Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

OSCAL-DORA-EN

DORA (Reg 2022/2255) and level 2 acts in OSCAL

Architecture and Public Interfaces

  • Maintain a reviewed source manifest covering:

    • Regulation 2022/2554 and Directive 2022/2556.
    • Level 2 acts 2024/1772, 2024/1773, 2024/1774 plus corrigenda, 2024/2956, 2025/295, 2025/301, 2025/302, 2025/420, 2025/532, 2025/1190, 2024/1502, and 2024/1505.
    • Level 3 guidelines, Q&As, opinions, and dynamic provider designations, clearly separated from binding requirements.
    • CELEX/ELI URI, legal effect, language, publication/effective dates, status, source checksum, and supersession relationships.
  • Produce one immutable OSCAL Catalog per independently versioned instrument. Organize it by chapter, section, and article, with one control per independently applicable/testable obligation. Use stable IDs such as dora-2022-2554-art-005-par-002-pt-a; preserve exact legal text and source anchors. Put derived guidance and assessment objectives in separate profiles so they cannot be mistaken for legislation.

  • Keep a complete coverage ledger classifying every provision as an obligation, permission, condition, exemption, definition, recital, authority duty, amendment, or informative material. Every source unit must have exactly one disposition and reviewer decision.

  • Publish a versioned extension vocabulary for properties including legal-effect, actor, instrument-id, article, applicability-rule-id, effective-from, proportionality, deadline, entity-type, group-level, competent-authority, and external artifact identifiers. Assign the final namespace from the repository’s permanent HTTPS identity before the first release and never change it.

  • Provide a typed applicability-context schema accepting actor/entity type, Article 2 exclusions, Member State and authority, microenterprise status, Article 16 eligibility, group level, payment-service status, TLPT designation, critical-provider designation, Article 45 participation, and critical-or-important functions. The generator emits:

    • A resolved OSCAL Profile.
    • An applicability decision ledger with rationale and provenance.
    • An unresolved-decision report that blocks finalization.
  • Ship profiles for all financial-entity types, full and simplified frameworks, microenterprise deltas, payment incidents, TLPT, entity/sub-consolidated/consolidated levels, ICT providers, critical ICT providers, competent authorities, Lead Overseers, and joint examination teams. Proportionality may tailor implementation depth but must not remove obligations unless the law provides an explicit exemption.

  • Create an identifier-only ISO locator catalog for ISO/IEC 27001:2022+A1:2024. It will contain clause and Annex A identifiers but no ISO titles, control measures, guidance, or other standard content. Required OSCAL statement fields will contain only neutral “licensed text intentionally omitted” wording.

About

DORA (Reg 2022/2255) and level 2 acts in OSCAL

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors