Regulation · Filed · London · 9 min read

DORA Readiness: A Compliance Playbook for ICT Third-Party Risk

The Digital Operational Resilience Act became applicable in January 2025. What financial entities must have in place for ICT third-party risk, incident reporting, and testing.

By Cyber Inspect Editorial Board

The five DORA pillars

  • ICT risk management (governance and framework).
  • ICT-related incident reporting to competent authorities.
  • Digital operational resilience testing.
  • ICT third-party risk management with register of information.
  • Information and intelligence sharing.

The register of information

DORA introduces a mandatory register of ICT third-party arrangements to be submitted to competent authorities in a prescribed format. Stand this up now; retrofitting a register from procurement records is expensive.