Annex to the ActAnnex I - high-criticality sector
Competent CSIRTNational CERT
The measures that carry most of the work in this sector
03Risk management
DORA and the Regulation require the same risk register. Two methodologies mean two registers that diverge.
08Supply chain security
The DORA register of information on ICT provider contracts is the hardest part, and it fails on data quality, not on the rules.
11Incident handling
Notification to the competent CSIRT and DORA reporting run in parallel, with their own forms and deadlines.
12Business continuity
DORA requires resilience testing, which goes beyond a classical recovery plan.
What we most often find
- A register of information populated by hand from three unconnected sources - procurement, IT and finance
- Cloud provider contracts with no obligation to disclose subcontractors
- A risk register that does not cover third-party risk
- Recovery testing that is documented but never timed
Check for yourself
Tri alata koja rade u pregledniku, bez registracije:
Entity categorisation check
Incident reporting deadline calculator
Readiness check against the 13 measures
Not sure where you stand?
Half an hour of conversation, with no obligation. By the end you know what needs doing and in what order.