ISMS & Risk

DORA

The register is drawn from your existing data, not kept beside it

DORA demands two things, and in practice both tend to blur into one collective task: evidence that the regulation’s requirements are met, and a register of all contractual arrangements with ICT third-party providers. This module keeps them apart. The obligations catalogue maps the requirements as controls, links each one to its article and to the implementing module, and derives a rate that counts only applicable controls. The register of information is not maintained separately: providers stay in the organisations, contracts in contract management, and on retrieval or export the module assembles both into the six layers of the register as at the reporting date.

DORAEU 2022/2554NIS2ISO 27001
Features

Your benefits

1

No second provider inventory

The register is assembled from organisations and contract management as at the reporting date. Whatever is maintained there is correct in the register too, with no reconciliation and no second version of the truth.

2

Two deadlines, the earlier one applies

The initial notification is due within four hours of classification, but no later than twenty-four hours after becoming aware. The module tracks both timestamps and warns two hours before the deadline.

3

A rate that does not flatter

Controls marked as not applicable are excluded from the calculation, neither helping nor hurting. In exchange the gap analysis surfaces controls that still have no implementing module assigned.

4

The notification content is frozen

When each reporting stage is recorded, what was reported at that moment is retained. Incident data changed later no longer alters the evidence.

Capabilities

All capabilities at a glance

  • Control catalogue for Articles 5 to 17, structured along the regulation’s five core areas
  • Compliance status per control with evidence field, owner and linked module
  • Gap analysis: applicable controls with no implementing module assigned
  • Dashboard with the compliance rate across all applicable controls and progress per category
  • Register of information under Article 28(3) in six layers, generated as at the reporting date
  • Reporting entity with LEI, entity type and competent authority
  • Contract profiles per agreement: governing law, notice periods, annual cost, CIF flag
  • ICT services per contract with type of service, data storage and data location
  • Business functions with CIF classification: critical, important or neither
  • Subcontracting chain per service with rank in the chain
  • Exit strategies per contract, as their own record and in the register export
  • Data quality check before extraction, plus export for the supervisory authority
  • Three-stage reporting chain with the deadlines of IR (EU) 2025/301, classification per RTS (EU) 2024/1772
  • Hourly deadline service with advance warning and overdue notice, plus a dashboard widget
  • Notification content per stage as JSON, the complete file as PDF
  • Test inventory with cycle, automatically calculated due date and owners
  • TLPT under Article 26 with a mandatory external tester field and a pre-set three-year cycle
  • Test findings feed into measure management as linked measures
Result

A register export drawn from the data you maintain anyway, and a reporting chain whose deadlines run before anyone asks about them.

Experience DORA live

Schedule a no-obligation demo – we will show you the module with your own use cases.