DORA

Regulation (EU) 2022/2554 - In force since January 17, 2025

DORA (Regulation 2022/2554) requires EU financial entities to maintain ICT risk management, incident reporting, resilience testing, and third-party oversight. It applies to banks, insurers, investment firms, payment institutions, and their ICT providers.

Asqav signs every agent action with ML-DSA signatures and generates DORA ICT risk management reports with PDF export.

The Asqav receipt format is profiled in IETF Internet-Draft draft-marques-asqav-compliance-receipts, which binds the underlying signed-receipt format to DORA Article 17 with a 5-year retention floor sourced from the sectoral instruments (MiFID II Art 16(7), AMLD Art 40) and dual-anchor timestamping.

Requirements

Article Requirement Asqav binding
Art. 5-6 Documented ICT risk management framework, subject to audit. Immutable, cryptographically signed audit trail of every agent action.
Art. 9 ICT security tools with strong authentication and cryptographic protection. ML-DSA signatures and per-agent identity key pairs.
Art. 10 Prompt anomaly detection with defined alert thresholds. Configurable per-agent alert rules. Content scanning catches PII, prompt injections, secrets.
Art. 11-12 Response, recovery, and backup for critical functions. Tamper-evident signed logs survive compromise and support incident investigation.
Art. 17 Classify, document, and report ICT incidents with root-cause analysis. Incident management with severity tracking, escalation, and agent quarantine. Signed records provide forensic evidence.
Art. 28 Third-party ICT risk management with audit rights. Audit export plus public verification endpoint for independent third-party audits.

Bring-your-own KMS, customer-owned storage, and air-gapped on-prem mode are all available for ICT third-party risk profiles that disallow outbound traffic. Full mapping detail in the docs.