Eleven deterministic, browser-based tools covering the full DORA framework — from ICT risk maturity scoring and CIF classification through incident classification with live reporting countdowns, third-party contract validation, concentration risk modelling, proportionality assessment, NCA submission calendars, NIS2/DORA overlap mapping, and the AP2 agentic policy mandate builder. EU 2022/2554. Zero PII.
Five stages cover the full DORA compliance lifecycle — from gap analysis and ICT function classification through incident response, third-party governance, and agentic policy mandate export.
Follow the 5-stage workflow above to navigate by use case, or scroll to any tool group directly. All tools run in your browser — no account, no data transmission.
Open T300 to score all five DORA pillars. The remediation priority table becomes your implementation backlog. Then use T302 to classify your ICT functions into CIF tiers and flag TLPT scope.
Add each ICT provider, assign CIF tier, and run the 24 ESA data quality checks. Then use T308 to identify your NCA's submission deadline and required format.
Input all 7 RTS 2024/1772 criteria in T303. The compound Major logic (Condition A + B1/B2) determines classification. Use T304 to design your proportionate resilience testing programme.
Use T305 to check ICT service agreements against Art. 30 mandatory clauses. Run T306 to model your provider portfolio HHI index and detect SPOF and CTPP exposure. Use T307–T309 for proportionality, NCA deadlines, and NIS2/DORA overlap.
Use T310 to configure all five DORA pillars into a validated Policy Mandate JSON. The built-in validator flags RTO violations and runbook gaps. Export the mandate for board reporting or agentic pipeline consumption.
Five-pillar DORA maturity assessment scored 0–4 per pillar. Composite score /100, pillar heatmap, remediation priority table. Policy Mandate JSON and Markdown export. Client-side. Zero PII.
Open ToolT1/T2/T3 three-tier critical ICT function classification engine. RTO assessment against 72h Art. 11 requirement. TLPT scope flagging, Policy Mandate JSON and Markdown export. Client-side. Zero PII.
Open ToolDynamic provider entry with 24 ESA data quality checks. CIF T1/T2/T3 classification, xBRL-CSV export structure, Policy Mandate JSON. Client-side. Zero PII.
Open ToolAll 7 RTS 2024/1772 criteria. Compound Major logic: Condition A + B1/B2. Live 4h/72h/1-month countdown. ITS 2025/302 Annex I notification draft auto-populated. Policy Mandate JSON. Client-side. Zero PII.
Open ToolBasic Art. 25 testing (all entities) vs TLPT Art. 26 (significant entities ≥€30bn, TIBER-EU aligned). Test type schedule by article, frequency, TLPT scope, Policy Mandate JSON. Client-side. Zero PII.
Open Tool10 Art. 30 mandatory clause checklist. Compliance % score, missing clause list, model clause language stubs for renegotiation, Policy Mandate JSON. Client-side. Zero PII.
Open ToolProvider portfolio risk across HHI index, SPOF flags (dependency ≥40% + substitutability ≤2), 19 designated CTPP detection, diversification recommendations, Policy Mandate JSON risk register. Client-side. Zero PII.
Open ToolArt. 4 proportionality principle determination. Full vs Art. 16 simplified ICT risk management framework. Obligation applicability table for all DORA pillars, Markdown assessment. Client-side. Zero PII.
Open ToolAll 27 EU member state NCA deadlines and xBRL format requirements. Penalty exposure indicators, earliest deadline summary, Markdown compliance calendar export. Client-side. Zero PII.
Open Tool14-control dual-compliance matrix: SHARED / DORA-ONLY / NIS2-ONLY / AI-OVERLAP. Deduplication count, AI Act overlap flag for entities using AI in ICT functions, Policy Mandate JSON. Client-side. Zero PII.
Open ToolAnchor agentic tool. Configure ICT risk appetite, incident escalation triggers, TLPT schedule, RoI update frequency, and NCA calendar across all 5 DORA pillars. Outputs validated Policy Mandate JSON, board policy summary, and machine-readable agent instruction set. Client-side. Zero PII.
Last reviewed: May 2026 · 11 tools · Cat-22 · DORA & Operational Resilience
Use T300 to score ICT risk maturity against all five DORA pillars and generate a remediation roadmap. Use T303 for live incident classification against all 7 RTS criteria. Use T307 to confirm whether the simplified framework applies.
Use T302 to classify all ICT functions into CIF tiers. Use T301 to build and validate your Register of Information against 24 ESA data quality checks. Use T304 to design your proportionate resilience testing programme including TLPT scope.
Use T305 to check every ICT service agreement against the 10 Art. 30 mandatory clauses and generate model language stubs for renegotiation. Use T306 to model your provider portfolio HHI index and detect SPOF and CTPP exposure.
Use T308 to map DORA Register of Information submission deadlines across all 27 EU member state NCAs with xBRL format requirements. Use T309 to identify DORA/NIS2 overlap and deduplication opportunities for entities subject to both regimes.
Use T310 to compile a Policy Mandate JSON your autonomous compliance agent can consume via the AINumbers.co MCP server. The mandate covers all five DORA operational dimensions with built-in validation thresholds — deployable directly into your agent runtime.
T300 produces a radar heatmap and remediation priority table suitable for board reporting. T310 outputs a board-level policy summary covering all five pillars. T308 gives your upcoming NCA submission deadlines across all active jurisdictions.
Start with T300 — DORA ICT Risk Gap Analyser to score all five pillars. The remediation priority table becomes your implementation backlog. Then use T302 to classify your ICT functions into CIF tiers and flag TLPT scope before your Register of Information submission.
Open T301 — DORA RoI Structure Builder. Add each ICT provider, assign CIF tier, and run the 24 ESA data quality checks. Then use T308 to identify your NCA's submission deadline and required format (xBRL-CSV vs Excel).
Open T303 — DORA Incident Classification Engine. Input all 7 RTS 2024/1772 criteria. The compound Major logic (Condition A + B1/B2) determines classification. If Major: the live 4-hour countdown starts immediately and the ITS 2025/302 Annex I notification draft auto-populates.
Use T310 — AP2 DORA Policy Mandate Builder to configure all five DORA pillars. The built-in validator flags RTO violations and runbook gaps. Export the Policy Mandate JSON and reference the agent_instructions array as your agent's ordered DORA rulebook.
All 11 tools expose structured outputs compatible with the AINumbers MCP manifest. Use the tool IDs below with any MCP-capable agent.
| Tool ID | MCP Name | Input Schema | Output |
|---|---|---|---|
| T300 | analyse_dora_ict_risk | pillars[], maturity_scores{}, entity_type | composite_score, heatmap{}, remediation_priority[] |
| T301 | build_dora_roi | providers[], cif_tier, contract_type | roi_structure{}, quality_checks[], xbrl_export |
| T302 | classify_dora_cif | function_name, rto_hours, substitutability | cif_tier, tlpt_scope, rto_assessment, mandate_json |
| T303 | classify_dora_ict_incident | criteria{7 RTS fields}, incident_time | classification, major_flag, countdown_4h, notification_draft |
| T304 | design_dora_testing_programme | entity_size, assets_bn, cif_scope[] | test_schedule{}, tlpt_required, tiber_eu_flag, mandate_json |
| T305 | check_dora_contract_clauses | contract_clauses[], provider_type | compliance_pct, missing_clauses[], model_language{} |
| T306 | model_dora_concentration_risk | providers[], dependency_pct[], substitutability[] | hhi_index, spof_flags[], ctpp_detected[], diversification[] |
| T307 | assess_dora_proportionality | entity_type, total_assets, interconnectedness | framework_type, art16_applicable, obligation_table{} |
| T308 | track_dora_nca_deadlines | member_states[], submission_year | deadlines[], format_requirements[], penalty_indicators[] |
| T309 | map_nis2_dora_overlap | entity_scope[], ai_use_flag | overlap_matrix{}, dedup_count, ai_act_flag, mandate_json |
| T310 | build_dora_ap2_mandate | all 5 pillars config{}, nca_calendar[], rto_thresholds{} | mandate_json{}, board_summary, agent_instructions[] |