Skip to content

Compliance

DORA: evidencing ICT risk management technically

DORA has applied to financial entities since 17 January 2025. blacklens.io underpins inventory, vulnerability scanning, third-party risk and testing; TLPT remains a separate procedure.

DORA evidenceas PDF
Asset inventoryDORA Art. 8continuous
Vulnerability scansRTS (EU) 2024/1774 Art. 10weekly
Supplier watchlistDORA Art. 28about every 30 min
Pentest reportDORA Art. 24 and 25after each test

What DORA requires

Regulation (EU) 2022/2554 applies directly, without national transposition. Four of its five pillars concern technology directly.

Art. 5 to 16

ICT risk management

Identify, protect and monitor assets; scans at least weekly for critical or important functions.

Art. 17 to 23

Handle and report incidents

Detect and classify ICT-related incidents and report major ones to the competent authority.

Art. 24 to 27

Test resilience

An ongoing testing programme, plus TLPT at least every three years for selected entities.

Art. 28 to 30

ICT third-party risk

Monitor providers, keep the register of information, include mandatory contract terms.

Technical guidance, not legal advice. Which obligations apply to you is for your legal department, auditor or supervisory authority to confirm.

DORA requirements mapped to blacklens.io

The mapping follows the regulation and the RTS on the ICT risk management framework (Delegated Regulation (EU) 2024/1774).

Art. 8

Newly discovered assets+4 since yesterday
beispiel-gmbh.atRoot domain
vpn.beispiel-gmbh.atFortiGate SSL-VPN 7.0.12Critical
dev-old.beispiel-gmbh.atGitLab 15.2Shadow ITHigh
mail.beispiel-gmbh.atExchange Server 2019Medium
203.0.113.24OpenSSH 8.9NewInfo

Visuals show sample data.

What implementation looks like

  1. 1

    Map critical functions

    Add domains, cloud accounts and network segments to the scope and mark them with tags.

  2. 2

    Set the scan cadence

    External continuously, cloud weekly, Sentry on schedule. Critical findings go to ICT risk management.

  3. 3

    Monitor third parties

    Import suppliers from the register of information as CSV and enable leak site matching.

  4. 4

    Automate evidence

    Reports monthly, pentest reports per cycle, query reports for supervisory questions.

TLPT: what blacklens.io does and does not do

Under Article 26, supervisors require TLPT from selected financial entities; it follows TIBER-EU and is carried out by testers qualified under Article 27. blacklens.io does not replace TLPT but supports before, between and after.

  • Preparation

    External attack surface inventory and dark web signals feed into the threat analysis.

  • Between cycles

    Scans and PTaaS support the regular testing programme under Article 25.

  • Follow-up

    TLPT findings run through the same workflow up to retest.

Compromised identities3 new hits
m.hu•••@beispiel-gmbh.atStealer log, 2 h agoEmployee
Microsoft 365 session cookieStealer log, 5 h agoEmployee
k.wa•••@gmx.atCombolist, 3 days agoCustomer

Frequently asked questions

DORA, Regulation (EU) 2022/2554, has applied directly since 17 January 2025 to financial entities within the meaning of Article 2: credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, trading venues, insurance and reinsurance undertakings, insurance intermediaries above a certain size, occupational pension institutions, credit rating agencies and others. ICT third-party providers designated as critical are additionally supervised directly. The proportionality principle in Article 4 allows implementation according to size and risk profile.

DORA evidence without spreadsheet upkeep

See in a demo how inventory, weekly scans and third-party monitoring are documented. Or start with your domains.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings