Skip to content
Secantra

Solution · DORA

DORA compliance on the record you already keep

Regulation (EU) 2022/2554 has applied since 17 January 2025 to financial entities and their critical ICT third-party providers. Secantra maps its ICT risk-management, incident, resilience-testing and third-party requirements onto your assets, controls and evidence — one adoption, one posture.

At a glance
Instrument
Regulation (EU) 2022/2554
Applies from
17 January 2025
Who
Banks, insurers, investment firms, payment & e-money institutions, crypto-asset service providers, ICT third-party providers
Supervision
National competent authorities; ESAs for critical ICT third-party providers

Mapping

What DORA asks — and where it lives in Secantra

Status is stated honestly: LIVE is in the product today, PARTLY means the data model supports it but a workflow is not in the current release, PLANNED means not yet. Frameworks ship as curated, versioned libraries (ISO/IEC 27001 Annex A 93 requirements, DORA 29, NIS2 21 today) that you extend with tenant requirements — not verbatim reproductions of the legal text.

What DORA asks — and where it lives in Secantra
DORA areaArticlesWhat is expectedIn SecantraStatus
ICT risk management frameworkArt. 5–16A documented, board-owned framework: identification, protection, detection, response, recovery, learning.Requirements adopted per article; controls mapped; posture derived; governance documents for the framework itself.LIVE
ICT-related incident managementArt. 17–23Classify incidents, report major ones to the authority on the prescribed timeline.Procedures and classification criteria as governance documents; findings for gaps. A dedicated incident workflow is not in the current release.PARTLY
Digital operational resilience testingArt. 24–27A testing programme proportionate to size and risk; TLPT for significant entities.Test evidence attached to controls with recency rules; gaps raised as findings with owners and dates.LIVE
ICT third-party riskArt. 28–30Manage risk from ICT providers across the contract lifecycle; key contractual provisions.Third-party registry linked to the assets and services each provider supports; risks per supplier in the register. Contract records are not in the current release.PARTLY
Register of informationArt. 28(3)Maintain a register of all contractual arrangements on the use of ICT services.Providers, the ICT services they deliver and the functions they support are linked records — the data the register is built from.PARTLY
Information-sharing arrangementsArt. 45Exchange cyber-threat information and intelligence within trusted communities.Arrangements documented as governance documents; automated ingestion of shared intelligence is not in the current release.PLANNED

How it runs

A DORA programme in Secantra

  • 01

    Adopt DORA v1.x

    Pin the published version; mark applicability per article for your entity type and size.

  • 02

    Map assets and providers

    Business solutions, the ICT services under them, and the third parties that supply them.

  • 03

    Attach controls and evidence

    Framework documents, test results, provider assessments — with recency rules.

  • 04

    Show it from the record

    Posture snapshots, open findings, overdue reviews — and generated reports from the record: framework status, risk register, executive summary.

Questions DORA teams ask

Is Secantra a substitute for the register of information template?

No. The ESAs prescribe the register format. Secantra holds the linked records the register is built from, so the data is consistent and current when you produce it.

Does it cover the incident-reporting timelines?

Classification criteria and procedures are handled as governance documents today; a dedicated incident workflow is not in the current release. We say so on the page rather than imply it.

We are a small entity — does the simplified framework apply?

Applicability is decided per requirement, so a proportionate scope is a first-class setting, not a workaround.

See it on your own frameworks

A walkthrough on a workspace set up for your sector. No trial sign-up, no credit card.