DORA Operational Resilience Pack

This is the entry point for the DORA pack: start here, then follow the pack surfaces for incident reporting, the Register of Information, TLPT evidence, and Article 45 information sharing.

The DORA Operational Resilience Pack is an optional Assurance pack for financial-entity operators that need DORA-oriented evidence, handoff, and retention workflows. Stella supplies deterministic local artifacts, timelines, operator settings, and signed handoff support; the customer/operator remains the regulated financial entity and reporting party.

Claim boundary: operator-support.

Primary evidence scope: operator-observed-estate.

The pack supports operational-resilience evidence for ICT software Stella can monitor, deploy, scan, or control for the financial-entity operator: services, release bundles, container images, direct software dependencies, integrations, plugins, runtime host agents, asset registry entries, policy gates, and signed evidence bundles. Financial-entity legal identity, ICT risk strategy, tolerance decisions, outsourcing contract terms, subcontracting beyond direct integrations, competent-authority filing, and formal approvals remain operator-supplied.

Pack Surfaces

SurfacePurpose
Major ICT incident reportingClassify incidents against the seven DORA criteria and prepare initial, intermediate, and final signed handoff artifacts.
Register of InformationProduce annual RoI B.01-B.14 local-contract bundles with retention, prior-year hash binding, and operator-filled subcontracting provenance.
TLPT evidencePrepare white-team TLPT scoping, replay baselines, and signed EvidenceLocker capsules without running offensive tooling.
Information sharingGenerate and dispatch STIX 2.1/TAXII 2.1-aligned Article 45 sharing batches through dedicated DORA-purpose channels.

Current Implementation Posture

The pack is exposed as one optional Assurance pack in Web and CLI discovery, but not every owning service reports DORA pack-level readiness yet. Web and CLI must fail closed for missing DORA export or reporting profile readiness instead of treating local commands as production readiness.

CapabilityCurrent runtime statusRemaining documented gap
Major ICT incident classification and report handoffTelemetry classifies frozen facts; Notify encodes local XBRL/iXBRL/envelope artifacts; CLI exports and verifies filesystem handoffs.Official EBA schema validation requires the DORA incident taxonomy completion procedure: Framework 4.3 was re-verified as the wrong asset, so a correct machine-validation package or operator-supplied package decision is required before any official XSD/XBRL claim. Generic Assurance reporting profile dora.article19.incident still needs registry exposure.
Register of InformationFindings encodes local B.01-B.14 XML/index output; CLI has local-contract export and verify paths; EvidenceLocker has DORA RoI retention metadata. Official EBA XSD-structural validation is live against the vendored, SHA-256-pinned pin eba-dora-roi-reporting-framework-4.0-taxo-package-4.0-errata5 (offline; flips conformance from not-claimed to claimed-against:..., fail-closed to the local contract when the package is absent/mismatched).Deeper XBRL conformance (DPM dimensional, formula/assertion rules, instance-level XBRL processing) is a residual follow-up. ExportCenter dora.roi readiness no longer reports dora-roi-schema-mapping-missing once the pin validates; remaining source-data and owner-approval gates stay operator-controlled.
TLPT evidenceCLI can create scope, baseline, pack, and verification handoff artifacts over local inputs.Live Graph query mode and EvidenceLocker TLPT audit action emission remain service-owned follow-up work.
Article 45 information sharingNotify has a dedicated dora-info-sharing purpose channel and Notifier worker dispatch path that persists receipt metadata.Tenant channel enablement, subscriber approvals, trust material, and live delivery remain operator-controlled setup; pack-level readiness must stay unavailable until those service-owned checks are exposed.

Assurance Descriptor

The embedded pack descriptor is:

{
  "schemaVersion": "assurance-pack-v1",
  "packId": "dora",
  "frameworkId": "dora",
  "packVersion": "1.0.0",
  "displayName": "DORA Operational Resilience Pack",
  "claimBoundary": "operator-support",
  "evidenceScopes": ["operator-observed-estate", "operator-supplied", "stella-supplier"],
  "coverageSummary": {
    "primaryScope": "operator-observed-estate",
    "coverageLabel": "Operational-resilience evidence for Stella-monitored or Stella-deployed ICT software.",
    "supplierEvidenceProfile": "stella.supplier-evidence"
  },
  "jurisdictions": ["EU"],
  "features": ["exports", "timelines", "asset-inventory", "retention", "info-sharing", "tlpt-evidence"],
  "setupPrerequisites": [
    "dora.major-incident.handoff",
    "dora.roi.local-contract-export",
    "dora.info-sharing.channel",
    "dora.tlpt.evidence-pack"
  ],
  "exports": [
    "dora.major-incident-report",
    "dora.roi",
    "dora.info-sharing",
    "dora.tlpt-evidence-pack"
  ],
  "reportingTimelines": ["dora.article19.incident"],
  "controlMappings": [
    "dora-incident-classification-v1",
    "dora-major-incident-report-v1",
    "dora-roi-v1",
    "dora-info-sharing-event-v1",
    "tlpt-evidence-pack-v1"
  ]
}

This descriptor is discovery metadata. It does not replace the pack-specific DORA commands and does not imply that DORA exports, reporting timelines, or handoff channels are configured for a tenant.

Export And Handoff Profiles

Profile idPurposeCurrent compatibility route
dora.major-incident-reportSigned initial, intermediate, or final major ICT incident report handoff.stella export dora-incident-report, stella verify dora-incident-report
dora.roiAnnual RoI local-contract ZIP with retention metadata and prior-year hash binding.stella export dora-roi, stella verify dora-roi
dora.info-sharingSTIX/TAXII-aligned Article 45 batch and receipt handoff.stella export dora-info-sharing, stella verify dora-info-sharing
dora.tlpt-evidence-packSigned TLPT EvidenceLocker capsule handoff.stella tlpt pack, stella verify tlpt-pack

Reporting Timeline Profiles

Profile idPurposeRuntime route
dora.article19.incidentDORA major ICT incident initial, intermediate, and final report milestones over the shared Notify timeline.GET /api/v1/regulatory/reporting-timelines?regime=dora

Notify already has a dora runtime regime in the shared incident-reporting timeline. The generic Assurance reporting profile endpoint must return not-found or unavailable for dora.article19.incident until its readiness checks are wired and can fail closed with stable reason codes.

Source Contracts And Module Docs

Product Boundary

This pack must not say that Stella is DORA compliant or that enabling the pack submits anything to a regulator. The safe product claim is that Stella helps a financial-entity operator collect evidence, prepare signed handoff artifacts, track deadlines, retain artifacts, and run offline verification.

Do not use this pack as legal advice, a regulator portal, a source of truth for the operator’s legal entity data, a substitute for competent-authority filing, or a TLPT execution platform. Operator-supplied fields remain labelled as operator supplied.

When Stella Ops is an ICT third-party provider in the operator estate, attach stella.supplier-evidence for Stella release, SBOM/VEX, lifecycle, CVD, signing, and incident-notification posture. That profile is supplier evidence, not a declaration that Stella is the operator’s financial entity or a critical ICT third-party provider.

Release Pinning

DORA schema and taxonomy pins must be rechecked during each Stella release candidate cycle. Release notes must call out the exact local pins used for:

Runtime code must not fetch regulator schemas or taxonomies from the network. Approved schema packages must enter through the offline asset intake and license review path before they can unblock fileable XBRL/XSD validation.

Change Log

Date (UTC)UpdateOwner
2026-06-16Reconciled to verified code state. Confirmed against src/: all four export profiles (dora.roi, dora.major-incident-report, dora.info-sharing, dora.tlpt-evidence-pack) registered in AssuranceExportProfileRegistry; RoI runs live offline XSD-structural EBA validation (DoraRoiTaxonomyValidator, flips not-claimedclaimed-against:eba-reporting-framework-4.0-taxo-package-4.0-errata5, fail-closed on absent/mismatched SHA-256, XSD-structural only); TLPT pack (TlptCommandGroup) and Article 45 info-sharing (DoraInfoSharingExportService + Notifier durable dispatch) shipped; info-sharing signer hardened — legacy in-line HMAC signer replaced by ICryptoProviderRegistryICryptoSigner (DoraInfoSharingSignerService), regression guard Dispatcher_DoesNotReference_InlineHmacReferenceSigner confirms the HMAC types are gone. Residual: deeper XBRL/DPM conformance, CLI-only bundle production (no live HTTP POST .../runs), no live e2e. Major-incident EBA XBRL/XSD validation stays blocked — no valid upstream DORA-IR taxonomy package (Framework 4.3 = wrong asset). operator-support claim boundary unchanged.Documentation