From Rules to Proof: Regulation, Certification, and Why We Joined CertifAI
Last of eight. Building something secure is one job. Proving it to a customer, an auditor or a regulator who has every reason to be sceptical is a different one — and it is the job the rules are now catching up with.
Across seven posts we have looked at how an autonomous vessel resists deception, survives physical capture, accepts software it can trust, and is commanded from shore infrastructure that has been thought about as carefully as the vessel itself. Which leaves the question that has been sitting underneath all of it. Anyone can say their system is secure. How would a customer know?
The rules are catching up
For a long time, cybersecurity in many industries was left to the good sense of individual companies. That era has ended, and the change has been quick enough that it is worth laying out plainly.
- The EU’s NIS2 Directive raised baseline security and incident-reporting obligations for operators of important and critical services, with member states applying national measures since late 2024. Maritime infrastructure is within scope.
- The Cyber Resilience Act is in force and applies from 11 December 2027. It places essential cybersecurity and vulnerability-handling requirements on manufacturers of products with digital elements — which covers a great deal of what goes into an autonomous vessel — with third-party assessment required for the more critical categories.
- The EU AI Act applies from 2 August 2026, adding obligations where AI systems are used in ways the regulation classifies as higher risk.
- In the maritime domain specifically, the classification societies’ unified requirements on the cyber resilience of ships and of on-board systems and equipment have applied to newbuilds since 1 July 2024.
The direction of travel is unmistakable: organisations are increasingly expected not merely to be secure, but to demonstrate it — with proper risk management, documented evidence, incident reporting and accountability at the leadership level.
For a company like MindChip this isn’t a burden to resent. It is a bar we want to clear comfortably, because our customers increasingly need to clear it too, and a supplier who has already done the work makes their customer’s compliance easier. Security maturity becomes a selling point rather than a cost line.
Proving it: the role of certification
Certification exists to turn a claim into something an independent party has checked against an agreed, published standard. In the industrial and maritime world, families of standards set out what a secure supplier and a secure system should actually do — from how software is developed, to how risks are assessed, to how the whole thing is maintained over its life. Certifying against them means an outside assessor has examined the evidence and confirmed that it holds up.
The catch is that certification has traditionally been slow, expensive and heavily manual. Requirements are written in dense normative language that must be interpreted before it can be applied. Evidence is scattered across design documents, test reports, tickets and tools, and must be assembled into a coherent argument by hand. And because the assessment reflects a snapshot, every significant change to an agile product threatens to invalidate the picture — so the process pushes against the way modern software is actually built.
For a large manufacturer this is an expensive nuisance with a dedicated team behind it. For a small or medium-sized company it can be the difference between entering a market and not.
What CertifAI set out to do
CertifAI was a three-year Horizon Europe research project, running from September 2023 to August 2026, that asked whether artificial intelligence could make cybersecurity certification faster, cheaper and more continuous — without making it weaker. It brought together eleven partners: research institutes, universities, certification and assurance bodies including DNV and EZU, and industrial partners including Hitachi Rail, Schneider Electric, TTTech, Catalink and MindChip.
The project built a connected set of capabilities, each aimed at one of the bottlenecks above:
- Requirement interpretation — assistants that help a team work out what a dense normative requirement actually demands in their specific context, and what evidence would satisfy it.
- Threat modelling automation — tools that propose threats, mitigations and requirements drawn from maintained international knowledge bases, and keep the threat model current as the system changes.
- Assurance case construction — support for building the structured argument that links each requirement to claims and to the evidence that backs them, plus automated checking of whether that argument actually holds together.
- Supply-chain analysis — enrichment and risk-based prioritisation of software bills of materials, so that vulnerability handling becomes a ranked work list instead of a wall of alerts.
- Operational monitoring — mining logs and runtime traces from a live system to find structure, anomalies and vulnerabilities that static analysis misses.
- Formal verification — machine-checked proof of critical properties, made accessible from ordinary engineering diagrams.
What MindChip did, and what we got out of it
MindChip led Use Case 3, the maritime use case, with the Artificial Captain platform as the system under assessment. Our job in the project was, bluntly, to be the awkward customer: to take prototype tools built by researchers and run them against a real production platform, then report exactly where they helped and where they fell short. Over three years we tested threat modelling, supply-chain analysis, log and trace mining, assurance case construction and formal verification, and our findings fed into successive releases of each. Both the project’s midterm workshop and its final conference, held in Prague in June 2026, included the maritime use case.

We would be doing the project a disservice if we pretended everything worked perfectly. These are research prototypes, and much of our contribution was documenting the gap between promising and production-ready — imprecise results that cost a security team more time than they save, output formats that don’t fit an audit trail, automation that proposes plausible threats but cannot yet judge whether they apply. Human expertise remains essential, and the honest finding of three years is that AI shifts where that expertise is spent rather than removing the need for it.
What MindChip took away is more tangible than a set of tool reviews. We now hold a complete, maintained threat model of the shore platform, built with a systematic method rather than assembled from intuition. We have a disciplined software bill of materials practice and a defined path from a published vulnerability to a decision. We have a machine-checked proof of a critical property of our command channel. And we have all of it organised as assessment-ready evidence, mapped to the standards our customers are increasingly being asked about.
None of that existed in this form before the project. That, for a small company, is what participating in European research is actually for.
The thread that runs through it all
If there is one idea to carry away from this series, it is that security and autonomy are not opposites. A vessel you can trust to operate on its own is precisely a vessel whose every input is checked, whose secrets are guarded even against physical capture, whose software is provably genuine, whose critical properties have been proven rather than assumed, and whose command centre is as well-defended as the vessel itself.
Autonomy without security is a liability. Autonomy built on security is what turns a clever prototype into something the world can actually rely on — and that is exactly what MindChip sets out to build.
About this series. This post is part of MindChip’s “Cybersecurity for Maritime Autonomy” series, sharing practical insight from our work securing, assessing and certifying autonomous surface vessels. MindChip OÜ led Use Case 3 — the maritime use case — in CertifAI (certifai.info), a three-year Horizon Europe research project that developed AI-assisted tools for cybersecurity certification. MindChip was one of eleven partners, alongside Tecnalia, Hitachi Rail GTS Austria, Schneider Electric, TTTech, DNV, NTNU, Simula Research Laboratory, UBITECH, Catalink and EZU.

Funded by the European Union under Grant Agreement No 101120606. Views and opinions expressed are however those of the author only and do not necessarily reflect those of the European Union or the granting authority. Neither the European Union nor the granting authority can be held responsible for them.

