Continuous compliance as code

Attestation is not evidence.

Argus runs in your pipeline and verifies your product against the CRA, NIS2 and IEC 62443 on every push. Not a snapshot you signed once. A current record you can defend.

The problem

A signed PDF describes the past.

Most compliance work produces a document. Someone reviews the system, writes down what they found, signs it, and files it. The moment after, the code changes. A dependency updates. A configuration drifts.

The document keeps saying what was true on the day it was signed. Nobody notices the gap until an auditor, or an incident, finds it for you.

Attestation

A stamp on a moment that has already passed.

signed: 14 March 2026
reviewed by: one person, once
valid until: something changed

Evidence

A current record, tied to the requirement it satisfies.

verified: on every push
mapped to: a specific clause
valid: right now

How Argus works

Three steps, then it keeps running.

01

Connect

Point Argus at your repository and build pipeline. It reads your code, dependencies, configuration and process artifacts where they already live.

02

Map

Every check is tied to a specific clause. A CRA Annex I requirement, a NIS2 article, an IEC 62443 control. Nothing is checked without a reason you can cite.

03

Verify

On every push, or on the schedule you set, Argus re-runs the checks and records the result. The evidence stays current and points back to the exact requirement.

What it covers

The frameworks that decide whether you can sell.

CRA

EU Regulation 2024/2847

Cyber Resilience Act

Essential requirements from Annex I, conformity assessment readiness, and the technical documentation a Module A self assessment expects.

NIS2

EU Directive 2022/2555

Network and information security

The Article 21 risk management measures mapped to what your systems actually do, with the incident reporting timeline kept in view.

IEC 62443

Industrial and OT standard

Secure products for OT

Secure development lifecycle and product requirements, checked against the security level you claim rather than the one you hope for.

This is the initial set. The rule set is built to extend, so new standards, framework updates and your own internal policies can be added as your obligations grow.

Before you start

Not sure which rules apply to you?

Answer a few questions about your product and market. The applicability checker shows which of the CRA, NIS2 and IEC 62443 you need to account for, and why.

Open the applicability checker Free. About two minutes. No sign up.

For partners

Put the checker on your own site.

Embed the applicability checker as a widget on your website. It runs entirely in the browser, with no backend and no tracking, and links your visitors back to Argus. Add your name with the partner parameter and it shows as co-branded.

Embed code
<iframe
  src="https://attigo.dk/widget.html?partner=YourCompany"
  width="500"
  height="600"
  style="border:1px solid #D1D9E0;border-radius:8px;"
  title="Compliance Applicability Checker"></iframe>

Preview the widget · under 15KB · no cookies

Argus by Attigo

Compliance you can still prove the day after you signed it.

Attestation tells an assessor what you believed. Evidence shows them what is true.

In early access with a small number of design partners.