Is AGICY DORA compliant?
The question does not quite work, and the answer no supplier should give is yes. DORA imposes duties on financial entities, not on their compute suppliers. What we can be is contractible: able to accept the Article 30 terms your own compliance requires. Today we could accept some of them and not others, and the standing table above says which.
Are you a critical ICT third-party provider?
No. That status is a designation made by the European Supervisory Authorities under Article 31, based on criteria including systemic importance and substitutability. It is not a badge a provider awards itself, and a provider implying otherwise is misreading the regulation.
Can you sign the Article 30(3) location clause?
Not for a live service today. That clause requires naming the countries where the function is provided and the data processed and stored. The Cyprus campus is pre-construction, so there is no operating location to name yet. For workloads running through the Copperway gateway we can describe the actual processing path, which is a narrower commitment and should be read as one.
Does a Sovereign Reserve Agreement help our DORA position?
Not on its own. An SRA is a commercial reservation of planned capacity. It is not a legal certification and does not by itself satisfy DORA, NIS2, the EU AI Act, or GDPR. It is a place in a queue, and your counsel should treat it as exactly that.
Would you accept audit and supervisory access?
In principle yes, including unrestricted rights of access, inspection, and audit for you, your auditors, and your competent authority. We would rather say this plainly than dress it up: we have no executed financial entity contract, so this is a stated position rather than a demonstrated track record.
What do you hold in the way of certifications?
None that bear on this. ISO 27001 and SOC 2 are design targets rather than certificates in hand, and we would rather lose a tender than let a design target be read as an audit result.