Two mandates. One platform. One evidence trail.
If you're supervised under DORA and assessed under PCI DSS, you're being asked to prove the same testing twice. breachr runs one programme and hands you both evidence packs.
DORA Article-by-Article Coverage
General ICT Testing
Continuous vulnerability scanning mapped to your ICT asset register — continuous coverage vs. point-in-time sampling. Automated cadence supports the annual testing requirement.
✅ Fully coveredAdvanced Testing
LLM exploit chaining combines vulnerabilities into real attack paths. Threat intelligence from MITRE ATT&CK and FS-ISAC. CREST-certified human validation for all critical/high findings.
✅ Fully coveredTLPT — Significant Entities
Full TIBER-EU framework. Independent CREST red team, threat intelligence provider, purple team exercises, BaFin notification support, management board reporting templates.
✅ Enterprise tierDeploy Your Way
Same platform, same evidence engine — your data never has to leave your control:
- ✅ EU sovereign cloud — Frankfurt, eu-central-1
- ✅ Your own cloud account — AWS, Azure, or GCP
- ✅ Fully air-gapped on-premise
- ✅ In-CDE testing — cardholder data stays inside your environment
- ✅ Data residency, audit rights and exit strategy documented in the DPA
What Your Auditor Asks — And What breachr Hands You
| The question | What you hand over |
|---|---|
| “Show me your methodology” | Signed, documented red-team methodology |
| “Prove segmentation holds” | In-CDE Req. 11.4.5/11.4.6 evidence |
| “Who found this, and how?” | Cryptographic chain of custody per finding |
| “Where does our data go?” | Sovereign deployment — nothing leaves your environment |
| “Is the AI auditable?” | Model, version, confidence + SHA-256 on every finding |
Why Compliance Deadlines Matter Now
Meet Every Regulatory Deadline
PCI DSS pen tests are annual and the date doesn't move. DORA has been in force since January 2025. Start building your compliance evidence trail today.