No second provider inventory
The register is assembled from organisations and contract management as at the reporting date. Whatever is maintained there is correct in the register too, with no reconciliation and no second version of the truth.
The register is drawn from your existing data, not kept beside it
DORA demands two things, and in practice both tend to blur into one collective task: evidence that the regulation’s requirements are met, and a register of all contractual arrangements with ICT third-party providers. This module keeps them apart. The obligations catalogue maps the requirements as controls, links each one to its article and to the implementing module, and derives a rate that counts only applicable controls. The register of information is not maintained separately: providers stay in the organisations, contracts in contract management, and on retrieval or export the module assembles both into the six layers of the register as at the reporting date.
The register is assembled from organisations and contract management as at the reporting date. Whatever is maintained there is correct in the register too, with no reconciliation and no second version of the truth.
The initial notification is due within four hours of classification, but no later than twenty-four hours after becoming aware. The module tracks both timestamps and warns two hours before the deadline.
Controls marked as not applicable are excluded from the calculation, neither helping nor hurting. In exchange the gap analysis surfaces controls that still have no implementing module assigned.
When each reporting stage is recorded, what was reported at that moment is retained. Incident data changed later no longer alters the evidence.
A register export drawn from the data you maintain anyway, and a reporting chain whose deadlines run before anyone asks about them.
Schedule a no-obligation demo – we will show you the module with your own use cases.