[{"data":1,"prerenderedAt":309},["ShallowReactive",2],{"section-links-solutions-en":3,"section-links-reglementation-en":36,"section-links-guides-en":65,"section-links-comparatifs-en":90,"regulation-en-dora":103},[4,8,12,16,20,24,28,32],{"label":5,"to":6,"description":7},"DORA + ISO 27001","\u002Fen\u002Fsolutions\u002Fdora-iso27001-compliance-software","Run DORA and ISO 27001 in one platform: CTPP register, SoA, Annex A controls and unified audit exports.",{"label":9,"to":10,"description":11},"NIS2 vendors","\u002Fen\u002Fsolutions\u002Fnis2-vendor-compliance","Extend your NIS2 compliance to your vendor chain: assessment campaigns, supply chain mapping and regulator-ready exports.",{"label":13,"to":14,"description":15},"Supply chain","\u002Fen\u002Fsolutions\u002Fsupply-chain-cybersecurity","Map your supply chain, assess your vendors' cybersecurity and track remediation through to risk closure.",{"label":17,"to":18,"description":19},"Third-party GRC","\u002Fen\u002Fsolutions\u002Fthird-party-grc-platform","CISAPP brings governance, risk and compliance (GRC) together for your third-party ecosystem: regulatory frameworks, audits and risk register.",{"label":21,"to":22,"description":23},"TPRM SaaS","\u002Fen\u002Fsolutions\u002Ftprm-saas","CISAPP is a TPRM SaaS platform unifying assessment campaigns, scoring, dependency mapping and regulatory compliance.",{"label":25,"to":26,"description":27},"Vendor risk","\u002Fen\u002Fsolutions\u002Fvendor-risk-management","Map, assess and steer your vendor risk with campaigns, a security score and a centralised risk register.",{"label":29,"to":30,"description":31},"Questionnaires","\u002Fen\u002Fsolutions\u002Fvendor-security-questionnaire","Run preconfigured vendor security questionnaire campaigns (ISO 27001, NIS2, DORA, GDPR) and track responses in real time.",{"label":33,"to":34,"description":35},"SecOps score","\u002Fen\u002Fsolutions\u002Fvendor-security-score","Track a vendor security score computed automatically from external technical scans (DNS, TLS, exposure, headers, breach), with history and alerts.",[37,41,45,49,53,57,61],{"label":38,"to":39,"description":40},"AI Act","\u002Fen\u002Fregulations\u002Fai-act","Prepare your EU AI Act compliance: AI system register, FRIA and article-level mapping, connected to your risk management.",{"label":42,"to":43,"description":44},"DORA","\u002Fen\u002Fregulations\u002Fdora","Manage your critical third-party ICT provider (CTPP) register, TLPT testing, and ICT incidents in an audit-ready DORA framework.",{"label":46,"to":47,"description":48},"GDPR","\u002Fen\u002Fregulations\u002Fgdpr","Maintain your records of processing activities and DPIAs, and manage data breaches with a severity wizard and a 72-hour notification tracker.",{"label":50,"to":51,"description":52},"ISO 27001","\u002Fen\u002Fregulations\u002Fiso-27001","Manage your Statement of Applicability (SoA), Annex A controls and ISO 27001 audit evidence in a single platform.",{"label":54,"to":55,"description":56},"NIS2","\u002Fen\u002Fregulations\u002Fnis2","Manage your NIS2 obligations (Article 21 measures, significant incidents, supply chain) and prepare regulator-ready exports from one platform.",{"label":58,"to":59,"description":60},"Part-IS","\u002Fen\u002Fregulations\u002Fpart-is","EASA Part-IS compliance (Regulations (EU) 2023\u002F203 and 2022\u002F1645): aviation ISMS, PSOE levels, Present & Suitable self-assessment, evidence and audit questionnaire.",{"label":62,"to":63,"description":64},"TISAX","\u002Fen\u002Fregulations\u002Ftisax","Understand TISAX assessment levels (AL1 to AL3), the VDA ISA catalogue, label validity, and what an automotive supplier must prove to its customers.",[66,70,74,78,82,86],{"label":67,"to":68,"description":69},"Fourth-party risk","\u002Fen\u002Fresources\u002Ffourth-party-risk","Your vendors depend on subcontractors you've never assessed. How to identify and manage this often-invisible fourth-party risk.",{"label":71,"to":72,"description":73},"Questionnaire fatigue","\u002Fen\u002Fresources\u002Fsecurity-questionnaire-fatigue","Why security questionnaires overwhelm procurement, security teams, and vendors alike, and how to break the re-entry cycle without losing rigor.",{"label":75,"to":76,"description":77},"Supply chain attack","\u002Fen\u002Fresources\u002Fsupply-chain-cyberattack","How a cyberattack at a vendor spreads into your organization, why it's hard to anticipate, and how to structure your defense against it.",{"label":79,"to":80,"description":81},"Concentration & SPOF","\u002Fen\u002Fresources\u002Fvendor-concentration-risk-spof","How to identify single points of failure (SPOF) hidden in your vendor chain and map risk concentration before an incident reveals it for you.",{"label":83,"to":84,"description":85},"Due diligence","\u002Fen\u002Fresources\u002Fvendor-cyber-due-diligence","How to structure cyber due diligence before signing a vendor contract, what to ask, and how to avoid inheriting a third party's risk unknowingly.",{"label":87,"to":88,"description":89},"Incident playbook","\u002Fen\u002Fresources\u002Fvendor-security-incident-playbook","What to do in the first hours after a vendor discloses a security incident: a 5-step playbook to assess impact, contain, and document.",[91,95,99],{"label":92,"to":93,"description":94},"CISAPP vs spreadsheet","\u002Fen\u002Fcomparisons\u002Fcisapp-vs-spreadsheet-third-party-risk","How far a spreadsheet takes you in vendor risk management, and the point at which it costs more than a platform: a comparison on verifiable criteria.",{"label":96,"to":97,"description":98},"European alternatives","\u002Fen\u002Fcomparisons\u002Feuropean-alternatives-us-tprm-platforms","What choosing a European vendor changes for third-party risk management: applicable law, data transfers, sovereignty and GDPR compliance.",{"label":100,"to":101,"description":102},"TPRM selection criteria","\u002Fen\u002Fcomparisons\u002Ftprm-platform-selection-criteria","An evaluation grid for third-party risk platforms: regulatory coverage, assessment cycle, evidence, hosting, integrations and total cost of ownership.",{"id":104,"title":105,"author":106,"body":107,"description":44,"entities":254,"extension":256,"faq":257,"keywords":276,"meta":282,"navigation":283,"ogImage":284,"path":43,"persona":285,"publishedAt":284,"regulation":286,"relatedFeatures":287,"relatedPages":291,"seo":294,"shortTitle":42,"slug":286,"sources":295,"stem":305,"tldr":306,"updatedAt":307,"__hash__":308},"regulations_en\u002Fen\u002Fregulations\u002Fdora.md","DORA Compliance Software | CTPP Register, TLPT | CISAPP","CISAPP",{"type":108,"value":109,"toc":247},"minimark",[110,115,129,152,156,159,230,234,237],[111,112,114],"h2",{"id":113},"what-is-dora-and-who-does-it-apply-to","What is DORA and who does it apply to?",[116,117,118,128],"p",{},[119,120,121,122,127],"strong",{},"DORA is Regulation (EU) 2022\u002F2554 on ",[123,124,126],"a",{"href":125},"\u002Fen\u002Fglossary\u002Fdigital-operational-resilience","digital operational resilience"," in the European financial sector, applicable since 17 January 2025."," It unifies requirements previously scattered across sectoral authorities and, above all, puts control over ICT providers on the same footing as internal information system security.",[130,131,132],"key-takeaways",{},[133,134,135,139,142,145],"ul",{},[136,137,138],"li",{},"Five pillars: ICT risk governance, major incident reporting, resilience testing, ICT third-party risk, information sharing.",[136,140,141],{},"The register of information lists all ICT contractual arrangements and is reported to competent authorities.",[136,143,144],{},"Critical or important functions require a documented exit strategy.",[136,146,147,151],{},[123,148,150],{"href":149},"\u002Fen\u002Fglossary\u002Fconcentration-risk","Concentration risk"," must be analysed before engaging a critical provider.",[111,153,155],{"id":154},"what-does-dora-require-on-ict-third-parties","What does DORA require on ICT third parties?",[116,157,158],{},"The third-party pillar is the one that shifts the most work onto vendor management. It creates four standing deliverables:",[160,161,163],"comparison-table",{"caption":162},"DORA obligations on ICT providers and the artefacts they require",[164,165,166,182],"table",{},[167,168,169],"thead",{},[170,171,172,176,179],"tr",{},[173,174,175],"th",{},"Obligation",[173,177,178],{},"Expected artefact",[173,180,181],{},"Frequency",[183,184,185,197,208,219],"tbody",{},[170,186,187,191,194],{},[188,189,190],"td",{},"Register of contractual arrangements",[188,192,193],{},"Register of information, in the authorities' format",[188,195,196],{},"Kept current, reported on request",[170,198,199,202,205],{},[188,200,201],{},"Minimum contractual clauses",[188,203,204],{},"Compliant contract (access, audit, subcontracting, exit)",[188,206,207],{},"At signature and at every amendment",[170,209,210,213,216],{},[188,211,212],{},"Concentration risk analysis",[188,214,215],{},"Documented assessment before contracting",[188,217,218],{},"Before the decision, then on review",[170,220,221,224,227],{},[188,222,223],{},"Exit strategy",[188,225,226],{},"Reversibility plan for critical functions",[188,228,229],{},"Documented and maintained",[111,231,233],{"id":232},"how-cisapp-structures-dora-compliance","How CISAPP structures DORA compliance",[116,235,236],{},"Instead of scattered files, CISAPP links every critical provider to its security assessment, certifications and incident history. The CTPP register is fed from the vendor record, the concentration matrix cross-references declared dependencies, and both resilience tests and ICT incidents are tracked in the same framework — ready to present during a review.",[116,238,239,240,243,244,246],{},"See also the ",[123,241,242],{"href":6},"DORA and ISO 27001 compliance software"," solution and the ",[123,245,54],{"href":55}," page.",{"title":248,"searchDepth":249,"depth":249,"links":250},"",2,[251,252,253],{"id":113,"depth":249,"text":114},{"id":154,"depth":249,"text":155},{"id":232,"depth":249,"text":233},[255,150],"Digital operational resilience","md",[258,261,264,267,270,273],{"q":259,"a":260},"What is the DORA regulation?","DORA (Digital Operational Resilience Act) is Regulation (EU) 2022\u002F2554, which gives EU financial entities a harmonised digital operational resilience framework: ICT risk governance, major incident reporting, resilience testing, ICT third-party risk management and information sharing on cyber threats.",{"q":262,"a":263},"Since when does DORA apply?","The regulation entered into force on 16 January 2023 and has applied since 17 January 2025. Being a regulation, it applies directly, without national transposition.",{"q":265,"a":266},"Who is in scope of DORA?","Around twenty categories of financial entities: credit institutions, investment firms, payment and electronic money institutions, insurers and reinsurers, asset managers, crypto-asset service providers and market infrastructures, among others. ICT providers designated as critical are additionally subject to direct oversight by the European supervisory authorities.",{"q":268,"a":269},"What is the register of information required by DORA?","It is the register of contractual arrangements with ICT providers, maintained at entity and, where relevant, group level. It identifies each provider, the functions supported, whether they are critical or important, data location and the subcontracting chain, and it is reported to the competent authorities.",{"q":271,"a":272},"What is TLPT?","Threat-Led Penetration Testing is advanced testing carried out on production systems, required of the most significant entities on a multi-year cycle. It comes on top of the baseline resilience testing programme expected of all entities.",{"q":274,"a":275},"Does CISAPP manage the critical ICT provider register?","Yes. The DORA module maintains a CTPP register linked to your concentration risk matrix and vendor assessments, tracks resilience testing and ICT incidents, and produces the exports expected by your supervisory authorities.",[277,278,279,280,281],"DORA compliance software","DORA CTPP","critical ICT provider register","DORA compliance","TLPT",{},true,null,"entreprise","dora",[288,289,290],"Regulatory frameworks","Risk register","Vendor mapping",[292,293],"nis2","iso-27001",{"title":105,"description":44},[296,301],{"label":297,"url":298,"publisher":299,"date":300},"Regulation (EU) 2022\u002F2554 (DORA) — consolidated text","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2022\u002F2554\u002Foj","EUR-Lex","2022-12-14",{"label":302,"url":303,"publisher":304},"Digital Operational Resilience Act — EIOPA page","https:\u002F\u002Fwww.eiopa.europa.eu\u002Fdigital-operational-resilience-act-dora_en","EIOPA","en\u002Fregulations\u002Fdora","DORA (Regulation (EU) 2022\u002F2554) has applied to EU financial entities since 17 January 2025. It structures digital operational resilience in five pillars, one of which is ICT third-party risk: register of contractual arrangements, mandatory clauses, concentration analysis and an exit strategy for critical functions.","2026-08-16","KL2GJwhTIAGMWn-UKILjFpkKUQZDcIdSeOVA8F2QJ2A",1791391138491]