[{"data":1,"prerenderedAt":827},["ShallowReactive",2],{"globals":3,"article-dora-regulation-latest-articles-en":464,"article-article-dora-regulation":489},{"de":4,"en":193,"fr":347},{"id":5,"documentId":6,"titleSeparator":7,"title":8,"createdAt":9,"updatedAt":10,"publishedAt":11,"locale":12,"logo":13,"favicon":27,"seo":40,"navigation":48,"header":128,"footer":137,"videoPoster":160,"localizations":181},70,"nxlpiutyi22j347lzjvtcmt9","|","Cybervadis","2025-03-26T10:37:37.549Z","2026-06-23T08:53:06.827Z","2026-06-23T08:53:07.128Z","de",{"id":14,"documentId":15,"name":16,"alternativeText":17,"caption":17,"width":18,"height":19,"formats":17,"hash":20,"ext":21,"mime":22,"size":23,"url":24,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":26,"updatedAt":26,"publishedAt":26},276,"ns1dycmcy8eby82nudaixp17","logo.svg",null,303,57,"logo_9f7aa692ba",".svg","image/svg+xml",4.05,"https://assets.cybervadis.com/strapi/assets/logo_9f7aa692ba.svg","strapi-provider-upload-azure-storage","2025-04-10T15:46:43.920Z",{"id":28,"documentId":29,"name":30,"alternativeText":17,"caption":17,"width":31,"height":31,"formats":32,"hash":33,"ext":34,"mime":35,"size":36,"url":37,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":38,"updatedAt":39,"publishedAt":38},122,"ngfzwjibdex3knh7ftwqfvjx","favicon.png",32,{},"favicon_032a9b11b1",".png","image/png",0.5,"https://assets.cybervadis.com/strapi/assets/favicon_032a9b11b1.png","2025-02-25T09:03:35.564Z","2025-02-25T11:54:37.400Z",{"id":41,"metaDescription":17,"metaImage":17,"metaTags":42,"scripts":43},1707,[],[44,46],{"id":45,"src":17,"tagPosition":17,"innerHTML":17,"defer":17},123,{"id":47,"src":17,"tagPosition":17,"innerHTML":17,"defer":17},124,{"id":5,"links":49},[50,75,98,103],{"id":51,"label":52,"to":53,"external":17,"target":17,"icon":17,"children":54},311,"Third-Party Risiken reduzieren","/third-party-risiken-reduzieren",[55,59,63,67,71],{"id":56,"label":57,"to":58,"external":17,"target":17,"icon":17,"display":17},8311,"Automatisierte Risikoanalysen","/third-party-risiken-reduzieren/automatisierte-risikoanalysen",{"id":60,"label":61,"to":62,"external":17,"target":17,"icon":17,"display":17},8312,"Evidenzbasierte Risikobewertung","/third-party-risiken-reduzieren/evidenzbasierte-risikobewertung",{"id":64,"label":65,"to":66,"external":17,"target":17,"icon":17,"display":17},8313,"Gemeinsame Risikoreduzierung","/third-party-risiken-reduzieren/gemeinsame-risikoreduzierung",{"id":68,"label":69,"to":70,"external":17,"target":17,"icon":17,"display":17},8314,"Framework-basierte Methodik","/third-party-risiken-reduzieren/framework-basierte-methodik",{"id":72,"label":73,"to":74,"external":17,"target":17,"icon":17,"display":17},8315,"Preise","/third-party-risiken-reduzieren/preise",{"id":76,"label":77,"to":78,"external":17,"target":17,"icon":17,"children":79},312,"Jetzt bewertet werden","/jetzt-bewertet-werden",[80,84,88,92],{"id":81,"label":82,"to":83,"external":17,"target":17,"icon":17,"display":17},8316,"So funktioniert es","/jetzt-bewertet-werden/so-funktioniert-es",{"id":85,"label":86,"to":87,"external":17,"target":17,"icon":17,"display":17},8317,"Individuelle Bewertungen","/jetzt-bewertet-werden/individuelle-bewertungen",{"id":89,"label":90,"to":91,"external":17,"target":17,"icon":17,"display":17},8318,"CyberVadis Badges","/jetzt-bewertet-werden/cybervadis-badges",{"id":93,"label":94,"to":95,"external":96,"target":97,"icon":17,"display":17},8319,"Help center (EN)","https://help.cybervadis.com/en/",true,"_blank",{"id":99,"label":100,"to":101,"external":17,"target":17,"icon":17,"children":102},310,"Ressourcen","/ressourcen",[],{"id":104,"label":105,"to":106,"external":17,"target":17,"icon":17,"children":107},313,"Über uns","/uber-uns",[108,112,116,120,124],{"id":109,"label":110,"to":111,"external":17,"target":17,"icon":17,"display":17},8320,"Warum CyberVadis","/warum-cybervadis",{"id":113,"label":114,"to":115,"external":17,"target":17,"icon":17,"display":17},8321,"Trust Center (EN)","/uber-uns/trust-center",{"id":117,"label":118,"to":119,"external":96,"target":97,"icon":17,"display":17},8322,"Careers (EN)","https://careers.cybervadis.com/",{"id":121,"label":122,"to":123,"external":17,"target":17,"icon":17,"display":17},8323,"Aktuelles","/de/aktuelles",{"id":125,"label":126,"to":127,"external":17,"target":17,"icon":17,"display":17},8324,"Kontakt","/uber-uns/kontakt",{"id":5,"info":17,"login":129,"button":134},{"id":130,"label":131,"to":132,"external":133,"target":17,"icon":17,"display":17},8325,"Demo buchen","/de/demo-anfordern",false,{"id":135,"icon":17,"label":131,"form":136,"display":133},1228,"demo",{"id":5,"newsletterTitle":138,"copyright":139,"legalLinks":140,"socialLinks":149},"Newsletter abonnieren","Urheberrecht © 2025. Alle Rechte vorbehalten.",[141,145],{"id":142,"label":143,"to":144,"external":17,"target":17,"icon":17,"display":17},8326,"Rechtliche Hinweise (EN)","/de/legal",{"id":146,"label":147,"to":148,"external":17,"target":17,"icon":17,"display":17},8327,"Datenschutzerklärung (EN)","/de/legal-notice",[150,155],{"id":151,"label":152,"to":153,"external":96,"target":97,"icon":154,"display":17},8328,"X","https://x.com/cybervadis","fa6-brands:x-twitter",{"id":156,"label":157,"to":158,"external":96,"target":97,"icon":159,"display":17},8329,"LinkedIn","https://www.linkedin.com/company/cybervadis/","fa6-brands:linkedin",{"id":161,"documentId":162,"name":163,"alternativeText":17,"caption":17,"width":164,"height":165,"formats":166,"hash":175,"ext":34,"mime":35,"size":176,"url":177,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":178,"updatedAt":179,"publishedAt":180},242,"vrv61ssc0oc744hr7dgkqznu","Video Preview",1028,690,{"thumbnail":167},{"ext":34,"url":168,"hash":169,"mime":35,"name":170,"path":17,"size":171,"width":172,"height":173,"sizeInBytes":174},"https://assets.cybervadis.com/strapi/assets/thumbnail_Design_sans_titre_6_f21ca94567.png","thumbnail_Design_sans_titre_6_f21ca94567","thumbnail_Design sans titre (6).png",14.9,232,156,14897,"Design_sans_titre_6_f21ca94567",18.5,"https://assets.cybervadis.com/strapi/assets/Design_sans_titre_6_f21ca94567.png","2025-03-12T09:54:21.008Z","2025-03-12T09:54:35.444Z","2025-03-12T09:54:21.009Z",[182,188],{"id":183,"documentId":6,"titleSeparator":7,"title":8,"createdAt":184,"updatedAt":185,"publishedAt":186,"locale":187},68,"2025-02-19T11:28:33.351Z","2026-06-23T08:53:07.327Z","2026-06-23T08:51:33.204Z","en",{"id":189,"documentId":6,"titleSeparator":7,"title":8,"createdAt":190,"updatedAt":185,"publishedAt":191,"locale":192},69,"2025-06-17T20:29:42.853Z","2026-06-23T08:52:32.610Z","fr",{"id":183,"documentId":6,"titleSeparator":7,"title":8,"createdAt":184,"updatedAt":185,"publishedAt":186,"locale":187,"logo":194,"favicon":195,"seo":197,"navigation":226,"header":301,"footer":324,"videoPoster":341,"localizations":344},{"id":14,"documentId":15,"name":16,"alternativeText":17,"caption":17,"width":18,"height":19,"formats":17,"hash":20,"ext":21,"mime":22,"size":23,"url":24,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":26,"updatedAt":26,"publishedAt":26},{"id":28,"documentId":29,"name":30,"alternativeText":17,"caption":17,"width":31,"height":31,"formats":196,"hash":33,"ext":34,"mime":35,"size":36,"url":37,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":38,"updatedAt":39,"publishedAt":38},{},{"id":198,"metaDescription":17,"metaImage":199,"metaTags":218,"scripts":219},1705,{"id":200,"documentId":201,"name":202,"alternativeText":17,"caption":17,"width":203,"height":204,"formats":205,"hash":214,"ext":34,"mime":35,"size":215,"url":216,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":217,"updatedAt":217,"publishedAt":217},284,"ntditjqus6ubg59uwiew5zqu","meta image by default.png",1200,630,{"thumbnail":206},{"ext":34,"url":207,"hash":208,"mime":35,"name":209,"path":17,"size":210,"width":211,"height":212,"sizeInBytes":213},"https://assets.cybervadis.com/strapi/assets/thumbnail_meta_image_by_default_5c51d0a0d5.png","thumbnail_meta_image_by_default_5c51d0a0d5","thumbnail_meta image by default.png",64.36,245,129,64355,"meta_image_by_default_5c51d0a0d5",210.02,"https://assets.cybervadis.com/strapi/assets/meta_image_by_default_5c51d0a0d5.png","2025-04-17T14:53:22.089Z",[],[220,222,224],{"id":221,"src":17,"tagPosition":17,"innerHTML":17,"defer":17},118,{"id":223,"src":17,"tagPosition":17,"innerHTML":17,"defer":17},119,{"id":225,"src":17,"tagPosition":17,"innerHTML":17,"defer":17},120,{"id":183,"links":227},[228,252,272,277],{"id":18,"label":229,"to":230,"external":17,"target":17,"icon":17,"children":231},"Mitigate third-party risks","/mitigate-third-party-risks",[232,236,240,244,248],{"id":233,"label":234,"to":235,"external":17,"target":17,"icon":17,"display":17},8273,"Automated Risk Insights","/mitigate-third-party-risks/automated-risk-insights",{"id":237,"label":238,"to":239,"external":17,"target":17,"icon":17,"display":17},8274,"Evidence-based risk assessment","/mitigate-third-party-risks/evidence-based-risk-assessment",{"id":241,"label":242,"to":243,"external":17,"target":17,"icon":17,"display":17},8275,"Collaborative Risk Reduction","/mitigate-third-party-risks/risk-reduction",{"id":245,"label":246,"to":247,"external":17,"target":17,"icon":17,"display":17},8276,"Framework-based methodology","/mitigate-third-party-risks/framework-based-methodology",{"id":249,"label":250,"to":251,"external":17,"target":17,"icon":17,"display":17},8277,"Pricing","/mitigate-third-party-risks/pricing",{"id":253,"label":254,"to":255,"external":17,"target":17,"icon":17,"children":256},304,"Get assessed ","/get-assessed",[257,261,265,269],{"id":258,"label":259,"to":260,"external":17,"target":17,"icon":17,"display":17},8278,"How it works","/get-assessed/how-it-works",{"id":262,"label":263,"to":264,"external":17,"target":17,"icon":17,"display":17},8279,"Standardized Assessments","/get-assessed/tailored-and-standardized-assessment",{"id":266,"label":267,"to":268,"external":17,"target":17,"icon":17,"display":17},8280,"CyberVadis Medals","/get-assessed/medals",{"id":270,"label":271,"to":95,"external":96,"target":97,"icon":17,"display":17},8281,"Help center",{"id":273,"label":274,"to":275,"external":17,"target":17,"icon":17,"children":276},302,"Resources","/resources",[],{"id":278,"label":279,"to":280,"external":17,"target":17,"icon":17,"children":281},305,"About us ","/about-us",[282,286,290,293,297],{"id":283,"label":284,"to":285,"external":17,"target":17,"icon":17,"display":17},8282,"Why CyberVadis","/why-cybervadis",{"id":287,"label":288,"to":289,"external":17,"target":17,"icon":17,"display":17},8283,"Trust center","/about-us/trust-center",{"id":291,"label":292,"to":119,"external":96,"target":97,"icon":17,"display":17},8284,"Careers",{"id":294,"label":295,"to":296,"external":17,"target":17,"icon":17,"display":17},8285,"In the news","/in-the-news",{"id":298,"label":299,"to":300,"external":17,"target":17,"icon":17,"display":17},8286,"Contact","/about-us/contact",{"id":183,"info":302,"login":317,"button":321},[303],{"type":304,"children":305},"paragraph",[306,309,315],{"text":307,"type":308},"Already a CyberVadis client ? ","text",{"url":310,"type":311,"children":312},"https://app.cybervadis.com/","link",[313],{"text":314,"type":308},"You can access your account here",{"text":316,"type":308},"",{"id":318,"label":319,"to":320,"external":133,"target":17,"icon":17,"display":17},8287,"Book a demo","/request-a-demo",{"id":322,"icon":17,"label":319,"form":323,"display":133},1226,"demo-enterprise",{"id":183,"newsletterTitle":325,"copyright":326,"legalLinks":327,"socialLinks":336},"Subscribe to newsletter","Copyright © 2025. All rights reserved.",[328,332],{"id":329,"label":330,"to":331,"external":17,"target":17,"icon":17,"display":17},8288,"Legal mentions","/legal",{"id":333,"label":334,"to":335,"external":17,"target":17,"icon":17,"display":17},8289,"Data privacy","/legal-notice",[337,339],{"id":338,"label":152,"to":153,"external":96,"target":97,"icon":154,"display":17},8290,{"id":340,"label":157,"to":158,"external":96,"target":97,"icon":159,"display":17},8291,{"id":161,"documentId":162,"name":163,"alternativeText":17,"caption":17,"width":164,"height":165,"formats":342,"hash":175,"ext":34,"mime":35,"size":176,"url":177,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":178,"updatedAt":179,"publishedAt":180},{"thumbnail":343},{"ext":34,"url":168,"hash":169,"mime":35,"name":170,"path":17,"size":171,"width":172,"height":173,"sizeInBytes":174},[345,346],{"id":5,"documentId":6,"titleSeparator":7,"title":8,"createdAt":9,"updatedAt":10,"publishedAt":11,"locale":12},{"id":189,"documentId":6,"titleSeparator":7,"title":8,"createdAt":190,"updatedAt":185,"publishedAt":191,"locale":192},{"id":189,"documentId":6,"titleSeparator":7,"title":8,"createdAt":190,"updatedAt":185,"publishedAt":191,"locale":192,"logo":348,"favicon":349,"seo":351,"navigation":361,"header":434,"footer":441,"videoPoster":458,"localizations":461},{"id":14,"documentId":15,"name":16,"alternativeText":17,"caption":17,"width":18,"height":19,"formats":17,"hash":20,"ext":21,"mime":22,"size":23,"url":24,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":26,"updatedAt":26,"publishedAt":26},{"id":28,"documentId":29,"name":30,"alternativeText":17,"caption":17,"width":31,"height":31,"formats":350,"hash":33,"ext":34,"mime":35,"size":36,"url":37,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":38,"updatedAt":39,"publishedAt":38},{},{"id":352,"metaDescription":17,"metaImage":353,"metaTags":356,"scripts":357},1706,{"id":200,"documentId":201,"name":202,"alternativeText":17,"caption":17,"width":203,"height":204,"formats":354,"hash":214,"ext":34,"mime":35,"size":215,"url":216,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":217,"updatedAt":217,"publishedAt":217},{"thumbnail":355},{"ext":34,"url":207,"hash":208,"mime":35,"name":209,"path":17,"size":210,"width":211,"height":212,"sizeInBytes":213},[],[358,360],{"id":359,"src":17,"tagPosition":17,"innerHTML":17,"defer":17},121,{"id":28,"src":17,"tagPosition":17,"innerHTML":17,"defer":17},{"id":189,"links":362},[363,388,408,413],{"id":364,"label":365,"to":366,"external":17,"target":17,"icon":17,"children":367},307,"Atténuer les risques liés aux tiers","/attenuer-les-risques-lies-aux-tiers",[368,372,376,380,384],{"id":369,"label":370,"to":371,"external":17,"target":17,"icon":17,"display":17},8292,"Analyse automatisée des risques","/attenuer-les-risques-lies-aux-tiers/analyse-automatisee-des-risques",{"id":373,"label":374,"to":375,"external":17,"target":17,"icon":17,"display":17},8293,"Évaluation basée sur la revue de preuves","/attenuer-les-risques-lies-aux-tiers/evaluation-basee-sur-la-revue-de-preuves",{"id":377,"label":378,"to":379,"external":17,"target":17,"icon":17,"display":17},8294,"Réduction des riques","/attenuer-les-risques-lies-aux-tiers/reduction-des-risques",{"id":381,"label":382,"to":383,"external":17,"target":17,"icon":17,"display":17},8295,"Méthodologie basée sur un cadre de références","/attenuer-les-risques-lies-aux-tiers/methodologie-basee-sur-un-cadre-de-references",{"id":385,"label":386,"to":387,"external":17,"target":17,"icon":17,"display":17},8296,"Tarification","/attenuer-les-risques-lies-aux-tiers/tarification",{"id":389,"label":390,"to":391,"external":17,"target":17,"icon":17,"children":392},308,"Se faire évaluer","/se-faire-evaluer",[393,397,401,405],{"id":394,"label":395,"to":396,"external":17,"target":17,"icon":17,"display":17},8297,"Comment ça marche","/se-faire-evaluer/comment-ca-marche",{"id":398,"label":399,"to":400,"external":17,"target":17,"icon":17,"display":17},8298,"Évaluation standardisée","/se-faire-evaluer/evaluation-adaptee-et-standardisee",{"id":402,"label":403,"to":404,"external":17,"target":17,"icon":17,"display":17},8299,"Les médailles CyberVadis","/se-faire-evaluer/medailles",{"id":406,"label":407,"to":95,"external":96,"target":97,"icon":17,"display":17},8300,"Help Center (EN)",{"id":409,"label":410,"to":411,"external":17,"target":17,"icon":17,"children":412},306,"Ressources","/ressources",[],{"id":414,"label":415,"to":416,"external":17,"target":17,"icon":17,"children":417},309,"À propos","/a-propos",[418,422,425,427,431],{"id":419,"label":420,"to":421,"external":17,"target":17,"icon":17,"display":17},8301,"Pourquoi choisir CyberVadis","/pourquoi-choisir-cybervadis",{"id":423,"label":114,"to":424,"external":17,"target":17,"icon":17,"display":17},8302,"/a-propos/trust-center",{"id":426,"label":118,"to":119,"external":96,"target":97,"icon":17,"display":17},8303,{"id":428,"label":429,"to":430,"external":17,"target":17,"icon":17,"display":17},8304,"Actualités","/actualites",{"id":432,"label":299,"to":433,"external":17,"target":17,"icon":17,"display":17},8305,"/a-propos/contact",{"id":189,"info":17,"login":435,"button":439},{"id":436,"label":437,"to":438,"external":133,"target":17,"icon":17,"display":17},8306,"Réserver une démonstration","/demander-une-demo",{"id":440,"icon":17,"label":437,"form":136,"display":133},1227,{"id":189,"newsletterTitle":442,"copyright":443,"legalLinks":444,"socialLinks":453},"S'inscrire à la newsletter","Copyright © 2025. Tous droits réservés. ",[445,449],{"id":446,"label":447,"to":448,"external":17,"target":17,"icon":17,"display":17},8307,"Mentions légales (EN)","/fr/legal",{"id":450,"label":451,"to":452,"external":17,"target":17,"icon":17,"display":17},8308,"Confidentialité des données","/fr/legal-notice",[454,456],{"id":455,"label":152,"to":153,"external":96,"target":97,"icon":154,"display":17},8309,{"id":457,"label":157,"to":158,"external":96,"target":97,"icon":159,"display":17},8310,{"id":161,"documentId":162,"name":163,"alternativeText":17,"caption":17,"width":164,"height":165,"formats":459,"hash":175,"ext":34,"mime":35,"size":176,"url":177,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":178,"updatedAt":179,"publishedAt":180},{"thumbnail":460},{"ext":34,"url":168,"hash":169,"mime":35,"name":170,"path":17,"size":171,"width":172,"height":173,"sizeInBytes":174},[462,463],{"id":5,"documentId":6,"titleSeparator":7,"title":8,"createdAt":9,"updatedAt":10,"publishedAt":11,"locale":12},{"id":183,"documentId":6,"titleSeparator":7,"title":8,"createdAt":184,"updatedAt":185,"publishedAt":186,"locale":187},[465,470,474,479,484],{"id":466,"documentId":467,"title":468,"slug":469},92,"i7g1fcl68rkfq3tmeg2lqb0w","CyberVadis achieves ISO 27001 certification","cybervadis-achieves-iso27001certification",{"id":5,"documentId":471,"title":472,"slug":473},"ec2tyjm5615mnv64a17mrh67","DORA and Third-Parties Cyber Risks Management : A Structured Approach for Businesses ","dora-and-third-parties-cyber-risks-management",{"id":475,"documentId":476,"title":477,"slug":478},53,"m2rrd4lon01c6p2po0le8qmd","Secure 2024","article-secure-2024",{"id":480,"documentId":481,"title":482,"slug":483},102,"nbbyc7pkeeqhiz917sv5aik8","5 Key Steps to Mitigate Cyber Risks in Your Supply Chain","5-key-steps-to-mitigate-cyber-risks-in-your-supply-chain",{"id":485,"documentId":486,"title":487,"slug":488},100,"bb9sjmiykz7ulcu3vjzt3zck","Ensure NIS2 compliance for third-party management","ensure-nis-2-compliance-for-third-party-management",{"id":490,"documentId":491,"language":187,"title":492,"slug":493,"newsletter":96,"createdAt":494,"updatedAt":495,"publishedAt":496,"locale":187,"date":497,"description":498,"seo":499,"blockTableOfContents":17,"blocks":504,"localizations":822,"relatedArticles":826},163,"u8tmlc0e28hnmvuq9ic0uom2","DORA Regulation: Obligations, 5 Pillars and ICT Third-Party Risk Management","article-dora-regulation","2026-06-05T17:57:09.122Z","2026-06-16T07:18:40.985Z","2026-06-16T07:18:41.310Z","2026-06-08","The DORA regulation imposes strict obligations on EU financial entities regarding the management of ICT risks and their technology providers. Discover the 5 pillars, your obligations and how CyberVadis supports your compliance.",{"id":500,"metaDescription":501,"metaImage":17,"metaTags":502,"scripts":503},1617,"DORA has been in force since January 2025. Discover the 5 pillars, your obligations and the impact on your ICT providers. Complete CyberVadis guide.",[],[],[505,619,653,732,770,777],{"__component":506,"id":507,"anchor":17,"badge":17,"title":17,"description":508,"features":618,"link":17},"block.text",1626,[509,515,524,530,536,542,548,552,556,560,564,568,572,576,579],{"type":510,"level":511,"children":512},"heading",2,[513],{"text":514,"type":308},"Key takeaways",{"type":516,"format":517,"children":518},"list","unordered",[519],{"type":520,"children":521},"list-item",[522],{"text":523,"type":308},"DORA (Digital Operational Resilience Act) has been in force since 17 January 2025 for all EU financial entities",{"type":516,"format":517,"children":525},[526],{"type":520,"children":527},[528],{"text":529,"type":308},"The regulation rests on 5 pillars, including ICT third-party risk management, the most complex obligation to implement",{"type":516,"format":517,"children":531},[532],{"type":520,"children":533},[534],{"text":535,"type":308},"The entities concerned must maintain a register of all their ICT providers and assess their cybersecurity",{"type":516,"format":517,"children":537},[538],{"type":520,"children":539},[540],{"text":541,"type":308},"The fundamental difference with the GDPR: DORA addresses operational resilience, not personal data",{"type":516,"format":517,"children":543},[544],{"type":520,"children":545},[546],{"text":547,"type":308},"CyberVadis offers an evidence-based assessment that directly meets the requirements of Chapter V of DORA",{"type":304,"children":549},[550],{"text":551,"type":308},"The DORA regulation (Digital Operational Resilience Act) is a European regulatory text that requires financial entities to demonstrate their ability to withstand, respond to and recover from any incident linked to information and communication technology (ICT). In force since 17 January 2025, DORA applies to banks, insurers, payment institutions, asset management companies and other financial sector players operating in the European Union. Its distinctive feature: it places the management of ICT third-party providers at the heart of compliance obligations. CyberVadis helps security and compliance teams meet the requirements of Chapter V of DORA through supplier assessments validated by expert analysts.",{"type":510,"level":511,"children":553},[554],{"text":555,"type":308},"What is the DORA regulation?",{"type":304,"children":557},[558],{"text":559,"type":308},"DORA, an acronym for Digital Operational Resilience Act, is a European regulation adopted in December 2022 and applicable since 17 January 2025. It applies directly across the 27 Member States without requiring national transposition, an important distinction compared with directives such as NIS2.",{"type":304,"children":561},[562],{"text":563,"type":308},"Its objective is to ensure that financial entities can maintain their critical activities even in the event of serious ICT incidents: cyberattacks, system failures, breakdowns of technology providers. According to Recital 3 of the regulation, \"the EU financial sector increasingly relies on digital technologies and third-party undertakings for the provision of critical ICT services\".",{"type":304,"children":565},[566],{"text":567,"type":308},"This text is the first European regulation to address the operational digital resilience of the financial sector so comprehensively, covering both internal risk management and the management of ICT third-party risks.",{"type":510,"level":511,"children":569},[570],{"text":571,"type":308},"Who is concerned by DORA?",{"type":304,"children":573},[574],{"text":575,"type":308},"The entities subject to DORA cover a broad spectrum of the financial sector:",{"type":304,"children":577},[578],{"text":316,"type":308},{"type":516,"format":580,"children":581},"ordered",[582,586,590,594,598,602,606,610,614],{"type":520,"children":583},[584],{"text":585,"type":308},"Credit institutions (banks)",{"type":520,"children":587},[588],{"text":589,"type":308},"Payment and electronic money institutions",{"type":520,"children":591},[592],{"text":593,"type":308},"Investment firms",{"type":520,"children":595},[596],{"text":597,"type":308},"UCITS management companies and alternative investment fund managers",{"type":520,"children":599},[600],{"text":601,"type":308},"Insurance and reinsurance undertakings",{"type":520,"children":603},[604],{"text":605,"type":308},"Central counterparties and central securities depositories",{"type":520,"children":607},[608],{"text":609,"type":308},"Crypto-asset service providers (CASPs)",{"type":520,"children":611},[612],{"text":613,"type":308},"Credit rating agencies",{"type":520,"children":615},[616],{"text":617,"type":308},"Crowdfunding service providers",[],{"__component":506,"id":620,"anchor":17,"badge":17,"title":17,"description":621,"features":652,"link":17},1627,[622,626,630],{"type":510,"level":511,"children":623},[624],{"text":625,"type":308},"The 5 pillars of DORA",{"type":304,"children":627},[628],{"bold":96,"text":629,"type":308},"The DORA regulation is built around 5 fundamental pillars, each framed by specific articles of the text.",{"type":516,"format":580,"children":631},[632,636,640,644,648],{"type":520,"children":633},[634],{"text":635,"type":308},"The first pillar is ICT risk management. Entities must have a robust ICT risk management framework: policies, procedures, mapping of critical systems, business continuity and recovery plans. This framework must be approved and overseen by the management body (Chapter II).",{"type":520,"children":637},[638],{"text":639,"type":308},"The second pillar covers ICT incident management, classification and reporting. DORA requires a structured process for detecting, classifying and reporting ICT incidents to the competent authorities. Major incidents must be notified according to a strict timeline: initial notification (4 hours), intermediate report (72 hours), final report (1 month) (Chapter III).",{"type":520,"children":641},[642],{"text":643,"type":308},"The third pillar is digital operational resilience testing. Entities must test their ICT systems regularly: basic annual testing for all, and TLPT (Threat-Led Penetration Testing) every 3 years for entities of significant importance (Chapter IV)",{"type":520,"children":645},[646],{"text":647,"type":308},"The fourth pillar is ICT third-party risk management, the most structuring pillar for the majority of security teams. DORA requires maintaining a complete register of ICT providers, assessing their cybersecurity before contracting and on an ongoing basis, and including specific contractual clauses (Chapter V, see dedicated section below)",{"type":520,"children":649},[650],{"text":651,"type":308},"The fifth pillar is information sharing. DORA encourages financial entities to share cyber threat intelligence with one another, through voluntary information-sharing arrangements (Chapter VI).",[],{"__component":654,"id":655,"anchor":17,"size":656,"smallPadding":17,"badge":17,"title":17,"description":657,"fit":708,"align":709,"backgroundColor":710,"features":711,"link":17,"image":712},"block.text-image-with-editor",128,"md",[658,662,666,670,674,678,682,686,704],{"type":510,"level":511,"children":659},[660],{"text":661,"type":308},"What are the obligations of financial entities ?",{"type":304,"children":663},[664],{"text":665,"type":308},"Beyond the 5 pillars, DORA generates concrete operational obligations that compliance and security teams must implement.",{"type":304,"children":667},[668],{"text":669,"type":308},"On governance, the management body is directly responsible for the digital resilience strategy. Senior managers can be held personally liable in the event of a breach; a provision that has considerably increased the attention paid to DORA at the highest level.",{"type":304,"children":671},[672],{"text":673,"type":308},"On systems, entities must map their entire ICT estate, identify critical assets and maintain up-to-date documentation. According to a European Commission estimate, a mid-sized bank relies on average on more than 5,000 ICT providers, so the scope of the obligations is considerable.",{"type":304,"children":675},[676],{"text":677,"type":308},"On incidents, the notification timeline is non-negotiable: any entity that misses the deadlines exposes itself to sanctions from its competent national authority (ACPR in France, BaFin in Germany, for example).",{"type":510,"level":511,"children":679},[680],{"text":681,"type":308},"DORA and ICT third-party management: the central obligation",{"type":304,"children":683},[684],{"text":685,"type":308},"Chapter V of DORA is the one that generates the most operational work for security and procurement teams. It imposes four main obligations:",{"type":516,"format":580,"children":687},[688,692,696,700],{"type":520,"children":689},[690],{"text":691,"type":308},"The register of ICT providers: each entity must keep a complete and up-to-date register of all its ICT providers, with, for each one, a classification according to its criticality for the entity's essential functions. This register must be submitted to the supervisory authorities on request.",{"type":520,"children":693},[694],{"text":695,"type":308},"Prior and ongoing assessment: before contracting with a new ICT provider, the entity must assess its cybersecurity risks. This assessment must then be maintained on an ongoing basis; not only at the time of contracting. According to the IBM Cost of a Data Breach 2024 report, the average cost of a data breach involving a third party reaches 4.88 million dollars, which fully justifies the ongoing assessment obligation imposed by DORA.",{"type":520,"children":697},[698],{"text":699,"type":308},"Contractual obligations: DORA defines a list of mandatory clauses in contracts with ICT providers: right to audit, service levels (SLAs), exit plans, incident notification obligations. Existing contracts must be brought into compliance.",{"type":520,"children":701},[702],{"text":703,"type":308},"Critical ICT providers (CTPPs): for providers deemed critical at European level (designated by the supervisory authorities), DORA provides for a specific oversight framework. According to ENISA, incidents involving critical ICT providers increased by 42% between 2022 and 2024 in the European financial sector.",{"type":304,"children":705},[706],{"text":707,"type":308},"It is precisely on this Chapter V that CyberVadis intervenes. Our platform makes it possible to assess the cybersecurity posture of each ICT provider with evidence verified by our analysts, rather than a simple automated score, to meet the documentary requirements expected by supervisors.","object-cover","left","white",[],{"id":713,"documentId":714,"name":715,"alternativeText":17,"caption":17,"width":716,"height":717,"formats":718,"hash":726,"ext":34,"mime":35,"size":727,"url":728,"previewUrl":17,"provider":25,"provider_metadata":17,"createdAt":729,"updatedAt":730,"publishedAt":731},323,"dhptz5izh0emosypl365kni2","Screenshot 2026-06-04 at 17.35.17.png",1296,940,{"thumbnail":719},{"ext":34,"url":720,"hash":721,"mime":35,"name":722,"path":17,"size":723,"width":724,"height":173,"sizeInBytes":725},"https://assets.cybervadis.com/strapi/assets/thumbnail_Screenshot_2026_06_04_at_17_35_17_0c4b174601.png","thumbnail_Screenshot_2026_06_04_at_17_35_17_0c4b174601","thumbnail_Screenshot 2026-06-04 at 17.35.17.png",20.39,215,20394,"Screenshot_2026_06_04_at_17_35_17_0c4b174601",42.74,"https://assets.cybervadis.com/strapi/assets/Screenshot_2026_06_04_at_17_35_17_0c4b174601.png","2026-06-08T12:48:54.839Z","2026-06-15T09:55:51.940Z","2026-06-08T12:48:54.842Z",{"__component":506,"id":733,"anchor":17,"badge":17,"title":17,"description":734,"features":769,"link":17},1628,[735,739,743],{"type":510,"level":511,"children":736},[737],{"text":738,"type":308},"How to comply with DORA in 2026?",{"type":304,"children":740},[741],{"bold":96,"text":742,"type":308},"DORA compliance is organised around 6 concrete steps.",{"type":516,"format":580,"children":744},[745,749,753,757,761,765],{"type":520,"children":746},[747],{"text":748,"type":308},"The first step is to map ICT providers: build the exhaustive register of ICT providers (software publishers, hosting providers, cloud providers, maintenance providers) and classify each provider according to its criticality for the entity's essential functions.",{"type":520,"children":750},[751],{"text":752,"type":308},"The second step is to assess each provider's cybersecurity: for each identified provider, conduct a cybersecurity assessment. This assessment must go beyond the questionnaire: it must rely on evidence (certifications, audit reports, penetration tests) to be acceptable to supervisors.",{"type":520,"children":754},[755],{"text":756,"type":308},"The third step is to bring contracts into compliance: review all existing ICT contracts to incorporate the mandatory clauses defined in Article 30 of DORA (right to audit, SLAs, incident notification obligations, exit plans).",{"type":520,"children":758},[759],{"text":760,"type":308},"The fourth step is to set up the incident notification process: define the internal escalation chain and the process for notifying the authorities, and train teams on the regulatory deadlines (4 hours / 72 hours / 1 month).",{"type":520,"children":762},[763],{"text":764,"type":308},"The fifth step is to plan resilience testing: organise the annual testing programme and, for significant entities, prepare the triennial TLPTs.",{"type":520,"children":766},[767],{"text":768,"type":308},"The sixth step is to maintain on an ongoing basis. DORA compliance is not a one-off project. The provider register must be kept up to date, assessments renewed regularly, incidents documented. It is a permanent operational process, and this is where our fully managed service brings the most value: by automating the continuous monitoring of your ICT providers' security posture.",[],{"__component":771,"id":772,"size":656,"title":773,"description":774,"backgroundColor":775,"heading":776,"contactForm":17,"contactFormTitle":17,"form":17,"link":17,"button":17,"image":17},"block.cta",1043,"Want to know more?","CyberVadis supports financial entities across steps 1, 2 and 6: building and updating the ICT provider register, evidence-based cybersecurity assessments validated by certified analysts, and continuous monitoring. Unlike automated security ratings platforms, CyberVadis produces documented and auditable assessments; exactly what financial supervisors expect under DORA.","light-blue","h1",{"__component":778,"id":779,"headline":17,"title":780,"description":17,"backgroundColor":710,"items":781},"block.faq",505,"Questions fréquentes",[782,790,798,806,814],{"id":783,"label":784,"content":785},1784,"Q: What is the main objective of the DORA regulation?",[786],{"type":304,"children":787},[788],{"text":789,"type":308},"R : DORA vise à renforcer la résilience opérationnelle numérique du secteur financier européen. Il impose aux banques, assureurs et autres entités financières de démontrer qu'elles peuvent maintenir leurs activités critiques face à des incidents ICT graves, qu'ils soient d'origine interne ou liés à un prestataire technologique. DORA est en vigueur depuis le 17 janvier 2025.",{"id":791,"label":792,"content":793},1785,"Q: Which companies are exempt from applying DORA?",[794],{"type":304,"children":795},[796],{"text":797,"type":308},"A: Micro-enterprises (fewer than 10 employees and annual turnover below 2 million euros) benefit from a lighter regime. Certain entities such as sub-threshold alternative investment fund managers or small payment institutions may also benefit from partial exemptions. Entities outside the financial sector are not concerned by DORA.",{"id":799,"label":800,"content":801},1786,"Q: What is the date of application of DORA?",[802],{"type":304,"children":803},[804],{"text":805,"type":308},"A: DORA has been applicable since 17 January 2025 across all EU Member States. The entities concerned had to be compliant by that date. National supervisory authorities began their first compliance checks during 2025.",{"id":807,"label":808,"content":809},1787,"Q: Does DORA apply to ICT providers themselves?",[810],{"type":304,"children":811},[812],{"text":813,"type":308},"R : Oui, indirectement. Les prestataires ICT qui fournissent des services à des entités financières sont soumis aux clauses contractuelles imposées par DORA (Article 30) : droit d'audit, obligations de notification d'incident, SLA. Les prestataires ICT désignés \"critiques\" au niveau européen font l'objet d'un cadre de surveillance direct par les autorités de supervision.",{"id":815,"label":816,"content":817},1788,"Q: What is the difference between DORA and NIS2 for a financial institution?",[818],{"type":304,"children":819},[820],{"text":821,"type":308},"R : Un établissement financier peut être concerné par les deux textes. DORA est lex specialis : en cas de conflit, DORA prévaut sur NIS2 pour les entités financières. En pratique, une conformité DORA bien construite couvre et dépasse les exigences NIS2 pour le secteur financier.",[823],{"id":824,"documentId":491,"slug":825,"locale":192},184,"article-reglementation-dora",[],1782395078297]