rotascale authority and evidence for AI agents See the demo

Solutions — instrument

DORA is mappable. We have not mapped it yet.

Regulation (EU) 2022/2554. Not an AI regulation — an operational resilience one — in force since January 2025. RotaGrant touches two of its five pillars, which is an argument for mapping those two rather than a reason to have no map. This one is a gap in our coverage, not a judgement about the instrument.

Regulation (EU) 2022/2554 ESAs · national competent authorities not mapped
Status
Applies from 2025-01-17
Applies to
EU financial entities and their critical ICT providers

Where it contributes

ICT third-party risk
An agent's dependency surface is a third-party surface. MCP servers and their tool manifests are inventoried, watched for change, and a description that changes under an agent's feet is recorded as drift rather than absorbed.
Incident reporting
The classification and clock machinery is instrument-agnostic. DORA's thresholds and templates differ from Article 73's and are not encoded — but the record an incident report is assembled from is the same record.

It contributes nothing to business continuity or to the ICT risk management framework itself. Those are the bulk of DORA and a vendor implying otherwise is selling you a gap.

Why there is no clause map

Because we have not written one. That is the whole answer, and it is worth separating from the two regimes on this site that genuinely cannot be mapped — MAS FEAT, where the firm defines its own objective, and the UK approach, which has no statute to enumerate. DORA has numbered articles, and partial coverage is not the obstacle: a clause carries a provenance of platform, hybrid or customer, and only the first two are scored. The three pillars we do not touch would be recorded as yours and excluded from the reading, exactly as the AI Act map covers the articles a platform can evidence rather than the whole Act.

What a map would cover: Article 17–20 on incident management, classification and reporting, against the same classification machinery that already serves Article 73; and Articles 28–30 on ICT third-party risk, where the register of information is an inventory obligation and the agent inventory, model inventory and configuration provenance are the evidence. Article 25's testing requirement is a partial — the adversarial grid is a real test of one component, and it is not threat-led penetration testing under TIBER-EU.

Until it exists, the EU profile selects eu-ai-act and gdpr and nothing else, and a DORA reading of this platform is something you would have to assemble yourself from the evidence it produces. Clause maps are YAML validated against the evidence registry at load, so you do not have to wait for us — but you should know you are waiting.

RotaGrant ships no clause map for DORA. The engine takes clause maps as data, so one can be authored — by you, by your counsel, or with us — and it will be scored like any other. What this page will not do is imply a mapping that does not exist, because a readiness percentage against an instrument nobody encoded is a number with no denominator.