health, Decision Replay, Audit-Trail Integrity, Evidence Completeness, Policy Coverage.

Conformance maturity ladder

## Five rungs, contiguous — from schema-valid to reality-coupled.

The KYE™ Conformance Maturity Levels (L1–L5) are the procurement-facing depth gradient that sits on top of the binary KYE™ Conformance Pack™. The pack answers _“does the fixed fixture set pass?”_; the ladder answers _“how deep does enforcement reach at this deployment?”_ The rungs are contiguous — a deployment claims a level only when every capability of that level **and** every level below it is satisfied. No level-skipping.

L1 · Schema-valid

L1

Every emitted artefact validates against its locked KYE™ schema and every identifier conforms to the KYE™ ID format.

L2 · Entity + delegation captured

L2

Entity resolution and the full delegation chain are recorded in the evidence layer, not reconstructed later.

L3 · Admissibility enforced

L3

Action Admissibility™ is gated at runtime **before** the action runs — fail-closed when the decision point is unreachable.

L4 · Finality replayable

L4

Authority Finality™ and the Replay-Proof™ are HSM-signed and derivable from the published public keys alone — banking-grade.

L5 · Reality-coupling + contestability + revocation

L5

Full cascading revocation, delegated auditability + contestability surfaces, and reality-coupling drift wired into runtime effect.

L4 is the rung a Tier-1 bank’s GRC team asks for first: signed, sealed finality whose proof recomputes from public keys with zero trust in the runtime that produced it.

Try it live

## Verify a sample evidence pack in your browser.

Below is the Evidence Pack™ Viewer that ships at [widgets.html](https://kyeprotocol.com/evidence-pack/). Verify the signature offline, replay the bound decision, walk the audit chain, project to SOC 2 / ISO 27001 / EU AI Act / PSD3 / DORA. No signup, no install.

Trust & assurance

## Built to be handed to your audit team on day one.

Open spec. Reference implementation. Conformance fixture pack. Cryptographic proof bundles. Nine-framework control mapping. RFC 7807 error envelope. Quantitative SLA tiers. The artefacts a Tier-1 bank’s GRC team needs are in the repo, not in a sales deck.

Endpoints

87

Routed in the reference Gateway. Every state-changing endpoint accepts an `Idempotency-Key` and emits a correlated audit event.

Profiles · normative

15

Core, Gateway, Federation, Credentials, Attestation, Signals, Transparency, Conformance, Treasury, Custody, Healthcare, Telemetry, Capability, Recovery, Payments — plus 3 payment overlays.

Conformance fixtures

37

Each fixture is a deterministic black-box test the auditor replays against any conformant Gateway. `conformance-report.json` emits machine-readable evidence.

Control mappings

266

SOC 2 · ISO 27001:2022 · PCI DSS 4.0 · PSD2/PSD3 · DORA · NIS2 · EU AI Act · NIST 800-207 · HIPAA. Each row cites the KYE™ artefact + the Gateway endpoint that produces it.

SLA tiers

Tier-1 Bank (p99 ≤ 50 ms, 1k rps), Tier-2 Mid-market, Tier-3 Reference. Quantitative claims backed by signed conformance reports.

Tests · all green

220+

KYE™ Reference Gateway™ · ePDP · PEP · TS / Python / Go SDKs · webhook vectors · schema validations · 22 OPA Rego + Cerbos policy fixtures at parity.

Mapped to SOC 2 · ISO 27001:2022 · PCI DSS 4.0 · PSD2/PSD3 · DORA · NIS2 · EU AI Act · NIST 800-207 · HIPAA

KYE™ produces evidence; certifications are the customer’s. The repo ships a complete control-mapping document. For each KYE™ artefact (entity record, delegation, scope, credential, attestation, audit event, proof bundle, signal, transparency receipt, capability grant, recovery proof, break-glass grant, compromise report, state transition) it lists which control is satisfied and the exact endpoint to extract it.

Banking-grade

### Production posture

Banking-grade

- Append-only audit chain with point-in-time replay (`POST /v1/audit/point-in-time`)
- Ed25519-signed proof bundles — verifiable with public keys alone
- Cascading stop signals (entity → delegations → payment authorities → access rights → capability grants — in milliseconds)
- Break-glass authority with mandatory post-hoc review and time-cap
- Key rotation gated by break-glass grant (`POST /v1/keys:rotate`)
- Idempotency keys + signed webhooks + replay window + dead-letter
- Fail-closed PEP for high-risk actions on PDP unreachable
- Reference Rego sPDPs (22/22 passing)

Open governance

### What ships open

Open governance

- Vocabulary, ID format, schemas, OpenAPI — **Apache 2.0**
- KYE™ Reference Gateway™, three SDKs, conformance fixtures — **Apache 2.0**
- Reason-codes registry, control mappings, threat model — in the repo
- Proprietary mechanisms are separate — the open contract is and will remain royalty-free for any conformant implementation
- Trademark policy lets you say “KYE Protocol™-compatible” once you pass the conformance pack
- Discussions repo for RFCs, profile proposals, integration patterns

## Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Try the sandbox →](https://kyeprotocol.com/sandbox/demos/)

Canonical KYE™ surfaces referenced on this page: [Delegated Auditability](https://kyeprotocol.com/glossary/) · [KYE Protocol™](https://kyeprotocol.com/).
