Server data from the Official MCP Registry
DORA × NIS2 Crosswalk MCP — map Regulation (EU) 2022/2554 obligations to Directive (EU) 2022/255...
DORA × NIS2 Crosswalk MCP — map Regulation (EU) 2022/2554 obligations to Directive (EU) 2022/255...
This MCP server implements a DORA × NIS2 compliance crosswalk tool with reasonable domain-specific functionality. However, several security concerns lower the score: (1) fallback auth logic permits unauthenticated access if environment variables are missing, (2) unauthenticated API endpoints allow unlimited free-tier queries without proper rate-limiting enforcement, (3) external API calls to a third-party attestation service without request signing or validation, and (4) unsafe module path insertion for loading potentially untrusted local modules. While the core compliance logic appears sound and permissions are appropriate for the category, the auth and validation gaps create exploitable conditions. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.
5 files analyzed · 12 issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
This plugin requests these system permissions. Most are normal for its category.
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-csoai-org-dora-nis2-crosswalk-mcp": {
"args": [
"dora-nis2-crosswalk-mcp"
],
"command": "uvx"
}
}
}From the project's GitHub README.
Map Regulation (EU) 2022/2554 (DORA) obligations to Directive (EU) 2022/2555 (NIS2) Article 21-23 measures — so EU banks, insurers, payment institutions, crypto-asset service providers, and their CTPPs can prove dual compliance without re-auditing the same controls twice.
By MEOK AI Labs.
Most EU financial entities are in scope for both DORA and NIS2. The obligations overlap ~65% but:
If you treat them as two separate programmes, you duplicate work. If you treat them as one with a crosswalk, you don't.
list_overlapping_obligations — full crosswalk table with "satisfies-both-if" testcompare_reporting_clocks — side-by-side incident reporting timelinecheck_dual_compliance — score your current controls against both regimessign_dual_compliance_attestation — Pro/Enterprise: cryptographically signed dual-compliance certpip install dora-nis2-crosswalk-mcp
dora-compliance-mcp — DORA alonenis2-compliance-mcp — NIS2 alonecra-compliance-mcp — EU CRAmeok-attestation-verify — verify signed certsNeed more than crosswalk mapping? councilof.ai provides the complete EU regulatory compliance stack — DORA, NIS2, EU AI Act, CRA, CSRD — from £29/mo.
If this tool helps your compliance workflow, please star this repo — it helps other teams find it.
MIT — MEOK AI Labs, 2026.
Be the first to review this server!
by Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
by Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
by mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.