Regulations

DORA Compliance Software

Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.

TL;DR

DORA (Regulation (EU) 2022/2554) has applied to EU financial entities since 17 January 2025. It structures digital operational resilience in five pillars, one of which is ICT third-party risk: register of contractual arrangements, mandatory clauses, concentration analysis and an exit strategy for critical functions.

What is DORA and who does it apply to?

DORA is Regulation (EU) 2022/2554 on digital operational resilience in the European financial sector, applicable since 17 January 2025. It unifies requirements previously scattered across sectoral authorities and, above all, puts control over ICT providers on the same footing as internal information system security.

What does DORA require on ICT third parties?

The third-party pillar is the one that shifts the most work onto vendor management. It creates four standing deliverables:

DORA obligations on ICT providers and the artefacts they require
ObligationExpected artefactFrequency
Register of contractual arrangementsRegister of information, in the authorities' formatKept current, reported on request
Minimum contractual clausesCompliant contract (access, audit, subcontracting, exit)At signature and at every amendment
Concentration risk analysisDocumented assessment before contractingBefore the decision, then on review
Exit strategyReversibility plan for critical functionsDocumented and maintained

How CISAPP structures DORA compliance

Instead of scattered files, CISAPP links every critical provider to its security assessment, certifications and incident history. The CTPP register is fed from the vendor record, the concentration matrix cross-references declared dependencies, and both resilience tests and ICT incidents are tracked in the same framework — ready to present during a review.

See also the DORA and ISO 27001 compliance software solution and the NIS2 page.

FAQ

DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554, which gives EU financial entities a harmonised digital operational resilience framework: ICT risk governance, major incident reporting, resilience testing, ICT third-party risk management and information sharing on cyber threats.

Sources

  1. Regulation (EU) 2022/2554 (DORA) — consolidated text — EUR-Lex, 2022-12-14
  2. Digital Operational Resilience Act — EIOPA page — EIOPA

Ready for the regulations that apply to you

Ready to take control of your third-party risk?

I'm a company

We'll get back to you within 24 hours

I'm a vendor

Immediate onboarding

Create a free account