All frameworks
    Reg. (EU) 2022/2554Evidence pack

    DORA

    DORA has applied to EU financial entities since 17 January 2025. When you put AI into operational processes (credit scoring, fraud detection, KYC, customer service), the model providers behind it (OpenAI, Anthropic, Google) become ICT third-party service providers in scope. Nyx is the single control point that makes that AI surface auditable, and generates a DORA evidence pack on demand.

    ReferenceRequirementNyx capability
    Pillar 1 · Art. 5-6ICT risk management frameworkCentralized register of AI ICT assets with continuous risk scoring and policy enforcement, feeding the management body's framework
    Pillar 1 · Art. 9Protection & preventionOn-device PII redaction and k-anonymity before data leaves the endpoint; Ed25519-signed policy, TLS + AES-256
    Pillar 2 · Art. 17-19Incident management & reportingAutomated detection with severity classification and the initial / intermediate / final reporting cadence
    Pillar 3 · Art. 24-26Resilience testingStructured audit logs and captured scenarios as inputs to vulnerability assessments and TLPT of the AI attack surface
    Pillar 4 · Art. 28-29Third-party ICT riskPer-provider risk scoring, jurisdiction tracking and the technical dependency layer of the Art. 5(9) register
    Pillar 5 · Art. 45Information sharingMITRE ATT&CK-enriched threat data and aggregated incident reporting for voluntary intelligence sharing

    The report is an auditor-facing evidence pack (control, requirement, metrics and reasoning), not a binary compliance verdict. Auditors map Nyx severity onto the DORA RTS classification criteria and reconcile the dependency inventory against the contractual register.

    Get a readiness demo

    The information on this page is for informational purposes and does not constitute legal advice. For an assessment specific to your organization, consult a qualified professional. Nyx reports are evidence packs, control, requirement, metrics and reasoning, not a compliance verdict.