DORA is in force. Your ICT risk framework needs to be too.
The Digital Operational Resilience Act became enforceable on January 17, 2025. Financial entities operating in the EU must now demonstrate ICT risk management, incident reporting, resilience testing, and third-party oversight—or face supervisory sanctions. Sentrix is one of the few platforms that treats DORA as a first-class framework, not an afterthought module.
ICT risk. Third-party oversight. Resilience testing. All documented. All continuous.
DORA applies to credit institutions, payment institutions, investment firms, insurance companies, crypto-asset service providers, and their critical ICT third-party providers. The regulation requires a documented ICT risk framework, a register of all ICT third-party arrangements, major incident classification and reporting to competent authorities, and an annual digital operational resilience testing programme.
- Chapter II: ICT risk management framework with Board-level accountability
- Chapter III: Major ICT incident classification, reporting, and root cause analysis
- Chapter IV: Digital operational resilience testing including TLPT for significant entities
- Chapter V: ICT third-party risk management and register of all contractual arrangements
- Chapter VI: Information and intelligence sharing arrangements
DORA compliance · Article coverage
LIVE MONITORINGICT third-party register · DORA Art. 28
CONTINUOUSDORA Article 28: your ICT register cannot be a spreadsheet.
DORA requires a complete, continuously maintained register of all ICT third-party arrangements, including sub-outsourcing chains, concentration risk analysis, and contractual clause compliance. Sentrix builds this register automatically from your vendor data and monitors it continuously—flagging contractual gaps, expired certifications, and concentration risk before your supervisor does.
- Full ICT third-party inventory with criticality classification and sub-outsourcing chains
- Art. 30 contractual clause tracking—exit strategy, audit rights, incident notification
- Concentration risk analysis across CTP and non-CTP service providers
- Supervisory-ready register export in the format required by your competent authority
Every DORA pillar. One platform. Audit-ready always.
ICT risk framework documentation
Board-approved ICT risk policy, risk tolerance statements, and risk management procedures required by Articles 5–16. Pre-built templates adapted to your entity type and supervisory jurisdiction.
Incident classification & reporting
DORA incident classification matrix (major vs. significant), 4-hour initial notification timer, 72-hour intermediate report, and final root cause analysis—all workflow-automated with regulatory templates.
TLPT programme management
Threat-Led Penetration Testing programme tracking for significant entities. Test scheduling, scope documentation, tester credential verification, and remediation tracking in the format expected by the Joint Committee of ESAs.
Concentration risk analysis
DORA requires analysis of ICT concentration risk. Sentrix automatically identifies single points of failure in your ICT supply chain and generates the concentration risk report required for supervisory examinations.
NIS2 crosswalk
Financial entities subject to both DORA and NIS2 manage both from one Sentrix program. The 30%+ control overlap is mapped automatically—no duplicate evidence collection, no duplicate frameworks.
Board reporting
DORA places ICT risk accountability at Board level. Sentrix generates board-ready ICT risk dashboards, incident summaries, and third-party risk reports in the format financial regulators expect to see.
See your DORA compliance posture live.
We map your ICT framework and third-party register in the demo before the call ends.