Kaamos

Framework reference

DORA for EU B2B software companies.

DORA applies to EU financial entities and ICT third-party providers serving them. For software companies, it becomes important when the company sells to banks, insurers, payment institutions, investment firms, crypto-asset service providers, or other regulated financial customers.

Kaamos support
Supported in Kaamos
Category
Binding EU regulations
Obligation
Binding
Last updated

The obligation, in the act's words

Financial entities shall have a sound, comprehensive and well-documented ICT risk management framework as part of their overall risk management system, which enables them to address ICT risk quickly, efficiently and comprehensively and to ensure a high level of digital operational resilience.

Article 6(1), Regulation (EU) 2022/2554 (DORA)

Well-documented is an obligation in its own right: the framework has to exist on paper, be current, and connect to the systems it governs.

Who it applies to

  • EU financial entities and regulated fintech companies.
  • ICT vendors that support financial entities.
  • B2B software suppliers facing DORA due diligence from financial-sector customers.

What you need to do

  • ICT risk management, incident reporting, resilience testing, vendor oversight, and continuity planning.
  • Clear records of critical ICT dependencies and risk treatment decisions.
  • Evidence that controls and recovery processes are tested and maintained.

How Kaamos helps

  • Track ICT risk, incident response, resilience testing and supplier oversight.
  • Assign control owners and retain the documents behind supplier reviews.
  • Export controls, evidence and mappings for your audit preparation.

Sources

Company profiles this applies to

Supported in Kaamos

Manage DORA controls, owners and evidence in Kaamos. Talk to us about the framework scope and connected systems you need.