Regulation · Filed · London · 9 min read
DORA Readiness: A Compliance Playbook for ICT Third-Party Risk
The Digital Operational Resilience Act became applicable in January 2025. What financial entities must have in place for ICT third-party risk, incident reporting, and testing.
By Cyber Inspect Editorial Board
The five DORA pillars
- ICT risk management (governance and framework).
- ICT-related incident reporting to competent authorities.
- Digital operational resilience testing.
- ICT third-party risk management with register of information.
- Information and intelligence sharing.
The register of information
DORA introduces a mandatory register of ICT third-party arrangements to be submitted to competent authorities in a prescribed format. Stand this up now; retrofitting a register from procurement records is expensive.