In one paragraph
DORA organises operational resilience for the financial sector around five pillars. NexCyber maps the entire framework, with particular focus on the ICT third-party register — the artefact that carries the most concrete and demanding data points.
The five pillars
1. ICT risk management
Governance and the full control loop: identify, protect, detect, respond and recover, learn.
NexCyber tracks: governance documents, ICT risk policy, asset inventory with criticality, detection and response runbooks, post-incident learning records.
2. ICT-related incident management, classification, and reporting
A documented incident management process with structured classification and reporting to competent authorities.
NexCyber tracks: incident policy, classification taxonomy, reporting playbook, sample notifications, intermediate and final reporting templates.
3. Digital operational resilience testing
A testing programme, including advanced threat-led penetration testing (TLPT) for significant entities.
NexCyber tracks: testing strategy, scope per cycle, test reports (high-level findings), remediation plans, TLPT engagement records where applicable.
4. ICT third-party risk management
Pre-contractual due diligence, contracts with mandated content, the register of contracts (the artefact below), exit strategies, continuous monitoring of critical providers.
NexCyber tracks: every data point of the register, supplier evidence locker, contract clause inventory, exit plans per critical provider, monitoring metrics.
5. Information and intelligence sharing
Optional but encouraged, with conditions on confidentiality and competition law.
NexCyber tracks: sharing arrangements, contributions made and received, derogations and approvals where applicable.
The ICT third-party register — what makes it different
The register is the most data-rich artefact under DORA. ESAs publish technical standards (ITS / RTS) defining the exact data points. NexCyber tracks them all as structured fields in the supplier inventory.
Data points per contract
- Contract reference and date.
- Name and identifier of the financial entity (LEI).
- Name and identifier of the ICT provider (LEI when available).
- Description of the ICT service.
- Whether the service supports a critical or important function.
- Substitutability assessment.
- Sub-contracting chain, with each sub-provider documented.
- Personal data processing involved.
- Location of data and operation.
- Whether the service is on-premises, in private cloud, in public cloud, or hybrid.
- Service level objectives.
- Termination notice and exit strategies.
- Right-to-audit clauses.
NexCyber surfaces each data point as a required field, gives you a per-field readiness indicator, and exports the register in a regulator-ready shape.
Critical or important function flag
This flag drives much of the regulatory treatment. NexCyber asks for a structured justification when you raise the flag, so the auditor sees not only the value but the rationale.
Sub-contracting depth
Sub-contractors of sub-contractors count. NexCyber stores the full chain as a tree, with each level carrying its own data points (where available).
Critical ICT third-party providers (CTPP)
Some providers will be designated CTPP by the ESAs. The designation triggers oversight at EU level and concentrates a set of obligations on the provider. If you are a financial entity, NexCyber lets you mark a provider as CTPP and track the corresponding oversight artefacts. If you are a CTPP yourself, the oversight pillar is its own workspace.
Testing programme
DORA expects a structured testing programme:
- Routine tests (vulnerability assessment, scenario-based, penetration testing).
- TLPT every three years for significant entities.
NexCyber tracks the programme, the scope per cycle, and the remediation flow. TLPT engagements are typically scheduled with external red teams; NexCyber stores the engagement artefacts (not the offensive details).
Incident reporting timelines
DORA aligns on timelines for major ICT-related incidents. The exact timings come from the regulator; NexCyber surfaces the timer when an incident is opened, and the reporting playbook references the active timeline.
Information sharing
Information sharing is optional but encouraged. NexCyber lets you record sharing arrangements, contributions, and derogations. Privacy and competition-law guard-rails are surfaced as evidence prompts.
Cross-regulation
- NIS2 — overlaps on ICT risk management and supply chain security. NexCyber maps evidence once.
- CRA — overlaps where the financial entity is also a manufacturer of digital products.
- AI Act — overlaps where AI is used for safety, decision-making, or critical functions.
Governance angle
DORA puts ICT risk at the management body's level. The governance pillar requires explicit accountability, regular reporting to the board, and training. NexCyber tracks the governance artefacts and the cadence.
What DORA via NexCyber does NOT do
- It does not file your major-incident report.
- It does not run TLPT.
- It does not negotiate exit clauses with your providers.
Common pitfalls
- Treating the register as a spreadsheet.
- Missing sub-contracting depth beyond first tier.
- Critical-function flagging without rationale.
- Exit strategies that exist only in slides.
- Testing programmes without remediation tracking.
Related articles
- DORA basics — wider picture.
- Supplier evidence basics — register data points overlap.
- What evidence should I prepare? — cross-regulation evidence list.
Next step
Open the DORA assessment in your workspace and start by completing the register data points for your top ten ICT providers.