NMQ Protocol
GRC gap assessment
Multilingual checklist (EN, DE, FR, ES, IT, NL). Seed templates via the gap API; track status and evidence links per control.
Loading gap checklist…
DORA gap pack (financial)
Optional add-on for credit institutions, payment firms, and ICT third-party risk. Seed these templates on order — not included in default International Core assessment.
dora-ict-risk
ICT risk management framework
Art. 6 — Documented ICT risk policy covering critical functions, threat landscape, and board reporting for in-scope entities.
dora-incident-reporting
Major ICT incident reporting
Art. 19 — Runbooks for classification, initial notification, intermediate reports, and final report to competent authority.
dora-resilience-testing
Digital operational resilience testing
Art. 24 — Threat-led penetration testing or equivalent programme for critical ICT systems supporting the knowledge base.
dora-third-party
ICT third-party risk register
Art. 28 — Contractual clauses, exit strategies, and concentration risk for cloud, LLM, and critical ICT providers.
dora-information-sharing
Cyber threat information sharing
Art. 45 — Participation policy for trusted financial-sector ISACs; redaction rules before ingest into closed-loop KB.
