NMQ Protocol

GRC gap assessment

Multilingual checklist (EN, DE, FR, ES, IT, NL). Seed templates via the gap API; track status and evidence links per control.

Loading gap checklist…

DORA gap pack (financial)

Optional add-on for credit institutions, payment firms, and ICT third-party risk. Seed these templates on order — not included in default International Core assessment.

  • dora-ict-risk

    ICT risk management framework

    Art. 6Documented ICT risk policy covering critical functions, threat landscape, and board reporting for in-scope entities.

  • dora-incident-reporting

    Major ICT incident reporting

    Art. 19Runbooks for classification, initial notification, intermediate reports, and final report to competent authority.

  • dora-resilience-testing

    Digital operational resilience testing

    Art. 24Threat-led penetration testing or equivalent programme for critical ICT systems supporting the knowledge base.

  • dora-third-party

    ICT third-party risk register

    Art. 28Contractual clauses, exit strategies, and concentration risk for cloud, LLM, and critical ICT providers.

  • dora-information-sharing

    Cyber threat information sharing

    Art. 45Participation policy for trusted financial-sector ISACs; redaction rules before ingest into closed-loop KB.