TLD name registries and entities providing domain name registration services carry a dedicated set of duties aimed at DNS security, stability and resilience. They must collect and maintain accurate and complete domain name registration data with due diligence and in line with Union data protection law, holding at least the domain name, the registration date, the registrant's name, contact email address and telephone number, and the contact email address and telephone number of the point of contact administering the domain where those differ. They must have policies and procedures, including verification procedures, that keep the data accurate and complete, and those policies must be published. Registration data that is not personal data must be made publicly available without undue delay after registration. Access to specific registration data must be given on lawful and duly substantiated requests from legitimate access seekers, with a reply within 72 hours of receipt, under published disclosure policies. Registries and registrars must cooperate so the same data is not collected twice.
NIS2 Directive Art.28 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIS2 Directive your existing evidence covers. Hold DORA and 17 of 28 NIS2 Directive controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the DORA pair alone.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.