- The headline is the shared need: regulators, auditors and clients want evidence that critical software can be recovered and that the exit plan has been tested.
- The visual is the deliverable: the Certificates view, with the documents from each rung of the proof ladder, across four applications. It uses the same fictional applications as the homepage and the Exit Exercise page.
- The CTAs are the sitewide pair. Production's hero button was "Start free risk assessment" (/risk-assessment) and a "free compliance scan" (/impact-analysis) sat further down. Decide whether those tools stay as resources; they're not the primary conversion any more.
Many frameworks. One question: could you recover?
Regulators, auditors and clients now ask for the same thing: evidence that the software you rely on can be brought back, and that your exit plan has been tested. Codekeeper produces that evidence for each critical application, ready for your file.
- Trusted by 3,500+ teams
- ISO/IEC 27001:2022 certified
- Ready for a DORA Article 28 or PRA SS2/21 file
Certificates
4 applications · evidence on fileTrusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors
The shared need
Different rules. The same question underneath.
Whether you answer to DORA, PRA SS2/21, NIS2 or ISO 27001, the auditor's question is close to the same: if a supplier failed, could you bring the software back and keep working, and how do you know?
Can it be recovered?
Holding a copy of the code is the start. Assessors want to see that it builds and runs without the vendor.
Has the exit been tested?
An exit plan on file describes the exit. A tested one shows whether it works for the functions you rely on.
Do you know what's inside?
Supply-chain questions start with an inventory: the components and dependencies each application needs.
“Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically.”
“Firms should take reasonable steps to test exit plans; in particular, those relating to stressed exits.”
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
- Descriptions are labels, not promises. Production's cards said things like "Meet APRA's July 2025 deadline" (stale), "effective December 2027" for the CRA (incomplete) and "Close … compliance gaps". Each card now names the framework, who it covers and what our evidence supports.
- Every label was checked: the DORA, NIS2, CRA and EU AI Act numbers against their titles on EUR-Lex; the Cbw as the Dutch law implementing NIS2 (nldigitalgovernment.nl, 15 Apr 2026); CPS 230's title on apra.gov.au; ESMA's "Principles on third-party risks supervision" (esma.europa.eu, 12 Jun 2025); the ISO titles on iso.org. The DORA and PRA card lines paraphrase the verified quotes.
- Dropped: the HIPAA and GDPR cards (production has no page behind them) and the "Certified" badges on each card, which reused retired level names.
- To confirm: what the production OpEx page covers. Production describes it only as "enterprise risk management frameworks", so the label here is generic.
By framework
Find your framework.
The same evidence serves each of them. These pages show how it lines up with the wording of each one.
DORA
Regulation (EU) 2022/2554 · financial entitiesExit plans for ICT services that support critical or important functions, documented, sufficiently tested and reviewed periodically.
DORA evidence UKPRA SS2/21
PRA supervisory statement · outsourcing and third partiesExit plans for material outsourcing that cover stressed exits and are tested as far as possible.
PRA SS2/21 evidence EUNIS2
Directive (EU) 2022/2555 · essential and important entitiesCybersecurity risk management, including the risks that come from your software suppliers.
NIS2 evidence EUCRA
Regulation (EU) 2024/2847 · products with digital elementsSecurity for products with digital elements, including documenting their components in an SBOM.
CRA evidence ISOISO 27001
ISO/IEC 27001:2022 · information security managementEvidence your ISMS can draw on when auditors ask about suppliers and recovery.
ISO 27001 evidenceMore frameworks on codekeeper.co
Cbw
Netherlands · the Dutch law implementing NIS2Evidence for supply-chain and recovery questions.
Cbw AUCPS 230
Australia · APRA operational risk managementEvidence for service-provider and continuity reviews.
CPS 230 EUESMA
EU · principles on third-party risks supervisionEvidence for third-party risk reviews.
ESMA EUEU AI Act
Regulation (EU) 2024/1689 · artificial intelligenceEvidence for the AI models and systems you depend on.
EU AI Act USFFIEC
United States · Federal Financial Institutions Examination CouncilEvidence for vendor management and recovery reviews.
FFIEC ISOISO 22301
ISO 22301:2019 · business continuity managementEvidence for the recovery of critical software in your continuity plans.
ISO 22301 GLOpEx
Global · operational risk programmesEvidence for operational risk and continuity reviews.
OpEx USSOC 2
United States · service organisation auditsEvidence for vendor continuity questions in your audit.
SOC 2The evidence
Proof beats promises.
Having the code is the start. Having it back is the goal. Each rung of evidence shows more of the way there.
Software Resilience Certificate
The deposit is held, and an automated check confirms what's in it, with a vault report.
Proves: it's there.
Recoverability Certificate
AI agents rebuild the deposit in a sealed sandbox, with no help from the vendor, in hours. You also get the run report, an SBOM and an Exit workbook.
Proves: it builds. Agentic Verification
Tested Exit Report
Our specialists rebuild by hand in a clean room and test the business functions you nominate, without the original developers. An annex maps the result to your framework.
Proves: you could exit and keep working. Exit Exercise
The Recoverability Certificate documents the rebuild and its result. It doesn't grant release rights; those come from the agreement.
- Rows are kinds of requirement, not legal text. Each says what the document supports, and the "comes up in" line only names sources we checked: DORA Art. 28(8) (MESSAGING.md §7), PRA SS2/21 paras 10.1, 10.10, 10.16 and 10.24 (Bank of England PDF, November 2024 version), NIS2 recital 85 on supply-chain risk and CRA recital 77 on SBOMs (both read on EUR-Lex). ISO control numbers are left to the ISO 27001 page.
- The framework packs fold into one offer: the sitewide sample evidence pack (the band below) and the framework annex that comes with every Tested Exit Report. Redirect the production pack URLs (/solutions/dora-evidence-pack to dora.html; the NIS2, ISO 27001, SOC 2 and FFIEC packs to their framework pages or the sample evidence pack page).
Evidence map
Which document helps with which requirement.
One set of documents for each application. The same evidence serves several frameworks, and the Tested Exit Report adds an annex mapped to the one you report against.
| What you're asked to show | Evidence for your file |
|---|---|
| Exit plan testing: the exit works, not just the plan | Tested Exit Report + framework annexRecoverability CertificateRun reportTested Exit Report: Exit Exercise, an add-on to any plan. Recoverability Certificate: Escrow Pro, Resilience Pro, Continuity.Comes up in: DORA Art. 28(8); PRA SS2/21 paras 10.10 and 10.24. |
| Exit plan documentation: how the recovery would run | Exit workbookBuild stepsEscrow Pro, Resilience Pro, Continuity.Comes up in: DORA Art. 28(8) ("comprehensive, documented"); PRA SS2/21 para 10.10 ("appropriately documented"). |
| Third-party and ICT risk: what happens if a supplier fails | Software Resilience CertificateVault reportRecoverability CertificateSoftware Resilience Certificate: every protection. Recoverability Certificate: Pro levels and Continuity.Comes up in: DORA, PRA SS2/21 and other third-party risk rules. |
| Business continuity: a plan for the live service while you recover | Live environment mapResilience ArrangementLive environment map: Continuity, which keeps the live environment paid and switched on for an agreed period while we recover. Recovery run by Codekeeper: Resilience, Resilience Pro, Continuity.Comes up in: PRA SS2/21 paras 10.1 and 10.16; ISO 22301. |
| Supply-chain security: the software you depend on can be rebuilt without its supplier | Recoverability CertificateRun reportEscrow Pro, Resilience Pro, Continuity.Comes up in: NIS2 (supply-chain risk, recital 85) and the laws that implement it, such as the Cbw. |
| SBOM: an inventory of components and dependencies | SBOMEscrow Pro, Resilience Pro, Continuity.Comes up in: the CRA for manufacturers (recital 77), and in customer due diligence. |
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
Sample evidence pack
See what your auditor would receive.
An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.
- Recoverability Certificate
- Run report
- SBOM and Exit workbook excerpts
Choose the evidence you need
One account. A protection for each application.
Add the applications in scope. Attach the protection each one needs, then choose the level that produces the evidence you'll be asked for.
Escrow
Everything you need to be protected.
Software Resilience Certificate: the deposit is held, checked and certified.
From $199per application per month
Explore EscrowEscrow Pro
Everything you need to recover.
Adds the Recoverability Certificate, run report, SBOM and Exit workbook.
From $449per application per month
Explore Escrow ProResilience
We run the recovery.
Software Resilience Certificate, and Codekeeper brings the application back for you.
From $399per application per month
Explore ResilienceResilience Pro
Proven before we need it.
Adds the Agentic Verification evidence, so recovery starts from a deposit we know builds.
From $649per application per month
Explore Resilience ProContinuity
Full continuity.
Everything in Resilience Pro, plus a map of the live environment, kept current.
From $1,449per application per month
Explore ContinuityEscrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on. See all prices
Exit Exercise, from $12,000
An add-on to any plan, for when your exit plan needs exercising and not just a rebuild. You get a Tested Exit Report with an annex mapped to your framework.
Questions
Before you map your applications.
Will Codekeeper make us compliant?
No product can do that on its own. Codekeeper gives you evidence for your file: certificates, run reports, SBOMs, Exit workbooks and Tested Exit Reports. Whether that evidence meets a specific requirement is for you and your assessor to decide.
Which frameworks do you cover?
The evidence is the same whichever framework you answer to. This section has pages for DORA, PRA SS2/21, NIS2, the CRA and ISO 27001, and codekeeper.co has pages for the Cbw, CPS 230, ESMA, the EU AI Act, FFIEC, ISO 22301, OpEx and SOC 2. A Tested Exit Report comes with an annex mapped to the framework you name.
What happened to the framework evidence packs?
They're now one sample evidence pack, so you can see the actual documents before you talk to us: a Recoverability Certificate, a run report, and SBOM and Exit workbook excerpts. When you need the result mapped to a specific framework, the Exit Exercise adds that annex to its Tested Exit Report.
Which level do you recommend for regulated applications?
For an application that supports a critical or important function (DORA) or a material outsourcing arrangement (PRA SS2/21), our guidance is Resilience Pro or Continuity, plus an Exit Exercise when the exit plan needs to be exercised. Your own assessment of each application decides.
Does the Recoverability Certificate give us release rights?
No. It documents the rebuild and its result. Release rights come from the agreement, such as the Escrow Agreement for Escrow.
We're the vendor. Can we use this evidence with our customers?
Yes. With Escrow Pro you can show customers that the application builds without your team, which helps when a buyer has its own exit plan to test. Either party to the agreement can request an Exit Exercise.
Proof beats promises. Put it on file.
We'll map your critical applications to the evidence your frameworks ask for, and the level that produces it.