The mandate exists.
The condition record does not.
Not yet.
Every jurisdiction you operate in requires continuous monitoring of physical infrastructure integrity. Most covered entities today cannot meet that requirement with a physics record. VERA produces one.
- Periodic site inspections
- Annual audits
- SCADA and operational monitoring
- Self-reported incident logs
- Operator-controlled data
All of it is self-reported, periodic, and operator-controlled. None of it is independent. None of it is continuous. None of it is physics-based.
- Continuous physics-based monitoring
- Independent — not operator-generated
- Sealed condition record
- 24-hour incident signal capability
- Relying-party facing — not operator facing
The sensor is the instrument. The record is the product. The independence is the value.
The same requirement runs through every jurisdiction on the map.
Frameworks differ. The gap is the same. No jurisdiction has defined a standard for continuous independent physics-based monitoring of critical infrastructure. VERA fills that gap before the standard is mandated.
NIS2 Directive 2022/2555
Article 13 — covered entities must take appropriate technical measures to monitor the physical integrity of infrastructure. Eleven sectors designated including energy, digital infrastructure, and water. Data center operators and cloud providers explicitly covered.
Designation deadline: July 2026No continuous independent physics record exists for most covered entities. Periodic inspection is the current practice. The competent authority will ask how physical integrity is being monitored continuously. Most entities cannot answer with evidence.
TSA Security Directives
CISA Critical Infrastructure
NERC CIP-006 and CIP-014 require physical security and monitoring of bulk electric system assets. TSA pipeline security directives mandate continuous monitoring for covered pipeline operators. CISA sector-specific plans require physical security programs for all sixteen critical infrastructure sectors.
NERC enforcement: active — fines up to $1M per day per violationPeriodic inspection is the dominant model. SCADA monitoring covers cyber and operational state — not physical condition. No independent physics record standard exists for the bulk electric system or for data center infrastructure that draws from it.
CNI Resilience Framework
NIS2 transposition requires appropriate technical measures for physical resilience of network and information systems. Critical National Infrastructure framework designates energy, water, and digital infrastructure. NCSC guidance increasingly references physical monitoring alongside cyber.
NIS2 transposition: active from 2025Self-reported compliance is the current standard. No independent verification requirement exists for physical condition. The Lloyd’s and Swiss Re underwriting desks in London bind policies on assets they certify once — the independent physics record does not yet exist.
MAS Operational Resilience
Critical Information Infrastructure framework designates eleven sectors. Owners must conduct annual audits, submit compliance reports, and have measures to detect and respond to incidents. MAS operational resilience guidelines for financial entities require continuous monitoring of systems and physical environments effective 2023.
MAS guidelines: effective 2023Incident reporting is retrospective. No continuous monitoring standard for physical infrastructure condition is yet defined. Singapore’s position as the regional hub for project finance — Temasek, GIC, DBS infrastructure desk — means the gap has capital market implications across Southeast Asia.
Positive Security Obligations
Security of Critical Infrastructure Act 2018 imposes positive security obligations on designated entities including physical monitoring of critical assets. ASD has step-in powers for non-compliant entities. Data centers designated as critical infrastructure assets under the 2021 amendments. Sector risk management programs required.
Enforcement: active — ASD step-in powersAsset register exists. Continuous monitoring standard does not. Positive security obligations require physical monitoring but do not define the instrument. The Future Fund and Macquarie infrastructure portfolios include assets that require SOCI compliance — the independent physics record is the missing instrument.
Saudi NCA Standards
Qatar NCSA Framework
UAE Critical Infrastructure and Vital Assets regulation requires physical protection and monitoring of designated assets. Saudi NCA critical infrastructure protection standards mandate monitoring programs for energy and digital sectors. Qatar NCSA framework covers critical information infrastructure with physical security requirements.
UAE CIVA: active enforcementFramework exists. Verification standard does not. PIF, ADQ, Mubadala, and QIA are deploying capital into infrastructure assets across the region and globally. The verification standard for those assets does not yet exist. First mover defines it.
Africa — Where the standard is still being written.
The African Union Malabo Convention provides the baseline. South Africa’s Critical Infrastructure Protection Act 2019 — the most advanced framework on the continent — requires physical protection and periodic security assessment of designated assets. Kenya’s Critical Infrastructure Protection Bill is in parliament now. Nigeria’s CNII designation covers the energy sector. The CBN operational resilience guidelines for financial entities effective 2023 are the closest any African jurisdiction has come to a continuous monitoring requirement.
None of them have defined the instrument yet.
This is not a gap. This is an invitation.
Verified E.R.A. envisions Africa as the continent where the assurance standard is defined before it is mandated — not retrofitted after the fact. Where the development finance community, the sovereign institutions, and the infrastructure builders write the standard together, anchored in physics, before the regulation catches up.
The 600 million people without reliable electricity in Africa are not waiting for a compliance framework. They are waiting for infrastructure that delivers. Verified E.R.A. exists to confirm that it does.
We are actively seeking founding participants from African financial institutions, development banks, and infrastructure operators to help define what assurance means for the continent’s infrastructure era.
Join as a founding participant →Three ways to engage.
We are not a sensor company. We produce the independent condition record the regulation requires and the relying party can trust.
Resilience Plan Support
For entities being designated or recently designated under CER, SOCI, NERC CIP or equivalent. Baseline condition assessment, gap analysis against jurisdiction-specific mandate, and evidence package for competent authority submission.
Who engages: General Counsel, Chief Risk Officer, Head of Regulatory Affairs.
Continuous Monitoring Service
For designated entities that need ongoing compliance evidence. Continuous physics-based monitoring, monthly condition reports, incident detection support, and annual resilience evidence package for competent authority review.
Who engages: Chief Operating Officer, Infrastructure Director.
Independent Engineer Support
For IE firms certifying resilience plans for covered entities. White-labeled condition record, physics evidence behind IE certification, and continuous record between visits — liability shield for the engineer, assurance for the lender.
Who engages: IE firm CRO, Project Director.
The regulation requires continuous monitoring of physical infrastructure integrity.
The instrument that produces that record independently does not yet exist at scale.
We are building it. We are entering the Verified E.R.A.
Start the conversation