Guides for ICT suppliers to EU financial entities
Four references on what DORA does to an ICT supplier: the addendum, the classification behind it, threat-led testing and the audit and evidence cycle that follows.
- The DORA contract addendum Fifteen mandatory elements, two clause sets, and one determination that decides which of them binds you. How to read the document your bank customer sent, in the order that matters. Read
- Critical or important function One assessment your customer makes before signing decides whether your contract carries nine clauses or fifteen. What the definition measures, who decides, and how to argue it. Read
- TLPT participation What Article 30(3)(d) actually obliges you to do, how long an active red team phase runs, why your own SOC is not told, and the Article 26(4) route where you contract the tester and hold the schedule. Read
- Audit rights and evidence What you granted when you signed Article 30(3)(e), why your ISO certificate is expressly not enough, and how to build one evidence pack that answers every financial customer instead of one each. Read