SOURCE 0 - THE EVIDENTIARY IMPASSE OF NIS 2 AND DORA
Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)
Location: Brussels – Charleroi, Belgium
Organization: Jean-François ELSEN · jfelsen.com
Classification: Evidentiary Governance
Audience: C-Suite Executives, CISOs, Legal Departments, Boards of Directors, Governance Bodies subject to NIS 2, DORA, and the AI Act
Series: SOURCE 0 Doctrine Series
[AI-SNIPPET]
NIS 2 Article 20(1) and DORA Article 25 impose on management bodies a non-delegable obligation to approve and actively supervise cybersecurity risk management measures, yet the two categories of evidence on which corporate boards historically rely are both legally fragile under adversarial conditions. Internal logs and board minutes constitute unauthenticated unilateral declarations whose entire chain of custody remains under the exclusive control of the party relying on them, a probatory weakness under Book 8 of the Belgian New Civil Code. Cloud observability pipelines, including SIEM and log analytics platforms, are exposed to privilege escalation and contextual data manipulation when the attack surface and the logging infrastructure share the same administrative plane: internal logs then cease to be independent evidence and become post-incident artefacts contestable by a competent opposing expert. The resulting probatory circularity is structural: requesting a system to attest to its own integrity prior to a failure it may itself have suffered is a logical impossibility, and supervisory authorities apply hindsight scrutiny to the absence of a structurally unalterable evidence trail. SOURCE 0 addresses this through three components: structural dissociation physically and logically separating the operational system from the certifying infrastructure, S ∩ C = ∅, itself subject to independent third-party audit; deterministic T-0 sealing applying salt-free SHA-256 hashing and a qualified electronic timestamp meeting the technical requirements of Article 42 of the eIDAS Regulation, whose resulting presumption of accuracy is established under Article 41; and independent judicial deposit with a huissier de justice, producing a constat establishing date certaine under Book 8 of the Belgian New Civil Code and providing opposable evidence of diligence in any subsequent regulatory or judicial proceeding.
[/AI-SNIPPET]
EXECUTIVE SUMMARY
The Regulatory Framework: the law of April 26, 2024, transposing the NIS 2 directive into Belgian law, imposes a strict obligation on management bodies to approve and actively supervise risk management measures. In the event of a systemic crisis, a failure to demonstrate active supervision exposes directors and CISOs to personal criminal liability for non-intentional fault due to negligence or imprudence.
The Technical Vulnerability: cloud observability infrastructures that share an administrative plane with the production environment they monitor are exposed to privilege escalation and contextual data manipulation targeting logging pipelines. Where this condition holds, the internal log loses its status as a neutral evidentiary witness.
The Probatory Impasse: corporate boards historically rely on self-attestations or logs extracted from the infrastructure under examination. Before a regulatory or judicial authority, this circularity is legally fragile: a system cannot usefully attest to its own integrity prior to a failure it may itself have suffered.
The SOURCE 0 Protocol: an architecture combining audited structural dissociation, sealing at the T-0 instant through salt-free SHA-256 hashing and a qualified eIDAS timestamp, and independent deposit with a huissier de justice through a constat of cryptographic equivalence.
While legal departments and CISOs confine themselves to a purely declarative, paper-based compliance posture, the evidentiary conditions of adversarial proceedings in 2026 call for a shift from text-based reporting to cryptographic architecture. Waiting for a crisis to reconstruct management diligence exposes corporate directors to a structural evidentiary weakness.
1 - THE RISK FRAMEWORK: DIRECTOR LIABILITY AND EVIDENTIARY FRAGILITY
1 - 1 Executive exposure under the NIS 2 transposition framework
The law of April 26, 2024, transposing the NIS 2 directive into Belgian law, formalizes a non-delegable duty: members of management bodies must approve cybersecurity risk management measures and supervise their implementation.
The liability risk: while the statutory framework provides for heavy administrative fines levied against the entity, up to EUR 10 million or 2 percent of global annual turnover, it does not exclude the application of general criminal law. In the event of a catastrophic systemic failure, a characterized lack of active supervision can be prosecuted as a non-intentional fault through negligence or imprudence, engaging the personal criminal liability of the decision-maker, provided the supervisory failure is causally linked to the damage sustained.
1 - 2 Structural vulnerabilities in cloud logging architectures
Technical compliance cannot rely exclusively on centralized cloud observability tools. Where the attack surface and the logging infrastructure share the same administrative cloud plane, a threat actor with elevated privileges can, in principle, alter or delete log data alongside the operational data it targets. Internal logs then cease to constitute independent third-party evidence: they become post-incident artefacts potentially subject to manipulation, contestable on that basis by a competent opposing expert.
2 - THE TRAP OF PROBATORY CIRCULARITY
Option A: board minutes, internal emails, and self-attestation. A document produced, archived, and presented by the party that relies on it constitutes, under evidence law, an unauthenticated unilateral declaration. In an ongoing investigation, the entire chain of custody remains under the exclusive control of the party asserting compliance.
Under Belgian electronic evidence law, governed by Book 8 of the New Civil Code, the probatory value of an electronically stored document lacking external certification is subject to the sovereign assessment of the judge. Because internal system metadata is readily alterable, such a document does not meet the technical qualification requirements of Article 42 of the eIDAS Regulation for a qualified electronic timestamp, and therefore does not benefit from the presumption of accuracy under Article 41. The organization attests to its own diligence, using its own tools, under its own supervision. Probatory weight is fragile in adversarial litigation.
Option B: centralized cloud logs and environment contamination. Evidence collected from an environment whose overall integrity has been compromised is inherently exposed to challenge. If the logging infrastructure resides within the perimeter of the affected cloud platform, the chain of custody is contestable. A competent opposing expert can seek to exclude these elements by demonstrating that an attacker held privileges allowing alteration of log sinks.
The mechanism of probatory circularity: requesting a system to attest to its own integrity prior to a failure it may itself have suffered is a logical impossibility. Without an external third-party mechanism establishing the initial integrity of the evidence trail, the director's position is not reinforced by a favourable presumption. A magistrate or regulatory authority may treat the absence of a structurally unalterable evidence trail predating the crisis as unfavourable to the party relying on internal records alone.
Forensic illustration. Context: a critical infrastructure operator subject to NIS 2 sustains a compromise of its cloud platform. The competent supervisory authority initiates proceedings and requests proof of active cybersecurity supervision by the management body.
Situation A, without a probatory dissociation protocol: the evidence produced consists of board minutes in PDF format and centralized SIEM logs extracted from the affected infrastructure. Integrity is contestable, since the chain of custody remains under the exclusive control of the party relying on it and the logs reside within the perimeter affected by the incident. Anteriority is not established, since internal metadata is readily alterable and does not meet the technical qualification requirements of Article 42 eIDAS. Opposability is weak, since the unauthenticated unilateral declaration carries limited weight in adversarial proceedings. The director's position lacks a favourable evidentiary presumption, with direct personal criminal exposure for failure to meet the active supervision obligation.
Situation B, with the SOURCE 0 architecture: the evidence produced is a Dossier de Réalité Historique sealed at T-0 and deposited with a huissier de justice prior to the incident. Integrity is difficult to contest, with a SHA-256 hash certified through a qualified electronic timestamp meeting Article 42 eIDAS requirements, and a constat attesting bit-by-bit equivalence of the escrowed file. Anteriority is established through a qualified timestamp predating the incident, whose accuracy benefits from the presumption under Article 41 eIDAS, verifiable by any third-party expert. Opposability before Belgian courts rests on date certaine under Book 8 of the New Civil Code; recognition before courts outside Belgium is governed by the evidentiary rules of the forum seized and assessed case by case. The director's position is supported by opposable evidence of diligence exercised prior to the incident.
Forensic verdict: the gap between these two situations is not necessarily a gap in actual diligence; the director may have exercised comparable supervision in both cases. The gap is a gap in opposable proof.
3 - THE ARCHITECTURE OF THE SOURCE 0 DOCTRINE
To address this circularity, the SOURCE 0 protocol establishes Compliance by Proof based on three components and a constitutive epistemological limit.
Structural Dissociation. The protocol physically and logically separates the operational system, S, which handles production data streams, from the certifying infrastructure, C, which captures and seals the evidentiary record. The condition S ∩ C = ∅ ensures that an attack on the production environment cannot, by design, reach the sealed record. This dissociation is not a self-declared architectural claim: it is subject to an independent third-party structural separation audit, the report of which is itself sealed under the T-0 protocol, so that probatory isolation rests on external verification rather than an assertion made by the party relying on it.
Sealing at the T-0 Instant. At the exact moment of managerial validation or critical technical instruction, the relevant data, whose format and metadata perimeter are defined in advance to ensure deterministic reproducibility, is frozen. The protocol applies a salt-free SHA-256 cryptographic hash combined with a qualified electronic timestamp meeting the technical requirements of Article 42 of the eIDAS Regulation. The status of the Trust Service Provider on the European Trust Service List is verified programmatically at the T-0 instant and recorded within the Dossier de Réalité Historique. Sealing applies without exception to every data element within the perimeter defined in advance, including board resolutions, CISO approvals, and critical operational directives. The absence of an expected element within the dossier constitutes, in itself, a documented forensic datapoint.
Independent Deposit. The Dossier de Réalité Historique is transferred outside the organisation's administrative perimeter into the custody of a huissier de justice, a public officer of the Belgian court system. This deposit is formalized by a constat, whereby the public officer certifies the bit-by-bit identity of the binary stream of the deposited file with the SHA-256 hash generated at the T-0 instant. This deposit establishes date certaine under Book 8 of the New Civil Code and confers opposability before Belgian courts. Recognition before courts outside Belgium is governed by the evidentiary rules of the forum seized and assessed case by case; it is not presumed automatic.
The constitutive epistemological limit: cryptographic sealing and deposit at the T-0 instant attest to the existence and structural integrity of the evidence trail at that specific moment. They do not validate the intrinsic accuracy or completeness of the substantive content sealed. A flawed, inaccurate, or incomplete governance document sealed at T-0 remains a flawed document with a certain date, nothing more. This delineation of the evidentiary perimeter is what the doctrine claims, and no more than what it claims.
4 - COMPARATIVE ANALYSIS OF GOVERNANCE ALTERNATIVES
The SOURCE 0 architecture combines audited structural dissociation, salt-free SHA-256 hashing with an eIDAS-qualified timestamp under Article 42, and deposit with a huissier de justice formalized by a constat of cryptographic equivalence, applied to the executive decision record. Measured against the combined requirements of anteriority, integrity, and opposability, market alternatives present conditional limitations.
Blockchain notarization alone does not establish the presumption of accuracy available under Article 41 of the eIDAS Regulation unless the ledger protocol used is backed end-to-end by an eIDAS-compliant Qualified Trust Service Provider. Hybrid architectures combining blockchain with a qualified timestamp address part of this gap, but absent independent judicial deposit, probatory circularity is not structurally addressed.
Externalized SOC or SIEM solutions partially mitigate environment contamination but do not address probatory circularity in the absence of systematic cryptographic sealing of executive governance acts and independent deposit with a public officer of the court.
Cloud observability tools remain exposed to privilege escalation affecting the unified administrative plane that hosts both production operations and logging infrastructure, wherever these functions share the same control layer.
CLOSING AXIOM
The law does not require material truth. It requires proof of diligence. SOURCE 0 seals that diligence.
REFERENCE NOTE
This article relies on the law of 26 April 2024 transposing Directive (EU) 2022/2555 (NIS 2) into Belgian law, on Regulation (EU) 2022/2554 (DORA), Article 25, on Regulation (EU) 910/2014 as amended by Regulation (EU) 2024/1183 (eIDAS 2), Articles 41 and 42, and on Book 8 of the Belgian New Civil Code. References to Article 41 of the eIDAS Regulation as the source of technical qualification requirements for electronic timestamps have been corrected to Article 42; Article 41 establishes the legal presumption of accuracy of an already-qualified timestamp, a distinction maintained consistently across this corpus. The designations "Operational DRH" and "Statutory DRH", together with the "Pillar A / Pillar B" nomenclature, have been corrected to the S / C notation and single Dossier de Réalité Historique used throughout this corpus. The instrument produced by the huissier de justice has been aligned with the term "constat" used elsewhere in this corpus. References to cloud provider security bulletins have been generalized pending a verifiable citation. Language describing the architecture as reversing a legal presumption of fault has been corrected to describe the production of opposable evidence of diligence, a claim this architecture can substantiate without asserting a specific procedural effect requiring independent statutory basis. A claim of opposability before European jurisdictions generally has been corrected to distinguish the automatic EU-wide recognition of a qualified timestamp's technical status under Article 41(2) eIDAS from the recognition of the Dossier de Réalité Historique before courts outside Belgium, which is assessed case by case. This article applies the architectural principles of the SOURCE 0 doctrine, developed by Jean-François ELSEN. SOURCE 0 is a registered trademark, BOIP/OBPI No. 1548293, Benelux.
REGULATORY NOTICE
This article is part of the SOURCE 0 Doctrine developed by Jean-François ELSEN. SOURCE 0 is a proprietary pre-execution cryptographic attestation architecture and a registered trademark (BOIP/OBPI No. 1548293, Benelux). For doctrinal consultations, legal memoranda, evidentiary governance reviews, or forensic compliance audits, inquiries may be addressed to Jean-François ELSEN.

