Framework

DORA, with the ICT register done for you

In force since January 2025, DORA reaches every financial entity and all of their ICT providers. OptiTech covers ICT risk management, incident reporting, and produces the register of information as a supervisor-ready export.

  • Jan 2025

    DORA in force

  • ICT register

    Register of information, ready to export

  • All providers

    ICT suppliers in scope, not just banks

DORA pulls in the whole supply chain

  • Providers must prove it too

    It is not only banks. Every ICT provider to a financial entity is now asked for evidence.

  • The ICT register is mandatory

    A formal register of information for ICT contracts, in a supervisor-ready format.

  • Resilience must be tested

    Operational resilience and continuity have to be demonstrated, not assumed.

How OptiTech gets you compliant

  1. 01

    Map ICT risk

    Structured ICT risk management linked to controls and evidence.

  2. 02

    Register your ICT contracts

    Capture providers and contracts, with the fields DORA expects.

  3. 03

    Report and export

    A DORA incident report flow and the register of information as a ready export.

What OptiTech gives you for DORA

  • ICT risk management

    Risk linked to controls, evidence, and treatment.

  • Register of information

    The ICT contract register produced for supervisors.

  • DORA incident reports

    Structured reporting with schema validation and export.

  • Third-party risk

    Provider classification, substitutability, and exit plans.

DORA turned "trust your provider" into "prove your provider." The register of information is the receipt.
OptiTech, Product principle

Questions

  • Very possibly. DORA reaches financial entities and all of their ICT providers, so many technology suppliers are in scope.
  • Yes. The ICT contract register is generated as a supervisor-ready export from your vendor and contract data.
  • Yes. There is a structured DORA incident report flow with schema validation and export.
  • They overlap on risk and incidents. Controls are cross-mapped, so evidence you collect for one counts toward the other.
Framework

Get DORA-ready, register included

From ICT risk to the register of information.

Book a free gap analysis