Manage your ICT risk, maintain your register of information on third-party providers and document your resilience.
Regulation (EU) 2022/2554, known as DORA, has applied since 17 January 2025 to financial entities in the Union and to their ICT service providers. It rests on five pillars: management of risk relating to information and communication technologies, management and reporting of major ICT-related incidents, digital operational resilience testing, management of ICT third-party risk, and information sharing on cyber threats. Unlike a directive, a regulation applies directly: there is no national transposition to soften its edges.
Two obligations shape the workload. First the ICT risk management framework, which has to be documented, reviewed and tied to the entity's critical or important functions. Second the register of information on contractual arrangements with ICT third-party service providers, which competent authorities can request and which must single out providers supporting critical functions. A serious DORA platform holds that register, ties each provider to the functions it supports, and keeps the trace of resilience tests and incidents.
Vailor handles ICT risk management and third-party risk on the same data layer, which removes the usual drift between the provider register and the risk map. Agentic AI runs the risk assessments and prepares the expected deliverables, with every output explainable and traceable under review. Controls shared with ISO 27001, NIS2 and your existing EBIOS RM work are reused rather than re-entered.
AI-assisted risk assessment, tied to your critical or important functions.
The register of information on ICT arrangements, linked to the functions each provider supports.
The documented trace of your major incidents and your operational resilience tests.
Your resilience data stays sovereign, hosted in France and the European Union.
DORA applies to financial entities across the Union in a broad sense: credit institutions, investment firms, payment and electronic money institutions, insurers, reinsurers and insurance intermediaries, fund managers, crypto-asset service providers, market infrastructures and credit rating agencies. ICT third-party providers are caught in two ways: through the contractual requirements placed on their financial clients, and, for those the European Supervisory Authorities designate as critical, through direct oversight at EU level. A simplified ICT risk management framework remains open to certain smaller entities.
No. DORA is an EU regulation, not a certification scheme: no body issues a DORA certificate and no organisation can call itself DORA certified. Compliance is demonstrated to the competent authority that supervises you, which in France means the ACPR for banks and insurers and the AMF for asset management and market participants. What it looks at is your documentation: the ICT risk management framework, the register of information, incident reports and test results.
NIS2 is a directive transposed by each member state and spans many sectors; DORA is a directly applicable regulation aimed at the financial sector alone. Where the two could overlap, DORA takes precedence as the sector-specific text: a financial entity within its scope applies DORA for its cyber risk management measures and its incident reporting. The two texts share enough logic for a good share of the controls to serve both.
It is a function whose disruption would materially impair the financial performance of the entity, the soundness or continuity of its services and activities, or its ability to keep meeting the conditions of its authorisation and its other regulatory obligations. The label is not cosmetic: it triggers stricter requirements on the contractual terms agreed with the ICT provider concerned, on testing, and on what the register of information has to record. It is one of the first decisions to document, and to revisit whenever the scope moves.
DORA asks for a testing programme proportionate to risk, including at least yearly tests of the systems supporting critical or important functions: vulnerability assessments, continuity tests, security analyses. On top of that, entities designated by their competent authority on the basis of their risk profile and their impact on the financial sector must run threat-led penetration testing (TLPT) at least every three years, aligned with the TIBER-EU framework.
The regulation sets a baseline for every ICT service arrangement: a full description of the services, the locations where they are delivered and where data is processed or stored, data protection and data return, service levels, assistance in the event of an incident, cooperation with the authorities, and termination conditions with notice periods. Where the provider supports a critical or important function the bar rises: precise performance targets, unrestricted access, inspection and audit rights, participation in testing, and documented, tested exit strategies. That means reworking the stock of existing contracts, not only the new ones.
The register follows a format set at European level: several tables linked by identifiers, where a contractual arrangement points to the signing entity, to the provider, to its subcontractors and to the functions it supports. In a spreadsheet those links come apart on the first update, and one inconsistent reference is enough to fail the data quality checks when the file is submitted. A dedicated tool holds the relationships, verifies consistency before submission, and saves rebuilding the register for every collection round.
Discover all our resources on governance, risk, and compliance powered by artificial intelligence.
Everything you need to know about AI GRC: definition, benefits, implementation, and best practices to transform your governance with artificial intelligence.
Essential criteria for selecting the best cyber AI GRC platform. Architecture, sovereignty, features: the complete buying guide.
Book a demo and see how to hold your register and your ICT risk in one place.