DORA
Regulation (EU) 2022/2554
The requirement. The financial sector must prove its ICT resilience and control the risk of its providers — including their disappearance.
The AWA answer. For your files:
- Exit risk, addressed head on: source-code escrow with the Sovereign Guarantee (coming soon), as soon as our escrow service opens (everything fits in one dependency-free repository); versions received that stay usable with no time limit and a licence that follows the application if it is sold; open formats, self-hosting. Your rights outlive your supplier.
Compliance evidence pack — executive summary
DORA-01 partial Art. 28–30 — register of information; subcontracting chain
The technical sub-supplier chain is fully enumerable from the repository and pinned by digest — there is no opaque transitive tier to attest to.
the technical chain is proven; there is no contractual register, no entity-level attestation and no Art. 30 clause set. Those are business-side artifacts, outside this repository's perimeter.
DORA-02 proven Art. 28(8) — exit strategies and substitutability
Technical exit is unobstructed: source-available architecture, no bundler lock-in, self-hosting, and output in open standard formats (PDF/A-3, OOXML, ODF, UN/CEFACT CII, Markdown) rather than a proprietary container.
Proven for technical substitutability only. Contractual exit terms are out of repo scope and not claimed here.
DORA-03 partial Art. 24–27 — digital operational resilience testing
A large, executable verification corpus exists: 1 325 tracked test files repo-wide (967 in shipped front package sources), plus a NIST ACVP conformance harness running 46 056 committed test cases across 59 algorithm vector folders.
this is correctness testing at scale, not resilience testing. There is no chaos/failover programme, no performance-under-stress evidence and no threat-led penetration testing (TLPT, Art. 26).
DORA-04 proven Art. 17–23 — ICT-incident management and reporting
An incident and vulnerability notification channel is published in this repository: SECURITY.md names the address and the process by which a financial buyer is informed of vulnerabilities in the component.
Former absence claim, closed by the same artifact as cra.md CRA-03 and nis2.md NIS2-02. It is a published channel, not a contractual incident-notification commitment: the notification terms a financial entity needs under Art. 30 are business-side contract terms (see DORA-01).
DORA-05 gap Art. 9(4)(d), Art. 12 — logging and audit trail of ICT operations
The serving pair keeps no access log and records no client identifier.
the serving pair keeps no access log and records no client identifier. Two-sided fact, recorded once: this is a DORA/NIS2 audit-trail gap and the GDPR-03 data-minimisation proof (see gdpr.md GDPR-03). Closing one weakens the other; the resolution is an opt-in, default-off, documented logging mode — tracked as BL-816 ("Opt-in access-logging mode for services/site-host + services/edge (DORA audit trail vs GDPR minimisation)"), no owning plan today. BL-1861 (2026-10-01) adds the host-side measurement — firewall, journald, any proxy — that this code-level row does not cover.
| Pack generated | Evidence verified |
|---|---|
| 2026-10-01 | 2026-10-01 |
AwaCloud status
Watch · status as of 2026-09-15.