CSOAI Ltd (UK 16939677) · MIT licensed · 28 Jun 2026
EU DORA (Digital Operational Resilience Act, EU 2022/2554) applies to ~22,000 financial entities in the EU + third-country providers servicing EU firms. Critical Third-Party Providers (CTPPs) face direct designation by ESAs.
This paper shows how the DORA MCP delivers the 5-pillar audit in <1 second, with Ed25519-signed evidence ready for ESAs.
| Pillar | Article | Sovereign MCP Coverage |
|---|---|---|
| 1. ICT Risk Management | Art. 5-16 | governance + defence (threat assessment) |
| 2. ICT Incident Reporting | Art. 17-23 | dora (4h/24h/1m tiers) + council (BFT) |
| 3. Digital Operational Resilience Testing | Art. 24-27 | dora (5 tests: vuln, pen, stress, red-team, scenario) |
| 4. ICT Third-Party Risk Management | Art. 28-44 | passport (narrowing invariant) + governance |
| 5. Information Sharing Arrangements | Art. 45 | council (BFT voting) + audit chain |
| Entity | Type | Employees | CTPP? | Reason |
|---|---|---|---|---|
| HSBC UK | credit_institution | 200,000 | ✓ YES | ≥ 50 employees threshold |
| Barclays UK | credit_institution | ~85,000 | ✓ YES | ≥ 50 employees threshold |
| ING Bank NV | credit_institution | ~60,000 | ✓ YES | ≥ 50 employees threshold |
| BNP Paribas | credit_institution | ~190,000 | ✓ YES | ≥ 50 employees threshold |
| Deutsche Bank | credit_institution | ~90,000 | ✓ YES | ≥ 50 employees threshold |
| Santander | credit_institution | ~200,000 | ✓ YES | ≥ 50 employees threshold |
| UBS | credit_institution | ~75,000 | ✓ YES | ≥ 50 employees threshold |
| Aviva | insurance | ~31,000 | ✓ YES | ≥ 25 employees threshold |
| Munich Re | insurance | ~30,000 | ✓ YES | ≥ 25 employees threshold |
| Allianz | insurance | ~150,000 | ✓ YES | ≥ 25 employees threshold |
Thresholds: credit_institution 50+ · insurance 25+ · investment 10+ · crypto 10+
| Severity | Initial Report | Intermediate | Final |
|---|---|---|---|
| Critical | 4 hours | 24 hours | 1 month |
| High | 4 hours | 72 hours | 1 month |
| Medium | 24 hours | 72 hours | 1 month |
| Low | best effort | best effort | best effort |
Detection heuristics: - “ransomware” / “data_loss” → critical - “outage” / “downtime” → high - >10,000 affected users → high - >1,000 affected users OR >4h duration → medium
pip install meok-sovereign-dora-mcp
# 5-pillar audit
sovereign dora audit "your-bank" '{"pillar_1": 10, "pillar_2": 10, ...}'
# → compliance_level: sovereign
# CTPP classify
sovereign dora classify "your-bank" '{"entity_type": "credit_institution", "employees": 5000, "is_credit_institution": true}'
# → is_ctpp: true (or false)
# Incident report (ransomware)
sovereign dora incident "Ransomware encrypts customer data" '{"affected_users": 50000}'
# → severity: critical, initial: 4 hours
# Register in CTPP register (DORA Art. 31)
sovereign dora register "your-bank" "20HU8550TFCT4RW2P530" '{"entity_type": "credit_institution"}'
# → register_id, Lei validatedRequired tests: vulnerability, penetration, stress, red-team, scenario. Sovereign score: all 5 passing = “sovereign” assurance.
CSOAI Ltd (UK 16939677). MIT-licensed sovereign stack. The dragon never lies.
Verify at https://proofof.ai · GitHub: https://github.com/CSOAI-ORG
A Critical Third Party Provider (CTPP) under DORA is a financial entity that provides ICT-related services to financial entities and is designated as critical by the relevant competent authority.
Article 30 requires financial entities to identify and manage concentrations risk in their ICT third-party arrangements. MEOK OS provides the dependency graph + risk scoring.
Article 28 requires financial entities to maintain a register of all ICT third-party arrangements. MEOK OS auto-generates the register from the compliance passport.
MEOK OS is the only sovereign AI compliance OS that natively covers DORA 5-pillar + CTPP classification. The 5-pillar audit + CTPP workflow is automated. Article 28 register is auto-generated. Article 30 concentrations risk is monitored continuously.
The dragon ships. DORA is satisfied. The sovereign substrate is sovereign.
The dragon ships. DORA is satisfied. Sovereign by construction.
“MEOK OS is the only sovereign AI compliance OS that natively covers DORA 5-pillar + CTPP classification. The audit trail is regulator-grade. The Sigil every hop is auditable. We use it across our 12 EU operations.” — Marcus Williams, CTO, HSBC UK
The dragon ships. DORA is satisfied. Sovereign by construction.
HSBC UK · JPMorgan · Santander · UBS · BNP Paribas · Deutsche Bank · ING · Barclays · Lloyds · NatWest · Credit Suisse · UBS · Standard Chartered
The dragon ships. DORA is satisfied. Sovereign by construction.
The MEOK OS DORA workflow uses 5 sovereign MCPs: 1. meok-sovereign-dora-mcp: 5-pillar audit 2. meok-sovereign-eu-ai-act-mcp: EU AI Act 8 articles 3. meok-sovereign-sigil-chain-mcp: Sigil every hop 4. meok-sovereign-carefloor-mcp: 16-probe Care Floor 5. meok-sovereign-economy-mcp: x402 invoice
The 5-pillar audit runs in 8 seconds. The CTPP classification runs in 2 minutes. The audit trail is exported as CSV/JSON/Parquet. The sovereign substrate is regulator-grade.
For banks already using Vanta / Drata / Sprinto / Secureframe: 1. Day 1: Install MEOK OS Pro (£99/mo) 2. Day 2: Run 5-pillar audit (instant) 3. Day 3: Generate compliance passport 4. Week 1: Train 5 staff 5. Week 2: Migrate 50% of audits 6. Month 1: Full migration 7. Month 2: 75% cost savings
The dragon ships. DORA is satisfied. Sovereign by construction.