⚖️ Regulatory Compliance

Two mandates. One platform. One evidence trail.

If you're supervised under DORA and assessed under PCI DSS, you're being asked to prove the same testing twice. breachr runs one programme and hands you both evidence packs.

DORA — Digital Operational Resilience ActMandatory since Jan 2025
Article 25
ICT risk management
Continuous vulnerability scanning mapped to your ICT asset register. Risk scoring aligned to EBA guidelines.
Article 26
TLPT mandate
CREST-certified Threat-Led Penetration Testing built to TIBER-EU framework. Cryptographic proof of test included.
Article 30
Third-party ICT
breachr registers as a DORA ICT third-party provider. Audit rights, SLA, incident notification, and exit strategy included.
Deliverables: DORA compliance evidence package · Signed audit trail · Regulator-ready PDF

DORA Article-by-Article Coverage

Article 24

General ICT Testing

Continuous vulnerability scanning mapped to your ICT asset register — continuous coverage vs. point-in-time sampling. Automated cadence supports the annual testing requirement.

✅ Fully covered
Article 25

Advanced Testing

LLM exploit chaining combines vulnerabilities into real attack paths. Threat intelligence from MITRE ATT&CK and FS-ISAC. CREST-certified human validation for all critical/high findings.

✅ Fully covered
Article 26

TLPT — Significant Entities

Full TIBER-EU framework. Independent CREST red team, threat intelligence provider, purple team exercises, BaFin notification support, management board reporting templates.

✅ Enterprise tier

Deploy Your Way

Same platform, same evidence engine — your data never has to leave your control:

  • EU sovereign cloud — Frankfurt, eu-central-1
  • Your own cloud account — AWS, Azure, or GCP
  • Fully air-gapped on-premise
  • In-CDE testing — cardholder data stays inside your environment
  • Data residency, audit rights and exit strategy documented in the DPA

What Your Auditor Asks — And What breachr Hands You

The questionWhat you hand over
“Show me your methodology”Signed, documented red-team methodology
“Prove segmentation holds”In-CDE Req. 11.4.5/11.4.6 evidence
“Who found this, and how?”Cryptographic chain of custody per finding
“Where does our data go?”Sovereign deployment — nothing leaves your environment
“Is the AI auditable?”Model, version, confidence + SHA-256 on every finding

Why Compliance Deadlines Matter Now

💳
PCI DSS
v4.0.1 in effect
⚠️ Assessments are annual and non-movable — Req 11.4
Up to $100K/month + card brand fines
🇪🇺
DORA
In force since 17 Jan 2025
⚠️ TLPT cycles begin on NCA designation
Up to €10M or 2% global revenue
🇪🇺
NIS2
Transposed into national law
⚠️ Enforcement runs through national NCAs
Up to €10M or 2% global revenue

Meet Every Regulatory Deadline

PCI DSS pen tests are annual and the date doesn't move. DORA has been in force since January 2025. Start building your compliance evidence trail today.