DORA third party risk checklist
Check each item that applies to your ICT supply chain. DORA requires documented control over critical ICT providers and incident response.
DORA says you must have a plan to leave every critical provider. If your cloud goes down, can you move your data fast? Most companies cannot. Your regulator will ask for proof.
DORA gives you the right to audit your ICT providers. But big cloud companies will not change their contracts. You cannot check their security. That is a compliance gap you cannot fix.
DORA fines go up to EUR 10 million or 2% of your global turnover. Your management body is liable. Your provider holds the keys. You carry the risk.
DORA applies directly to banks, insurers, payment institutions, and crypto asset providers. If you serve financial clients, DORA Article 28 contractual flow-down catches you too. Check your NIS2 exposure if you are an MSSP.
Worried about NIS2, DORA, AI Act or GDPR?
These regulations ask the same question. Who controls the systems you depend on. Our sovereign platform gives you the answer. You.
No sales pressure. A clear look at your numbers, your dependencies, and your options.