Skip to content
Now taking design partners.Roadmap →

NIS2, DORA, CRA

Compliance evidence · EU

AI-agent, MCP, and software inventory, exposure, and incident-response evidence for EU essential and important entities, financial services, and digital-product manufacturers.

Request evidence packMapping updated

What we mean by "produces evidence"

Sekeye does not grant NIS2 or DORA compliance. It produces the inventory, exposure, and incident-response timeline evidence these regimes require you to demonstrate, for the AI agents and MCP servers running across your hosts, and for the package and extension layer underneath them, with EU-resident hosting or fully self-hosted inside your VPC.

This is a supporting angle, not the reason to deploy. The reason to deploy is that AI agents run on your laptops and servers with credentials, shell, and network egress, and nothing else in the stack governs them. The evidence trail is a by-product of doing that well.

NIS2 (essential and important entities)

  • Article 21 supply-chain security. Inventory of the AI agents, MCP servers, skills, and local models running across laptops and servers, plus the classic package and extension layer, feeds supplier and third-party controls evidence.
  • 24-hour early warning, 72-hour incident notification. Campaign scope identifies affected hosts and the exposure window per host, including which agents held which credentials at the time.
  • Executive accountability. Board-level attestation is easier when the posture evidence is a report, not a spreadsheet, and when the report can answer "which agents can reach production" directly.

DORA (financial-services entities)

  • ICT third-party risk. MCP servers and agent integrations are third-party ICT dependencies that rarely appear in a vendor register. Inventorying them alongside software artefacts gives the auditable evidence base.
  • ICT-related incidents. Campaign findings tie affected hosts to the incident timeline required for reporting, with per-agent blast radius as the scope statement.
  • Threat-led penetration testing (TLPT) preparation. Inventory context for scoping, which agents, MCP servers, and components exist across the fleet.

CRA (product manufacturers)

  • Vulnerability handling and SBOM obligations. The SBOM you export for compliance can be produced from the same inventory you use for operational security, covering AI-infrastructure dependencies as well as classic ones.
  • AI-infrastructure CVEs. Model proxies, agent frameworks, and MCP servers carry CVEs like any other dependency, and increasingly appear on KEV. They belong in the same vulnerability-handling process.
  • Coordinated vulnerability disclosure. Findings queue and closure tracking is the evidence trail.