Solutions — instrument
DORA is mappable. We have not mapped it yet.
Regulation (EU) 2022/2554. Not an AI regulation — an operational resilience one — in force since January 2025. RotaGrant touches two of its five pillars, which is an argument for mapping those two rather than a reason to have no map. This one is a gap in our coverage, not a judgement about the instrument.
Where it contributes
- ICT third-party risk
- An agent's dependency surface is a third-party surface. MCP servers and their tool manifests are inventoried, watched for change, and a description that changes under an agent's feet is recorded as drift rather than absorbed.
- Incident reporting
- The classification and clock machinery is instrument-agnostic. DORA's thresholds and templates differ from Article 73's and are not encoded — but the record an incident report is assembled from is the same record.
It contributes nothing to business continuity or to the ICT risk management framework itself. Those are the bulk of DORA and a vendor implying otherwise is selling you a gap.
Why there is no clause map
Because we have not written one. That is the whole answer, and it is worth
separating from the two regimes on this site that genuinely cannot be
mapped — MAS FEAT, where the firm
defines its own objective, and the UK
approach, which has no statute to enumerate. DORA has numbered
articles, and partial coverage is not the obstacle: a clause carries a
provenance of platform, hybrid or
customer, and only the first two are scored. The three pillars
we do not touch would be recorded as yours and excluded from the reading,
exactly as the AI Act map covers the
articles a platform can evidence rather than the whole Act.
What a map would cover: Article 17–20 on incident management, classification and reporting, against the same classification machinery that already serves Article 73; and Articles 28–30 on ICT third-party risk, where the register of information is an inventory obligation and the agent inventory, model inventory and configuration provenance are the evidence. Article 25's testing requirement is a partial — the adversarial grid is a real test of one component, and it is not threat-led penetration testing under TIBER-EU.
Until it exists, the EU profile selects eu-ai-act and
gdpr and nothing else, and a DORA reading of this platform is
something you would have to assemble yourself from the evidence it
produces. Clause maps are YAML validated against the evidence registry at
load, so you do not have to wait for us — but you should know you are
waiting.
RotaGrant ships no clause map for DORA. The engine takes clause maps as data, so one can be authored — by you, by your counsel, or with us — and it will be scored like any other. What this page will not do is imply a mapping that does not exist, because a readiness percentage against an instrument nobody encoded is a number with no denominator.