Compliance pack · DORA · Regulation (EU) 2022/2554
DORA evidence for financial-entity operators
The DORA pack turns the evidence chain that gates your releases into the artefacts DORA names: classified ICT incidents, the Register of Information, TLPT evidence, and Article 45 threat-information sharing. Each artefact records what was validated — and what was not.
Pack ownership: operator-support — Stella Ops helps your obligated team assemble and sign what a regulator asks for. It never files, never certifies, and never makes you compliant.
The claim boundary
Enabling starts evidence collection in conservative evidence-only mode; it does not claim regulatory compliance. The operator always remains the regulated decision-maker.
Regulation
Digital Operational Resilience Act — Regulation (EU) 2022/2554
Applies since
17 January 2025
Who it binds
Financial entities and their critical ICT third-party providers

What the pack ships today
Five artefact families, produced from recorded evidence, and only from recorded evidence.
Deterministic ICT incident classifier
Operational TodayClassifies ICT incidents against the seven DORA criteria. Deterministic: the same inputs produce the same classification every time, so a re-run months later matches the original.
Register of Information (B.01–B.14)
Operational TodayBuilds the B.01–B.14 register and validates it live against the official EBA RoI XSD. The taxonomy is vendored into the release and SHA-256 pinned: validation runs offline and fails closed — a register that does not validate is not exported.
Validation today is XSD-structural — schema shape and datatypes, not EBA business rules.
TLPT evidence pack
Operational TodayThreat-led penetration testing evidence, packaged and signed, retained 10 years by default. The pack binds scope, findings, and remediation state to one engagement record.
Article 45 information sharing
Operational TodayCyber threat information exchange under Article 45 as STIX 2.1 over TAXII 2.1. Outbound bundles carry hardware-backed signatures.
Four registered export profiles
Operational TodayEach export is a registered, versioned profile — not an ad-hoc report.
Register of InformationMajor-incident reportInformation-sharing bundleTLPT evidence pack
What is not claimed
What is validated, and what is not claimed.
Major-incident XBRL/iXBRL conformance
Not claimedThe pack produces major-incident reports as XBRL/iXBRL and validates them locally. EBA-taxonomy conformance is not claimed, because no valid upstream DORA-IR taxonomy package exists yet. Conformance will be claimed when the official asset ships — not before.
Register of Information validation scope
Validated: structuralThe register validates against the official EBA XSD — pinned, offline, fail-closed. That proves structure and datatypes. It does not prove EBA business-rule semantics, and the export does not say otherwise.
Retention defaults
Defaults follow each artefact's regulatory horizon. Every window is operator-configurable.
| Artefact | Default retention |
|---|---|
| Register of Information | 7 years |
| Major-incident report | 7 years |
| TLPT evidence pack | 10 years |
Built on the release evidence chain, not beside it
Same evidence primitives
The pack reads the same signed statements that gate releases along Source → Build → Scan → Verdict → Decision → Deploy → Watch. There is no second compliance database to keep in sync. DSSEDead Simple Signing Envelope - a simple, flexible standard for signing arbitrary data with cryptographic signatures
Incident deadlines as Notify timelines
When the classifier marks an incident major, Notify opens the report windows and counts each one down. A missed window shows as missed — it is never silently absorbed.
Scope the DORA pack against your estate
Bring your entity type and incident volume. We will tell you what the pack covers today and what remains yours to file.
