Single-regime checklists are everywhere; what a dual-scope entity actually needs is the difference — where one control satisfies both, and where two clocks start ticking on the same incident. The reporting-clock comparison is the tool worth having open during an incident, not after it.
A Python server that maps DORA against NIS2 for organisations in scope for both. The repository puts the overlap at 65% of obligations, which is the whole reason the server exists: most of the work is shared, and the parts that aren't are where people get caught.
Three tools, named in the repository's own examples: `list_overlapping_obligations` for what both regimes ask of you, `compare_reporting_clocks` for the incident-notification deadlines that differ between them, and `check_dual_compliance` for the combined position.
`pip install dora_nis2_crosswalk_mcp`, or point your client at `uvx` with the argument `dora-nis2-crosswalk-mcp` (package version 1.1.5, stdio transport). MIT-licensed.
One command — pip install dora_nis2_crosswalk_mcp
