Aller au contenu

DORA

Règlement (UE) 2022/2554

L'exigence. Le secteur financier doit prouver sa résilience TIC et maîtriser le risque de ses prestataires — y compris leur disparition.

La réponse AWA. Pour vos dossiers :

  1. Le risque de sortie, traité frontalement : séquestre du code source avec la Garantie souveraine (à venir), dès l'ouverture de notre service de séquestre (tout tient dans un dépôt sans dépendance) ; versions reçues utilisables sans limite de durée et licence qui suit l'application si elle est cédée ; formats ouverts, auto-hébergement. Vos droits survivent à votre fournisseur.

Dossier de preuves relatives à la conformité — synthèse exécutive

2 proven
2 partial
1 gap

DORA-01 partial Art. 28–30 — register of information; subcontracting chain

The technical sub-supplier chain is fully enumerable from the repository and pinned by digest — there is no opaque transitive tier to attest to.

the technical chain is proven; there is no contractual register, no entity-level attestation and no Art. 30 clause set. Those are business-side artifacts, outside this repository's perimeter.

snapshot 2026-10-01

DORA-02 proven Art. 28(8) — exit strategies and substitutability

Technical exit is unobstructed: source-available architecture, no bundler lock-in, self-hosting, and output in open standard formats (PDF/A-3, OOXML, ODF, UN/CEFACT CII, Markdown) rather than a proprietary container.

Proven for technical substitutability only. Contractual exit terms are out of repo scope and not claimed here.

snapshot 2026-10-01

DORA-03 partial Art. 24–27 — digital operational resilience testing

A large, executable verification corpus exists: 1 325 tracked test files repo-wide (967 in shipped front package sources), plus a NIST ACVP conformance harness running 46 056 committed test cases across 59 algorithm vector folders.

this is correctness testing at scale, not resilience testing. There is no chaos/failover programme, no performance-under-stress evidence and no threat-led penetration testing (TLPT, Art. 26).

snapshot 2026-10-01

DORA-04 proven Art. 17–23 — ICT-incident management and reporting

An incident and vulnerability notification channel is published in this repository: SECURITY.md names the address and the process by which a financial buyer is informed of vulnerabilities in the component.

Former absence claim, closed by the same artifact as cra.md CRA-03 and nis2.md NIS2-02. It is a published channel, not a contractual incident-notification commitment: the notification terms a financial entity needs under Art. 30 are business-side contract terms (see DORA-01).

snapshot 2026-10-01 · ai/plans/2026-08-19-publication-event.md (W1) — BL-810 (delivered)

DORA-05 gap Art. 9(4)(d), Art. 12 — logging and audit trail of ICT operations

The serving pair keeps no access log and records no client identifier.

the serving pair keeps no access log and records no client identifier. Two-sided fact, recorded once: this is a DORA/NIS2 audit-trail gap and the GDPR-03 data-minimisation proof (see gdpr.md GDPR-03). Closing one weakens the other; the resolution is an opt-in, default-off, documented logging mode — tracked as BL-816 ("Opt-in access-logging mode for services/site-host + services/edge (DORA audit trail vs GDPR minimisation)"), no owning plan today. BL-1861 (2026-10-01) adds the host-side measurement — firewall, journald, any proxy — that this code-level row does not cover.

snapshot 2026-10-01

Dossier généré le 2026-10-01 · preuves vérifiées le 2026-10-01

Statut AwaCloud

Veille · statut au 15/09/2026.