rotascale

Solutions — instrument

Your ICT third-party register now has agents in it.

Regulation (EU) 2022/2554, in force since January 2025. An operational resilience regulation rather than an AI one, which is why it reaches agents at all: an agent's tools are ICT third parties, its failures are ICT incidents, and both were written down for humans. RotaGrant touches two of the five pillars directly, and those two are where agents put pressure on a register and a clock that already exist.

Regulation (EU) 2022/2554 ESAs · national competent authorities not mapped
Status
Applies from 2025-01-17
Applies to
EU financial entities and their critical ICT providers

Where it contributes

ICT third-party risk
An agent's dependency surface is a third-party surface. MCP servers and their tool manifests are inventoried, watched for change, and a description that changes under an agent's feet is recorded as drift rather than absorbed.
Incident reporting
The classification and clock machinery is instrument-agnostic. DORA's thresholds and templates differ from Article 73's and are not encoded — but the record an incident report is assembled from is the same record.

Two pillars of five. Business continuity, the ICT risk management framework itself, and threat-led penetration testing are the bulk of DORA and sit outside what an agent governance layer can speak to.

What a clause map would cover

Articles 17–20 on incident management, classification and reporting, against the same classification machinery that already serves Article 73; and Articles 28–30 on ICT third-party risk, where the register of information is an inventory obligation and the agent inventory, model inventory and configuration provenance are the evidence. Article 25's testing requirement is a partial — the adversarial grid is a real test of one component, and it is not threat-led penetration testing under TIBER-EU.

Partial coverage is not an obstacle to writing one. A clause carries a provenance of platform, hybrid or customer, and only the first two are scored, so the three pillars outside this platform would be recorded as yours and excluded from the reading — exactly as the AI Act map covers the articles a platform can evidence rather than the whole Act.

Today the EU profile selects eu-ai-act and gdpr, so a DORA reading is assembled from the evidence rather than scored against clauses. Clause maps are YAML validated against the evidence registry at load, which means yours, your counsel's or ours — and none of those needs a release.

RotaGrant ships no clause map for DORA. The engine takes clause maps as data, so one can be authored — by you, by your counsel, or with us — and it will be scored like any other. What this page will not do is imply a mapping that does not exist, because a readiness percentage against an instrument nobody encoded is a number with no denominator.