DORA
Regulation (EU) 2022/2554 - In force since January 17, 2025
DORA (Regulation 2022/2554) requires EU financial entities to maintain ICT risk management, incident reporting, resilience testing, and third-party oversight. It applies to banks, insurers, investment firms, payment institutions, and their ICT providers.
Asqav signs every agent action with ML-DSA signatures and generates DORA ICT risk management reports with PDF export.
The Asqav receipt format is profiled in IETF Internet-Draft draft-marques-asqav-compliance-receipts, which binds the underlying signed-receipt format to DORA Article 17 with a 5-year retention floor sourced from the sectoral instruments (MiFID II Art 16(7), AMLD Art 40) and dual-anchor timestamping.
Requirements
| Article | Requirement | Asqav binding |
|---|---|---|
| Art. 5-6 | Documented ICT risk management framework, subject to audit. | Immutable, cryptographically signed audit trail of every agent action. |
| Art. 9 | ICT security tools with strong authentication and cryptographic protection. | ML-DSA signatures and per-agent identity key pairs. |
| Art. 10 | Prompt anomaly detection with defined alert thresholds. | Configurable per-agent alert rules. Content scanning catches PII, prompt injections, secrets. |
| Art. 11-12 | Response, recovery, and backup for critical functions. | Tamper-evident signed logs survive compromise and support incident investigation. |
| Art. 17 | Classify, document, and report ICT incidents with root-cause analysis. | Incident management with severity tracking, escalation, and agent quarantine. Signed records provide forensic evidence. |
| Art. 28 | Third-party ICT risk management with audit rights. | Audit export plus public verification endpoint for independent third-party audits. |
Bring-your-own KMS, customer-owned storage, and air-gapped on-prem mode are all available for ICT third-party risk profiles that disallow outbound traffic. Full mapping detail in the docs.