DORA Article 28 in 3 sentences

DORA is the EU digital operational resilience act. It applies to banks insurers and other financial entities. It requires you to secure your ICT third parties and report incidents within 24 hours.

Note: This is a simplified checklist. Refer to the official DORA Regulation (EU) 2022/2554 and RTS on ICT third party risk for full requirements. Consult qualified legal counsel for compliance decisions.

DORA third party risk checklist

Check each item that applies to your ICT supply chain. DORA requires documented control over critical ICT providers and incident response.

DORA gap assessment
Not Started
0 of 8 answered
DORA ICT third party risk requirements
Do you maintain a register of all critical ICT third party providers?DORA Article 28
You do not maintain a register of all critical ICT providers. DORA Article 28 requires you to map all critical ICT providers. You must keep an up-to-date register. This is a compliance gap.
Do you have contractual audit rights for every critical ICT provider?DORA Article 28
You do not have contractual audit rights for every critical ICT provider. DORA Article 28 requires full audit access for critical providers. Most providers use standard terms they will not change. You cannot verify security controls.
Do you conduct exit tests for critical ICT providers?DORA Article 28
You do not conduct exit tests for critical ICT providers. DORA Article 28 requires exit strategies. If your provider fails, you cannot switch. Your data and operations are at risk.
Do you have documented incident response plans with ICT providers?DORA Article 28
You do not have documented incident response plans with ICT providers. DORA requires incident response coordination. If your provider suffers a breach, you may not find out in time. Your management body is liable.
Do you monitor ICT provider performance against SLAs?DORA Article 28
You do not monitor ICT provider performance against SLAs. DORA expects ongoing monitoring of critical providers. You cannot demonstrate control if you do not track performance.
Do you know where your data is stored and processed?CLOUD Act reach
You do not know where your data is stored and processed. US providers can move data anywhere. The CLOUD Act lets US authorities seize data from US providers anywhere in the world. Your EU data centre does not protect you.
Do you run AI and data workloads on infrastructure you own and control?DORA Article 28
You depend on external providers for AI and data workloads. DORA requires exit strategies. NIS2 requires supply chain control. The EU AI Act requires documented governance. You cannot demonstrate any of these when the capability is rented.
Do you have a documented breach notification procedure that meets DORA requirements?DORA Article 28
You do not have a documented breach notification procedure that meets DORA requirements. DORA requires incident notification to your supervisor. NIS2 requires 24 hour early warning for essential entities. If your ICT provider suffers a breach, you may not find out in time. Your management body is liable for late notification.
Why your board needs to see this
You cannot switch providers

DORA says you must have a plan to leave every critical provider. If your cloud goes down, can you move your data fast? Most companies cannot. Your regulator will ask for proof.

Big cloud will not let you audit

DORA gives you the right to audit your ICT providers. But big cloud companies will not change their contracts. You cannot check their security. That is a compliance gap you cannot fix.

Fine: EUR 10M or 2%

DORA fines go up to EUR 10 million or 2% of your global turnover. Your management body is liable. Your provider holds the keys. You carry the risk.

DORA applies directly to banks, insurers, payment institutions, and crypto asset providers. If you serve financial clients, DORA Article 28 contractual flow-down catches you too. Check your NIS2 exposure if you are an MSSP.

Worried about NIS2, DORA, AI Act or GDPR?

These regulations ask the same question. Who controls the systems you depend on. Our sovereign platform gives you the answer. You.

NIS2 Checklist AI Act Checklist GDPR Checklist

No sales pressure. A clear look at your numbers, your dependencies, and your options.