All frameworks
    Reg. (EU) 2022/2554Evidence pack

    DORA

    DORA has applied to EU financial entities since 17 January 2025. When you put AI into operational processes — credit scoring, fraud detection, KYC, customer service — the model providers behind it (OpenAI, Anthropic, Google) become ICT third-party service providers in scope. Nyx is the single control point that makes that AI surface auditable, and generates a DORA evidence pack on demand.

    ReferenceRequirementNyx capability
    Pillar 1 · Art. 5–6ICT risk management frameworkCentralized register of AI ICT assets with continuous risk scoring and policy enforcement, feeding the management body's framework
    Pillar 1 · Art. 9Protection & preventionOn-device PII redaction and k-anonymity before data leaves the endpoint; Ed25519-signed policy, TLS + AES-256
    Pillar 2 · Art. 17–19Incident management & reportingAutomated detection with severity classification and the initial / intermediate / final reporting cadence
    Pillar 3 · Art. 24–26Resilience testingStructured audit logs and captured scenarios as inputs to vulnerability assessments and TLPT of the AI attack surface
    Pillar 4 · Art. 28–29Third-party ICT riskPer-provider risk scoring, jurisdiction tracking and the technical dependency layer of the Art. 5(9) register
    Pillar 5 · Art. 45Information sharingMITRE ATT&CK-enriched threat data and aggregated incident reporting for voluntary intelligence sharing

    The report is an auditor-facing evidence pack — control, requirement, metrics and reasoning — not a binary compliance verdict. Auditors map Nyx severity onto the DORA RTS classification criteria and reconcile the dependency inventory against the contractual register.

    Get a readiness demo

    The information on this page is for informational purposes and does not constitute legal advice. For an assessment specific to your organization, consult a qualified professional. Nyx reports are evidence packs — control, requirement, metrics and reasoning — not a compliance verdict.