Solution · DORA
DORA compliance on the record you already keep
Regulation (EU) 2022/2554 has applied since 17 January 2025 to financial entities and their critical ICT third-party providers. Secantra maps its ICT risk-management, incident, resilience-testing and third-party requirements onto your assets, controls and evidence — one adoption, one posture.
- Instrument
- Regulation (EU) 2022/2554
- Applies from
- 17 January 2025
- Who
- Banks, insurers, investment firms, payment & e-money institutions, crypto-asset service providers, ICT third-party providers
- Supervision
- National competent authorities; ESAs for critical ICT third-party providers
Mapping
What DORA asks — and where it lives in Secantra
Status is stated honestly: LIVE is in the product today, PARTLY means the data model supports it but a workflow is not in the current release, PLANNED means not yet. Frameworks ship as curated, versioned libraries (ISO/IEC 27001 Annex A 93 requirements, DORA 29, NIS2 21 today) that you extend with tenant requirements — not verbatim reproductions of the legal text.
| DORA area | Articles | What is expected | In Secantra | Status |
|---|---|---|---|---|
| ICT risk management framework | Art. 5–16 | A documented, board-owned framework: identification, protection, detection, response, recovery, learning. | Requirements adopted per article; controls mapped; posture derived; governance documents for the framework itself. | LIVE |
| ICT-related incident management | Art. 17–23 | Classify incidents, report major ones to the authority on the prescribed timeline. | Procedures and classification criteria as governance documents; findings for gaps. A dedicated incident workflow is not in the current release. | PARTLY |
| Digital operational resilience testing | Art. 24–27 | A testing programme proportionate to size and risk; TLPT for significant entities. | Test evidence attached to controls with recency rules; gaps raised as findings with owners and dates. | LIVE |
| ICT third-party risk | Art. 28–30 | Manage risk from ICT providers across the contract lifecycle; key contractual provisions. | Third-party registry linked to the assets and services each provider supports; risks per supplier in the register. Contract records are not in the current release. | PARTLY |
| Register of information | Art. 28(3) | Maintain a register of all contractual arrangements on the use of ICT services. | Providers, the ICT services they deliver and the functions they support are linked records — the data the register is built from. | PARTLY |
| Information-sharing arrangements | Art. 45 | Exchange cyber-threat information and intelligence within trusted communities. | Arrangements documented as governance documents; automated ingestion of shared intelligence is not in the current release. | PLANNED |
How it runs
A DORA programme in Secantra
- 01
Adopt DORA v1.x
Pin the published version; mark applicability per article for your entity type and size.
- 02
Map assets and providers
Business solutions, the ICT services under them, and the third parties that supply them.
- 03
Attach controls and evidence
Framework documents, test results, provider assessments — with recency rules.
- 04
Show it from the record
Posture snapshots, open findings, overdue reviews — and generated reports from the record: framework status, risk register, executive summary.
Questions DORA teams ask
Is Secantra a substitute for the register of information template?
No. The ESAs prescribe the register format. Secantra holds the linked records the register is built from, so the data is consistent and current when you produce it.
Does it cover the incident-reporting timelines?
Classification criteria and procedures are handled as governance documents today; a dedicated incident workflow is not in the current release. We say so on the page rather than imply it.
We are a small entity — does the simplified framework apply?
Applicability is decided per requirement, so a proportionate scope is a first-class setting, not a workaround.
See it on your own frameworks
A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.