Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- What does the Digital Operational Resilience Act (DORA) require?
- How do I implement an ICT - risk - management framework?
- How should I classify and report major ICT - related incidents?
- How do I maintain a Register of Information (RoI) for ICT - third - party contracts?
- What is required for ICT - third - party risk management?
- How often must I conduct digital operational - resilience testing?
- What contractual clauses must I include with ICT - TPPs?
- Is participation in information - sharing arrangements mandatory?
- How does oversight of Critical ICT - Third - Party Providers (CTPPs) work?
- What governance and senior - management responsibilities are required?
- What are the penalties for non - compliance and the enforcement timeline?
- Quick starter checklist (derived from the sources)
Key takeaways
- DORA mandates an ICT - risk - management framework approved by the board.
- Major ICT incidents must be reported within 4 hours, 72 hours and one month.
- Maintain a Register of Information (RoI) for all ICT - third - party contracts.
- Perform due - diligence and embed Article 30 clauses in every ICT - TPP contract.
- Conduct annual basic testing and, for significant entities, a Threat - Led Penetration Test every three years.
- Governance, senior - management accountability and penalties are clearly defined.
What does the Digital Operational Resilience Act (DORA) require?
DORA requires financial and crypto - asset firms to establish a comprehensive ICT - risk - management framework, report major incidents quickly, and manage third - party risk throughout the supply chain. The regulation is laid out in Regulation (EU) 2022/2554 and supporting RTS documents.
The core obligations are summarized in ten numbered requirements (see the checklist below). Each requirement maps to specific articles of the regulation and to publicly available guidance.
How do I implement an ICT - risk - management framework?
Start by drafting a policy that covers identification, protection, detection, response and recovery of ICT risks, then obtain board approval and embed the framework in the overall enterprise risk - management program.
Concrete steps
- Inventory all ICT assets and map them to critical business functions.
- Define risk - tolerance levels and control objectives.
- Assign a risk - owner for each asset.
- Document governance processes in a policy document.
- Hold a board meeting, record minutes approving the framework, and schedule quarterly reviews.
How should I classify and report major ICT - related incidents?
Classify an incident as “major” when it threatens the continuity of a critical function, causes significant data loss, or impacts a large number of users. Once classified, notify the competent authority within four hours, submit an interim report within 72 hours, and deliver a final root - cause analysis within one month.
Concrete steps
- Create an incident - classification matrix aligned with Articles 17 - 23.
- Build a reporting SOP that includes templates for initial, intermediate and final reports.
- Automate alerts to trigger the 4 - hour notification timer.
- Conduct tabletop exercises quarterly to test the process.
How do I maintain a Register of Information (RoI) for ICT - third - party contracts?
The RoI is a complete, up - to - date inventory of every ICT - third - party contract, including subcontractors, service criticality, concentration risk and identifiers. It must be ready for regulator request at any time.
Concrete steps
- Create a spreadsheet or database with columns for provider name, contract ID, service description, criticality rating, concentration risk, and ESG compliance.
- Populate the register during the onboarding of each new provider.
- Schedule a monthly review to reconcile the register with procurement records.
- Store the register in a read - only location accessible to compliance officers and auditors.
What is required for ICT - third - party risk management?
Before signing a contract, perform due - diligence covering business reputation, security standards, sub - contractor use, third - country risks, audit rights and ESG compliance (Article 6). After onboarding, continuously monitor performance and embed exit - strategy clauses (Article 30).
Concrete steps
- Use a standardized questionnaire that maps to each Article 6 sub - clause.
- Require providers to supply SOC 2 or ISO 27001 reports.
- Implement a dashboard to track SLA compliance and security incident frequency.
- Include termination notice periods and data - return obligations in the contract.
How often must I conduct digital operational - resilience testing?
All entities must perform at least annual basic testing, such as vulnerability assessments and scenario - based exercises. Significant entities must add a Threat - Led Penetration Test (TLPT) every three years, involving critical ICT - TPPs.
Concrete steps
- Schedule a quarterly vulnerability scan using an approved tool.
- Design a scenario - based test that simulates a ransomware attack on a critical service.
- For TLPT, engage an external assessor, share the scope, and ensure participation of any designated critical ICT - TPPs.
- Document findings, remediate within defined timelines, and update the risk - management framework.
What contractual clauses must I include with ICT - TPPs?
Contracts must contain audit rights, a right to test, service - level targets, data - protection obligations, exit - strategy provisions, concentration - risk limits and ESG clauses as required by Article 30.
Concrete steps
- Add a clause granting the firm the right to perform on - site or remote security audits.
- Specify maximum downtime and recovery time objectives.
- Require data - encryption at rest and in transit.
- Define a clear hand - over process for data and services upon termination.
Is participation in information - sharing arrangements mandatory?
Participation is optional but encouraged. Joining industry - wide cyber - threat - intelligence platforms helps meet the spirit of Articles 19 - 20 and demonstrates proactive resilience.
Concrete steps
- Register with a recognized information - sharing body (e.g., FS - ISAC).
- Document the participation agreement and store it in the RoI.
- Integrate threat feeds into the SIEM for automated correlation.
How does oversight of Critical ICT - Third - Party Providers (CTPPs) work?
Regulators may designate certain providers as “critical” (Articles 31 - 44). Critical CTPPs face direct ESA oversight, fees and possible remediation orders.
Concrete steps
- Monitor EU regulator publications for designation notices.
- If a provider becomes a CTPP, perform an additional audit and submit the results to the competent authority.
- Allocate budget for potential oversight fees and remediation costs.
What governance and senior - management responsibilities are required?
The management body must approve the ICT - risk - management framework, allocate sufficient resources, and demonstrate knowledge of ICT risks (Articles 5 (2) and 13 (6)).
Concrete steps
- Record board approval in meeting minutes and store them with governance evidence.
- Provide quarterly training for senior managers on ICT risk trends.
- Include ICT risk metrics in the executive dashboard reviewed by the board.
What are the penalties for non - compliance and the enforcement timeline?
Full compliance is required by 17 January 2025. Penalties can reach up to 2 % of worldwide turnover for financial entities, €1 million for individuals, and up to €5 million or 1 % of daily turnover for critical ICT - TPPs.
Concrete steps
- Conduct a gap analysis now to estimate compliance effort.
- Model potential fines using projected turnover to justify budgeting for remediation.
- Establish a remediation fund to cover unexpected enforcement costs.
Quick starter checklist (derived from the sources)
- ☐ ICT risk - management policy & board approval (Art 5 - 15) - [EIOPA]
- ☐ Incident - classification matrix & reporting SOP (Art 17 - 23) - [Bitsight]
- ☐ Register of Information populated & validated (Art 28) - [3rdRisk]
- ☐ Third - party due - diligence questionnaire covering Article 6 (a - f) - [EU RTS]
- ☐ Contracts contain all Article 30 elements (audit rights, exit, concentration) - [EU RTS]
- ☐ Annual basic testing plan + TLPT schedule (if “significant”) - [IBM]
- ☐ Information - sharing participation documented (optional) - [Navex]
- ☐ Governance evidence (board minutes, training records) - [Matproof]
- ☐ Penalty - risk assessment & budget for potential fines - [Vanta]
For deeper guidance on each requirement, see the linked sources in the table above.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.