Regulations
DORA Compliance Software
Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.
TL;DR
DORA (Regulation (EU) 2022/2554) has applied to EU financial entities since 17 January 2025. It structures digital operational resilience in five pillars, one of which is ICT third-party risk: register of contractual arrangements, mandatory clauses, concentration analysis and an exit strategy for critical functions.
What is DORA and who does it apply to?
DORA is Regulation (EU) 2022/2554 on digital operational resilience in the European financial sector, applicable since 17 January 2025. It unifies requirements previously scattered across sectoral authorities and, above all, puts control over ICT providers on the same footing as internal information system security.
What does DORA require on ICT third parties?
The third-party pillar is the one that shifts the most work onto vendor management. It creates four standing deliverables:
| Obligation | Expected artefact | Frequency |
|---|---|---|
| Register of contractual arrangements | Register of information, in the authorities' format | Kept current, reported on request |
| Minimum contractual clauses | Compliant contract (access, audit, subcontracting, exit) | At signature and at every amendment |
| Concentration risk analysis | Documented assessment before contracting | Before the decision, then on review |
| Exit strategy | Reversibility plan for critical functions | Documented and maintained |
How CISAPP structures DORA compliance
Instead of scattered files, CISAPP links every critical provider to its security assessment, certifications and incident history. The CTPP register is fed from the vendor record, the concentration matrix cross-references declared dependencies, and both resilience tests and ICT incidents are tracked in the same framework — ready to present during a review.
See also the DORA and ISO 27001 compliance software solution and the NIS2 page.
FAQ
DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554, which gives EU financial entities a harmonised digital operational resilience framework: ICT risk governance, major incident reporting, resilience testing, ICT third-party risk management and information sharing on cyber threats.
Sources
- Regulation (EU) 2022/2554 (DORA) — consolidated text — EUR-Lex, 2022-12-14
- Digital Operational Resilience Act — EIOPA page — EIOPA
Ready to take control of your third-party risk?
I'm a company
We'll get back to you within 24 hours