{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2025:7ZSVET63HZ5YRHVQ3BJTWFSDEH","short_pith_number":"pith:7ZSVET63","schema_version":"1.0","canonical_sha256":"fe65524fdb3e7b889eb0d8533b164321d833c7ba5a63cfdd33229d7a5a051edc","source":{"kind":"arxiv","id":"2508.21386","version":1},"attestation_state":"computed","paper":{"title":"Risks and Compliance with the EU's Core Cyber Security Legislation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CY","cs.SE"],"primary_cat":"cs.CR","authors_text":"Jakub Sk\\'orczynski, Jesper L{\\o}ffler Nielsen, Jukka Ruohonen","submitted_at":"2025-08-29T08:02:57Z","abstract_excerpt":"The European Union (EU) has long favored a risk-based approach to regulation. Such an approach is also used in recent cyber security legislation enacted in the EU. Risks are also inherently related to compliance with the new legislation. Objective: The paper investigates how risks are framed in the EU's five core cyber security legislative acts, whether the framings indicate convergence or divergence between the acts and their risk concepts, and what qualifying words and terms are used when describing the legal notions of risks. Method : The paper's methodology is based on qualitative legal in"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2508.21386","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2025-08-29T08:02:57Z","cross_cats_sorted":["cs.CY","cs.SE"],"title_canon_sha256":"cbfac5781fc7a22bfcaece7bfc55fc05bbd28f52a4d5cc6fb3c2821859f96e99","abstract_canon_sha256":"539f3e93df1b0044edf5d91b72e3ea5887c05694a7424fb79fe54f4d080130ab"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T12:01:33.951043Z","signature_b64":"fqT1QiYOg50w071zpbv+piwu5hAPVN6FRyY1mhVZsvofdcLWujewFNl3OFHTsVgs9hRpdVZ89vv3eZz6ddllAA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"fe65524fdb3e7b889eb0d8533b164321d833c7ba5a63cfdd33229d7a5a051edc","last_reissued_at":"2026-07-05T12:01:33.950536Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T12:01:33.950536Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Risks and Compliance with the EU's Core Cyber Security Legislation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":["cs.CY","cs.SE"],"primary_cat":"cs.CR","authors_text":"Jakub Sk\\'orczynski, Jesper L{\\o}ffler Nielsen, Jukka Ruohonen","submitted_at":"2025-08-29T08:02:57Z","abstract_excerpt":"The European Union (EU) has long favored a risk-based approach to regulation. Such an approach is also used in recent cyber security legislation enacted in the EU. Risks are also inherently related to compliance with the new legislation. Objective: The paper investigates how risks are framed in the EU's five core cyber security legislative acts, whether the framings indicate convergence or divergence between the acts and their risk concepts, and what qualifying words and terms are used when describing the legal notions of risks. Method : The paper's methodology is based on qualitative legal in"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2508.21386","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2508.21386/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2508.21386","created_at":"2026-07-05T12:01:33.950597+00:00"},{"alias_kind":"arxiv_version","alias_value":"2508.21386v1","created_at":"2026-07-05T12:01:33.950597+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2508.21386","created_at":"2026-07-05T12:01:33.950597+00:00"},{"alias_kind":"pith_short_12","alias_value":"7ZSVET63HZ5Y","created_at":"2026-07-05T12:01:33.950597+00:00"},{"alias_kind":"pith_short_16","alias_value":"7ZSVET63HZ5YRHVQ","created_at":"2026-07-05T12:01:33.950597+00:00"},{"alias_kind":"pith_short_8","alias_value":"7ZSVET63","created_at":"2026-07-05T12:01:33.950597+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2509.06012","citing_title":"A Rapid Review Regarding the Concept of Legal Requirements in Requirements Engineering","ref_index":27,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH","json":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH.json","graph_json":"https://pith.science/api/pith-number/7ZSVET63HZ5YRHVQ3BJTWFSDEH/graph.json","events_json":"https://pith.science/api/pith-number/7ZSVET63HZ5YRHVQ3BJTWFSDEH/events.json","paper":"https://pith.science/paper/7ZSVET63"},"agent_actions":{"view_html":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH","download_json":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH.json","view_paper":"https://pith.science/paper/7ZSVET63","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2508.21386&json=true","fetch_graph":"https://pith.science/api/pith-number/7ZSVET63HZ5YRHVQ3BJTWFSDEH/graph.json","fetch_events":"https://pith.science/api/pith-number/7ZSVET63HZ5YRHVQ3BJTWFSDEH/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH/action/timestamp_anchor","attest_storage":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH/action/storage_attestation","attest_author":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH/action/author_attestation","sign_citation":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH/action/citation_signature","submit_replication":"https://pith.science/pith/7ZSVET63HZ5YRHVQ3BJTWFSDEH/action/replication_record"}},"created_at":"2026-07-05T12:01:33.950597+00:00","updated_at":"2026-07-05T12:01:33.950597+00:00"}