⚖️ Regulatory Compliance

Two mandates. One platform. One evidence trail.

If you're supervised under DORA and assessed under PCI DSS, you're being asked to prove the same testing twice. breachr runs one programme and hands you both evidence packs.

DORA - Digital Operational Resilience ActMandatory since Jan 2025
Article 25
ICT risk management
Continuous vulnerability scanning mapped to your ICT asset register. Risk scoring aligned to EBA guidelines.
Article 26
TLPT mandate
Article 26 TLPT requires an independent accredited provider and threat-intelligence-led scoping. breachr is designed to align with TIBER-EU; we scope these engagements with you directly.
Article 30
Third-party ICT
breachr registers as a DORA ICT third-party provider. Audit rights, SLA, incident notification, and exit strategy included.
Deliverables: DORA compliance evidence package · Signed audit trail · Regulator-ready PDF

DORA Article-by-Article Coverage

Article 24

General ICT Testing

Continuous vulnerability scanning mapped to your ICT asset register - continuous coverage vs. point-in-time sampling. Automated cadence supports the annual testing requirement.

✅ Fully covered
Article 25

Advanced Testing

LLM exploit chaining combines vulnerabilities into real attack paths. Threat intelligence from MITRE ATT&CK and FS-ISAC. Every critical and high finding is confirmed by a named security professional.

✅ Fully covered
Article 26

TLPT - Significant Entities

TLPT under Article 26 requires an independent accredited testing provider and threat-intelligence-led scoping. breachr is designed to align with TIBER-EU, and we scope Article 26 engagements with you directly.

Talk to us

Where Your Data Lives

Residency is a compliance property, not a deployment preference - so we are explicit about it:

  • ✅ Stored and processed in the EU - Frankfurt, eu-central-1
  • ✅ We do not sell your data, and it is never used to train models for other customers
  • ✅ Credentials encrypted per tenant, and deleted after the scan
  • ✅ Every access recorded on an append-only audit trail
  • ✅ Some AI analysis uses a model provider hosted outside the EU - minimised to what a finding needs, and never retained for training
  • ✅ Data residency, audit rights and exit strategy documented in the DPA

What Your Auditor Asks - And What breachr Hands You

The questionWhat you hand over
“Show me your methodology”Signed, documented red-team methodology
“Prove segmentation holds”In-CDE Req. 11.4.5/11.4.6 evidence
“Who found this, and how?”Cryptographic chain of custody per finding
“Where does our data go?”Stored and processed in the EU (Frankfurt, eu-central-1). Some AI analysis uses a provider outside the EU, minimised and never used to train models for other customers.
“Is the AI auditable?”Model, version, confidence + SHA-256 on every finding

Why Compliance Deadlines Matter Now

💳
PCI DSS
v4.0.1 in effect
⚠️ Assessments are annual and non-movable - Req 11.4
Up to $100K/month + card brand fines
🇪🇺
DORA
In force since 17 Jan 2025
⚠️ TLPT cycles begin on NCA designation
Up to €10M or 2% global revenue
🇪🇺
NIS2
Transposed into national law
⚠️ Enforcement runs through national NCAs
Up to €10M or 2% global revenue

Meet Every Regulatory Deadline

PCI DSS pen tests are annual and the date doesn't move. DORA has been in force since January 2025. Start building your compliance evidence trail today.