Compliance
DORA: evidencing ICT risk management technically
DORA has applied to financial entities since 17 January 2025. blacklens.io underpins inventory, vulnerability scanning, third-party risk and testing; TLPT remains a separate procedure.
What DORA requires
Regulation (EU) 2022/2554 applies directly, without national transposition. Four of its five pillars concern technology directly.
ICT risk management
Identify, protect and monitor assets; scans at least weekly for critical or important functions.
Handle and report incidents
Detect and classify ICT-related incidents and report major ones to the competent authority.
Test resilience
An ongoing testing programme, plus TLPT at least every three years for selected entities.
ICT third-party risk
Monitor providers, keep the register of information, include mandatory contract terms.
Technical guidance, not legal advice. Which obligations apply to you is for your legal department, auditor or supervisory authority to confirm.
DORA requirements mapped to blacklens.io
The mapping follows the regulation and the RTS on the ICT risk management framework (Delegated Regulation (EU) 2024/1774).
Art. 8
Art. 9; RTS Art. 10
Art. 10; Art. 17 to 19
- CVE published08:12
- 2 assets in your inventory affected09:00
- Confirmed by PoC scan09:26
- Alert sent to Microsoft Teams09:27
Art. 24 and 25
Art. 28 to 30
Visuals show sample data.
What implementation looks like
- 1
Map critical functions
Add domains, cloud accounts and network segments to the scope and mark them with tags.
- 2
Set the scan cadence
External continuously, cloud weekly, Sentry on schedule. Critical findings go to ICT risk management.
- 3
Monitor third parties
Import suppliers from the register of information as CSV and enable leak site matching.
- 4
Automate evidence
Reports monthly, pentest reports per cycle, query reports for supervisory questions.
TLPT: what blacklens.io does and does not do
Under Article 26, supervisors require TLPT from selected financial entities; it follows TIBER-EU and is carried out by testers qualified under Article 27. blacklens.io does not replace TLPT but supports before, between and after.
Preparation
External attack surface inventory and dark web signals feed into the threat analysis.
Between cycles
Scans and PTaaS support the regular testing programme under Article 25.
Follow-up
TLPT findings run through the same workflow up to retest.
Frequently asked questions
- DORA, Regulation (EU) 2022/2554, has applied directly since 17 January 2025 to financial entities within the meaning of Article 2: credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, trading venues, insurance and reinsurance undertakings, insurance intermediaries above a certain size, occupational pension institutions, credit rating agencies and others. ICT third-party providers designated as critical are additionally supervised directly. The proportionality principle in Article 4 allows implementation according to size and risk profile.
Related pages
DORA evidence without spreadsheet upkeep
See in a demo how inventory, weekly scans and third-party monitoring are documented. Or start with your domains.
- 14 days free, all features
- No credit card required
- We walk you through your first findings