NEW · The Founders' Circle Grant — full-platform access for select companies. Redeem a grant →
Compliance · EU Financial

DORA ICT third-party risk, with the register built in.

QFX templates aligned to DORA Article 28 ICT service provider requirements. All ICT service providers assessed via Vendor Portal; results feed the DORA register required for regulatory reporting. Critical ICT third-party provider identification and concentration risk supported.

What DORA requires

How Verisq covers DORA.

EU Digital Operational Resilience Act · Application from 17 Jan 2025

Article 28 ICT third-party risk

All ICT service providers in scope, with contractual provisions evidence (Art. 30) and exit strategy documentation.

DORA register

Information register required by Art. 28(3) maintained continuously — generated for regulatory submission on demand.

Concentration risk analysis

Identifies critical and important functions provided by the same or affiliated ICT third-party providers.

Operational resilience testing

TLPT (Threat-Led Penetration Testing) evidence and digital operational resilience testing records preserved.

What you take to the audit

Outputs auditors and regulators expect.

DORA register export

Article 28(3) register in the format competent authorities request.

Critical third-party assessment

Per-provider documentation of criticality assessment under Art. 30.

Industries

DORA relevance.

Financial Services

Stop building DORA evidence in spreadsheets.

Verisq generates the artifacts your auditors and regulators expect — on demand, with current data, with framework mappings embedded.

See pricing Sign in to platform