DORA Operational Resilience Pack
This is the entry point for the DORA pack: start here, then follow the pack surfaces for incident reporting, the Register of Information, TLPT evidence, and Article 45 information sharing.
The DORA Operational Resilience Pack is an optional Assurance pack for financial-entity operators that need DORA-oriented evidence, handoff, and retention workflows. Stella supplies deterministic local artifacts, timelines, operator settings, and signed handoff support; the customer/operator remains the regulated financial entity and reporting party.
Claim boundary: operator-support.
Primary evidence scope: operator-observed-estate.
The pack supports operational-resilience evidence for ICT software Stella can monitor, deploy, scan, or control for the financial-entity operator: services, release bundles, container images, direct software dependencies, integrations, plugins, runtime host agents, asset registry entries, policy gates, and signed evidence bundles. Financial-entity legal identity, ICT risk strategy, tolerance decisions, outsourcing contract terms, subcontracting beyond direct integrations, competent-authority filing, and formal approvals remain operator-supplied.
Pack Surfaces
| Surface | Purpose |
|---|---|
| Major ICT incident reporting | Classify incidents against the seven DORA criteria and prepare initial, intermediate, and final signed handoff artifacts. |
| Register of Information | Produce annual RoI B.01-B.14 local-contract bundles with retention, prior-year hash binding, and operator-filled subcontracting provenance. |
| TLPT evidence | Prepare white-team TLPT scoping, replay baselines, and signed EvidenceLocker capsules without running offensive tooling. |
| Information sharing | Generate and dispatch STIX 2.1/TAXII 2.1-aligned Article 45 sharing batches through dedicated DORA-purpose channels. |
Current Implementation Posture
The pack is exposed as one optional Assurance pack in Web and CLI discovery, but not every owning service reports DORA pack-level readiness yet. Web and CLI must fail closed for missing DORA export or reporting profile readiness instead of treating local commands as production readiness.
| Capability | Current runtime status | Remaining documented gap |
|---|---|---|
| Major ICT incident classification and report handoff | Telemetry classifies frozen facts; Notify encodes local XBRL/iXBRL/envelope artifacts; CLI exports and verifies filesystem handoffs. | Official EBA schema validation requires the DORA incident taxonomy completion procedure: Framework 4.3 was re-verified as the wrong asset, so a correct machine-validation package or operator-supplied package decision is required before any official XSD/XBRL claim. Generic Assurance reporting profile dora.article19.incident still needs registry exposure. |
| Register of Information | Findings encodes local B.01-B.14 XML/index output; CLI has local-contract export and verify paths; EvidenceLocker has DORA RoI retention metadata. Official EBA XSD-structural validation is live against the vendored, SHA-256-pinned pin eba-dora-roi-reporting-framework-4.0-taxo-package-4.0-errata5 (offline; flips conformance from not-claimed to claimed-against:..., fail-closed to the local contract when the package is absent/mismatched). | Deeper XBRL conformance (DPM dimensional, formula/assertion rules, instance-level XBRL processing) is a residual follow-up. ExportCenter dora.roi readiness no longer reports dora-roi-schema-mapping-missing once the pin validates; remaining source-data and owner-approval gates stay operator-controlled. |
| TLPT evidence | CLI can create scope, baseline, pack, and verification handoff artifacts over local inputs. | Live Graph query mode and EvidenceLocker TLPT audit action emission remain service-owned follow-up work. |
| Article 45 information sharing | Notify has a dedicated dora-info-sharing purpose channel and Notifier worker dispatch path that persists receipt metadata. | Tenant channel enablement, subscriber approvals, trust material, and live delivery remain operator-controlled setup; pack-level readiness must stay unavailable until those service-owned checks are exposed. |
Assurance Descriptor
The embedded pack descriptor is:
{
"schemaVersion": "assurance-pack-v1",
"packId": "dora",
"frameworkId": "dora",
"packVersion": "1.0.0",
"displayName": "DORA Operational Resilience Pack",
"claimBoundary": "operator-support",
"evidenceScopes": ["operator-observed-estate", "operator-supplied", "stella-supplier"],
"coverageSummary": {
"primaryScope": "operator-observed-estate",
"coverageLabel": "Operational-resilience evidence for Stella-monitored or Stella-deployed ICT software.",
"supplierEvidenceProfile": "stella.supplier-evidence"
},
"jurisdictions": ["EU"],
"features": ["exports", "timelines", "asset-inventory", "retention", "info-sharing", "tlpt-evidence"],
"setupPrerequisites": [
"dora.major-incident.handoff",
"dora.roi.local-contract-export",
"dora.info-sharing.channel",
"dora.tlpt.evidence-pack"
],
"exports": [
"dora.major-incident-report",
"dora.roi",
"dora.info-sharing",
"dora.tlpt-evidence-pack"
],
"reportingTimelines": ["dora.article19.incident"],
"controlMappings": [
"dora-incident-classification-v1",
"dora-major-incident-report-v1",
"dora-roi-v1",
"dora-info-sharing-event-v1",
"tlpt-evidence-pack-v1"
]
}
This descriptor is discovery metadata. It does not replace the pack-specific DORA commands and does not imply that DORA exports, reporting timelines, or handoff channels are configured for a tenant.
Export And Handoff Profiles
| Profile id | Purpose | Current compatibility route |
|---|---|---|
dora.major-incident-report | Signed initial, intermediate, or final major ICT incident report handoff. | stella export dora-incident-report, stella verify dora-incident-report |
dora.roi | Annual RoI local-contract ZIP with retention metadata and prior-year hash binding. | stella export dora-roi, stella verify dora-roi |
dora.info-sharing | STIX/TAXII-aligned Article 45 batch and receipt handoff. | stella export dora-info-sharing, stella verify dora-info-sharing |
dora.tlpt-evidence-pack | Signed TLPT EvidenceLocker capsule handoff. | stella tlpt pack, stella verify tlpt-pack |
Reporting Timeline Profiles
| Profile id | Purpose | Runtime route |
|---|---|---|
dora.article19.incident | DORA major ICT incident initial, intermediate, and final report milestones over the shared Notify timeline. | GET /api/v1/regulatory/reporting-timelines?regime=dora |
Notify already has a dora runtime regime in the shared incident-reporting timeline. The generic Assurance reporting profile endpoint must return not-found or unavailable for dora.article19.incident until its readiness checks are wired and can fail closed with stable reason codes.
Source Contracts And Module Docs
- Assurance Runtime
- Assurance Scope Model
- Assurance Pack v1
- Assurance Evidence Export v1
- Assurance Reporting Timeline v1
- Assurance Setup Prerequisites v1
- DORA Incident Classification v1
- DORA Major Incident Report v1
- DORA Incident Taxonomy Completion Procedure
- DORA Register of Information v1
- DORA Info Sharing Event v1
- TLPT Scope v1
- TLPT Baseline v1
- TLPT Evidence Pack v1
- Notify architecture
- DORA Article 45 information-sharing runbook
- DORA incident CLI guide
- DORA RoI CLI guide
- TLPT CLI guide
- DORA RoI retention policy
- Integrations DORA RoI metadata
- Stella Supplier Evidence Profile v1
Product Boundary
This pack must not say that Stella is DORA compliant or that enabling the pack submits anything to a regulator. The safe product claim is that Stella helps a financial-entity operator collect evidence, prepare signed handoff artifacts, track deadlines, retain artifacts, and run offline verification.
Do not use this pack as legal advice, a regulator portal, a source of truth for the operator’s legal entity data, a substitute for competent-authority filing, or a TLPT execution platform. Operator-supplied fields remain labelled as operator supplied.
When Stella Ops is an ICT third-party provider in the operator estate, attach stella.supplier-evidence for Stella release, SBOM/VEX, lifecycle, CVD, signing, and incident-notification posture. That profile is supplier evidence, not a declaration that Stella is the operator’s financial entity or a critical ICT third-party provider.
Release Pinning
DORA schema and taxonomy pins must be rechecked during each Stella release candidate cycle. Release notes must call out the exact local pins used for:
- major incident reporting:
dora-major-incident-report-eu-2025-302-local-contract-v1until the incident taxonomy completion procedure records a correct official package or operator-supplied package path; historicaleba-dora-incident-reporting-framework-4.3isABANDONED-wrong-asset; - RoI:
eba-dora-roi-reporting-framework-4.0-taxo-package-4.0-errata5; - local contract markers when official schema validation is still unavailable.
Runtime code must not fetch regulator schemas or taxonomies from the network. Approved schema packages must enter through the offline asset intake and license review path before they can unblock fileable XBRL/XSD validation.
Change Log
| Date (UTC) | Update | Owner |
|---|---|---|
| 2026-06-16 | Reconciled to verified code state. Confirmed against src/: all four export profiles (dora.roi, dora.major-incident-report, dora.info-sharing, dora.tlpt-evidence-pack) registered in AssuranceExportProfileRegistry; RoI runs live offline XSD-structural EBA validation (DoraRoiTaxonomyValidator, flips not-claimed→claimed-against:eba-reporting-framework-4.0-taxo-package-4.0-errata5, fail-closed on absent/mismatched SHA-256, XSD-structural only); TLPT pack (TlptCommandGroup) and Article 45 info-sharing (DoraInfoSharingExportService + Notifier durable dispatch) shipped; info-sharing signer hardened — legacy in-line HMAC signer replaced by ICryptoProviderRegistry→ICryptoSigner (DoraInfoSharingSignerService), regression guard Dispatcher_DoesNotReference_InlineHmacReferenceSigner confirms the HMAC types are gone. Residual: deeper XBRL/DPM conformance, CLI-only bundle production (no live HTTP POST .../runs), no live e2e. Major-incident EBA XBRL/XSD validation stays blocked — no valid upstream DORA-IR taxonomy package (Framework 4.3 = wrong asset). operator-support claim boundary unchanged. | Documentation |
