ECZ-ID DORA Readiness
Terms
These terms apply to the ECZ-ID DORA Readiness agent plugin — the package eczid-dora-readiness, version 0.1.1.
They are product-specific terms. They sit under the EcoCitizenz Terms of Service, which is the agreement between you and EcoCitizenz Ltd and which governs everything not addressed here.
- Applies to:
eczid-dora-readiness0.1.1- Effective date:
- 3 September 2026
In short
- The plugin is free to install and use. There is no fee, no subscription and no account.
- The package is open source under the MITlicence. You may read, copy, modify and redistribute it on that licence's terms.
- It is an evidence-organising readiness review. It does not certify DORA compliance, and it is not legal or regulatory advice.
- Its results are a starting point for your own review, not a conclusion you can rely on without looking, and never something to show a regulator as an assessment.
- Where it cites the regulation, it is describing published law, not stating your position under it.
- Governing law and the limits on our liability come from the EcoCitizenz Terms of Service. This page does not restate them differently.
How these terms fit together
The EcoCitizenz Terms of Service (last updated 31 August 2026) govern access to and use of EcoCitizenz websites, ECZ-ID products, TrustOps, the Resolver, developer tools, software, APIs and machine-facing interfaces. They expressly contemplate product-specific terms, and provide that where there is a conflict, the more specific agreed terms govern that particular service to the extent of the conflict.
This page is that more specific layer for this plugin. Read the two together. Where this page is silent — governing law, acceptable use in full, warranties, limitation of liability, changes, termination, contact — the EcoCitizenz Terms of Service applies unchanged, and nothing here is intended to broaden or narrow it.
Separately, the MIT licence granted with the source code governs your rights to copy, modify and distribute that code. Where the licence grants you a right, that right is not restricted by this page.
What the plugin is
ECZ-ID DORA Readiness is a free, local, read-only evidence review distributed as an Agent Plugins 1.0.0 package. Installed in an agent host, it adds one skill. When invoked, it lists the file names and paths under a folder you choose and reports which classes of ICT resilience evidence were observed, which were not, why each matters and what to review next, together with a deterministic Review Priority and the reasons for it.
It reads names and paths only, and does not open files — including the register, policies, incident records and contracts it reports on. It makes no network request and ships no MCP server. Its behaviour is described in detail on the Privacy page, and the source is public.
What you may do with it
You may install and run the plugin on your own machine and in your own agent host, for personal or business purposes, at no cost. You may run it against repositories you own or are authorised to review. You may share, publish or submit its output as you see fit — the output is yours.
Because the package is licensed under MIT, you may also read, copy, modify, merge, publish, distribute, sublicense and sell copies of it, subject to the licence conditions — principally that the copyright notice and permission notice are retained. The full text is in the repository licence file.
No account, registration, activation key or entitlement is needed, and none is created by using the plugin. Running a review does not create an ECZ-ID, an entitlement, a credential or any public proof.
Your responsibility
You choose which folder to review, and you are responsible for having the right to review it. You are responsible for what you do with the output, including any decision you take or communication you make on the strength of it.
The review is an input to your judgement, not a substitute for it. In particular:
- filename-and-path detection shows that a document exists where a reviewer would expect one; it cannot show that the document is current, complete, accurate or fit for purpose. A register that exists is not a register that is maintained;
- EVIDENCE NOT OBSERVED is neutral. It means the review did not see it in the place it looked. Most ICT resilience evidence lives outside a code repository, so its absence here usually means nothing at all;
- a result describes a folder at the moment it was reviewed. Re-check before relying on it;
- your own policy, your advisers and your competent authority decide what evidence is sufficient. The plugin does not decide that, and neither do we.
No certification, approval or advice
This is the most important clause on the page, and it is not boilerplate. Consistent with the EcoCitizenz Terms of Service, the plugin and its output do not:
- certify compliance with Regulation (EU) 2022/2554 (the Digital Operational Resilience Act) or with any other law, regulation, standard or scheme;
- determine whether you are within the scope of DORA, whether you are a financial entity or an ICT third-party service provider, or whether an arrangement supports a critical or important function;
- satisfy, discharge or evidence any obligation you have under DORA or any other law;
- constitute regulatory approval, or approval by any competent authority, supervisor, marketplace or platform;
- constitute an audit, an audit opinion, or an assurance engagement;
- constitute legal, regulatory, financial, insurance or other professional advice;
- certify that a repository, product, service or organisation is safe, secure or resilient;
- guarantee that a regulator, auditor, customer or insurer will accept your evidence;
- replace your own due diligence.
The Review Priority is an indication of how much attention an evidence review deserves, based only on what was observed locally by filename and path. It is not a score, a grade, a rating, a pass mark, a risk assessment, a readiness rating or a determination of safety, approval or compliance. A LOW Review Priority is not a clean bill of health, and a HIGH one is not a finding of breach.
Where the plugin cites articles or dates from Regulation (EU) 2022/2554 — which has applied since 17 January 2025 (Article 64) — it does so to explain why a class of evidence is asked for. That is description of published law, not a statement about your position under it, and it is not a substitute for reading the regulation or taking advice on it.
Acceptable use
The acceptable-use terms in the EcoCitizenz Terms of Service apply. In the specific context of this plugin, you must not:
- run it against systems or repositories you have no right to review;
- alter its output and present the altered version as the result of an ECZ-ID review;
- present a review as a certification, an audit, an approval or a statement of compliance, or otherwise misrepresent what it establishes;
- represent an expired, superseded or historical result as a current one;
- use the ECZ-ID name, logo or branding in a way that suggests endorsement, certification or a relationship that does not exist;
- imply that EcoCitizenz has verified, approved or is otherwise responsible for your product because you ran this plugin against it.
Intellectual property and licensing
The plugin package — its manifest, skill document, review script, evidence-class reference and documentation — is released under the MIT licence, copyright EcoCitizenz Ltd. That licence, and not this page, is what grants you rights in the code.
The MIT licence covers the code. It does not transfer or license the ECZ-ID and EcoCitizenz names, logos, branding or product marks, which remain the property of EcoCitizenz Ltd, nor the wider ECZ-ID services, schemas, verification formats and infrastructure, which are governed by the EcoCitizenz Terms of Service. You may say truthfully that your project uses this plugin. You may not use our marks to suggest endorsement or certification.
The output of a review that you run is yours. We assert no ownership over it and receive no copy of it.
Availability, changes and updates
The plugin is provided as it is, when it is available. We may change, update, re-version, rename, deprecate or withdraw it, and we may change the detectors, the guidance or the Review Priority rules in a future version. We do not guarantee uninterrupted availability of any distribution channel, and no service level applies to it.
The plugin runs on your machine, so a version you have already installed keeps working whether or not it is still distributed. Because it is MIT-licensed, a copy you hold remains yours to use under that licence.
Distribution through a marketplace or agent-plugin directory does not guarantee continued listing, ranking, visibility or recommendation, and does not imply that the operator of that marketplace has endorsed, certified or reviewed the product.
Agent hosts, marketplaces and other third parties
You run this plugin inside an agent host operated by a third party, and you may have obtained it through a third-party marketplace or directory. Those platforms are not operated by EcoCitizenz. Your use of them is governed by their own terms and privacy policies, and they may impose requirements of their own; where a marketplace's mandatory terms govern a transaction on that marketplace, those terms apply to it.
EcoCitizenz is not responsible for the availability, behaviour, security or data handling of any agent host or marketplace, and nothing on these pages is a commitment made on their behalf. Naming a platform here identifies the software involved; it does not indicate affiliation, sponsorship or endorsement in either direction.
Links from a review result to EcoCitizenz pages, or to public documentation elsewhere, are routing only. Setup, subscriptions and payment for paid ECZ-ID credentials happen in TrustOps under the EcoCitizenz Terms of Service. This plugin takes no payment and creates no entitlement.
Security research
EcoCitizenz supports good-faith security reporting. If you believe you have identified a vulnerability, report it through the route on the Support page rather than disclosing it publicly first.
When testing, you must not access customer data unnecessarily, destroy or alter data, disrupt production systems, perform denial-of-service testing, exploit a vulnerability beyond what is reasonably required to demonstrate it, or publicly disclose a vulnerability before reasonable coordinated disclosure where doing so would create material risk. These conditions are those set out in the EcoCitizenz Terms of Service.
Warranties and liability
The plugin package is distributed under the MIT licence, which provides the software as is and without warranty of any kind. That disclaimer applies to the code.
Beyond that, the warranty and liability terms in the EcoCitizenz Terms of Service apply, including the limits on liability and the exceptions to them. This page does not create a different liability position, and does not state a figure or a cap of its own — the Terms of Service is the place those are set.
Nothing on this page excludes or limits liability where it would be unlawful to do so, and nothing here affects rights you have under mandatory law, including consumer rights where they apply to you.
Governing law
The EcoCitizenz Terms of Service are governed by the laws of England and Wales, and set out the position on jurisdiction, including the protections that apply if you are a consumer. That governing-law position applies to these product terms as well. This page states no separate choice of law and no separate jurisdiction clause.
Questions about these terms
Write to support@ecocitizenz.com, naming ECZ-ID DORA Readiness in the subject line. The publisher details are below.
Plainly, so there is no doubt
- Running this review does not make you DORA compliant, and we never say that it does. It helps you see which evidence is where before someone asks for it.
- A review result is not an assessment, and it should not be presented to a supervisor, auditor or customer as one.
- EcoCitizenz has not certified, approved or audited your repository, your arrangements or your organisation, and a review result must not be presented as though we had.
- The same detectors ship in the free VS Code extension on the Visual Studio Marketplace and Open VSX; that is a separate product with its own terms.
- No ECZ-ID product on this page is endorsed by, affiliated with or approved by any regulator, supervisory authority, standards body, marketplace operator or AI platform.
Publisher
ECZ-ID DORA Readiness is published by EcoCitizenz Ltd, trading as EcoCitizenz, company number 17348848, registered in England and Wales.
66 Paul StreetLondon EC2A 4NAUnited KingdomContact: support@ecocitizenz.com