{"id":48828,"date":"2026-06-08T14:29:37","date_gmt":"2026-06-08T11:29:37","guid":{"rendered":"https:\/\/trueconf.com/blog\/?p=48828"},"modified":"2026-09-15T11:43:51","modified_gmt":"2026-09-15T08:43:51","slug":"dora-regulation","status":"publish","type":"post","link":"https:\/\/trueconf.com/blog\/reviews-comparisons\/dora-regulation","title":{"rendered":"DORA Regulation: Requirements, Risks and Compliance"},"content":{"rendered":"<p class=\"primary-medium-text ui-mb-sm-1\"><em>The Digital Operational Resilience Act (DORA)<\/em>, Regulation (EU) 2022\/2554, establishes EU-wide requirements for the digital operational resilience of financial entities. It covers <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/cybersecurity-for-government-applications\" target=\"_blank\" rel=\"noopener\">ICT risk management<\/a>, major ICT-related incident reporting, resilience testing, ICT <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/nis2-requirements-for-platforms\" target=\"_blank\" rel=\"noopener\">third-party risk<\/a>, and voluntary <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/sovereign-messaging-platform\" target=\"_blank\" rel=\"noopener\">information sharing<\/a>, with additional oversight applying to designated critical ICT third-party service providers.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA has applied since 17 January 2025. As an EU regulation, it is directly applicable across Member States, while supervision and sanctions are carried out by the competent authorities identified under DORA and relevant national frameworks.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA places responsibility for the ICT risk-management framework on the management body of the financial entity, making digital operational resilience a governance responsibility rather than an IT-only issue.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/secure-communication-platform-for-enterprises\" target=\"_blank\" rel=\"noopener\">Communication infrastructure<\/a> can form part of this framework when it supports financial services, <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/out-of-band-communication\" target=\"_blank\" rel=\"noopener\">incident response<\/a>, or <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/business-continuity-management\" target=\"_blank\" rel=\"noopener\">critical or important functions<\/a>.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Article 14 of DORA requires financial entities to maintain <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/business-continuity-communication-tool\" target=\"_blank\" rel=\"noopener\">crisis communication<\/a> plans for responsible disclosure of major ICT-related incidents or vulnerabilities to clients, counterparts, and the public as appropriate. Communication channels used for crisis coordination should therefore be assessed within the institution&#8217;s ICT risk and continuity planning.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA does not automatically classify every communication platform as critical infrastructure. The applicable controls depend on how the platform is used, whether it supports a critical or important function, and whether it is provided under a contractual arrangement with an ICT third-party service provider.<\/p>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Executive Summary: DORA at a Glance<\/h2>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Question<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Direct Answer<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>What is DORA?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Regulation (EU) 2022\/2554, a directly applicable EU law requiring financial entities to manage ICT risk, report major ICT-related incidents, test resilience, and manage ICT third-party risk; it also establishes an oversight framework for designated critical ICT third-party service providers<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>When did DORA become applicable?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">It entered into force on 16 January 2023 and has applied across the EU since 17 January 2025<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Who does DORA apply to?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">The financial entities listed in Article 2, including banks, insurers, investment firms, payment institutions, electronic money institutions, and certain crypto-asset market participants<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>What are the five core areas?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing arrangements<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Who is accountable?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">The management body remains responsible for defining, approving, overseeing, and implementing the ICT risk-management framework<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Why do communication platforms matter?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/enterprise-video-conferencing\" target=\"_blank\" rel=\"noopener\">Video conferencing<\/a> and <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/secure-messengers\" target=\"_blank\" rel=\"noopener\">messaging platforms<\/a> should be assessed when they are used as ICT services by a financial entity, with additional requirements applying where they support critical or important functions<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Does <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/self-hosted-video-conferencing\" target=\"_blank\" rel=\"noopener\">self-hosting<\/a> remove DORA third-party risk?<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">No. Deployment architecture can change the dependency model, but contracted software, support, maintenance, updates, and integrations can remain relevant ICT third-party dependencies<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">DORA Compliance Responsibilities by Role<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA becomes easier to interpret when responsibilities are separated between governance, operational teams, and external ICT providers. Outsourcing an ICT service does not transfer the financial entity&#8217;s responsibility for managing the associated risk.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Role<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Primary Responsibility<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Communication Platform Relevance<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Management body<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Defines, approves, oversees, and remains responsible for the ICT risk-management framework<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Ensures communication infrastructure is governed according to its role, risks, and criticality<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong><a href=\"https:\/\/trueconf.com\/blog\/productivity\/communication-security\" target=\"_blank\" rel=\"noopener\">ICT and security teams<\/a><\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Implement risk controls, monitoring, incident response, testing, recovery, and technical safeguards<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Assess architecture, <a href=\"https:\/\/trueconf.com\/docs\/server\/en\/admin\/security\/\" target=\"_blank\" rel=\"noopener\">access control<\/a>s, logs, dependencies, resilience, and recovery procedures<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Procurement and legal teams<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Manage contractual ICT-service requirements and exit provisions<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Review hosting, support, maintenance, <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/data-residency\" target=\"_blank\" rel=\"noopener\">data locations<\/a>, audit rights, service levels, and transition clauses<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>ICT third-party provider<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Fulfils contractual obligations and provides information required by the financial entity<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">May provide messaging, video conferencing, maintenance, cloud hosting, support, or related ICT services<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Critical ICT Third-Party Provider<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Subject to the DORA oversight framework after designation<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Additional ESA oversight applies at provider level<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><strong>Insight 1. Outsourcing infrastructure does not outsource DORA accountability.<\/strong><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>A financial entity can outsource hosting, messaging, conferencing, or other ICT services, but the management body&#8217;s responsibility for the ICT risk-management framework remains. Vendor selection changes how risk is managed, not who ultimately owns the governance obligation.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Understanding DORA&#8217;s Regulatory Architecture and Jurisdictional Reach<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46576 size-full\" title=\"Data security\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/06\/oauth.svg\" alt=\"Data security\" width=\"515\" height=\"380\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Unlike a directive, DORA does not require transposition into national law to become applicable. Its core requirements apply directly across the EU, although national competent authorities remain responsible for supervision and Member States provide the applicable national rules for penalties and remedial measures where DORA requires them.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The regulation is intended to harmonize ICT risk-management and digital operational resilience requirements across the EU financial sector.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-sm-1\"><b>DORA&#8217;s scope encompasses an extensive range of financial entities, including:<\/b><\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Credit institutions authorized under the Capital Requirements Directive<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Insurance and reinsurance undertakings operating within Solvency II frameworks<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Investment firms regulated by MiFID II<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Payment institutions governed by PSD2<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Electronic money institutions<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Crypto-asset service providers and issuers of asset-referenced tokens operating under the Markets in Crypto-Assets regulation<\/li>\n<\/ul>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA also establishes a Union-level oversight framework for ICT third-party service providers that the European Supervisory Authorities designate as critical under Article 31.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-sm-1\"><b>ICT third-party services used by financial entities can include:<\/b><\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\">Major cloud infrastructure providers<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Managed security service organizations<\/li>\n<li class=\"ui-list__item ui-list__item--disc\">Software vendors delivering core banking or trading systems<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/unified-communication-and-collaboration-tools\" target=\"_blank\" rel=\"noopener\">Communication and collaboration services<\/a> used by financial entities, depending on the contractual arrangement and role of the service<\/li>\n<\/ul>\n<\/div>\n<p class=\"primary-medium-text ui-mb-sm-1\">The regulation establishes an oversight framework in which national competent authorities supervise financial entities and the European Supervisory Authorities directly oversee ICT third-party service providers designated as critical under Article 31.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/ucaas-providers-regulated-organizations\" target=\"_blank\" rel=\"noopener\">Communication platform vendors<\/a> serving financial entities may face contractual requirements imposed under DORA by their financial-sector customers. Vendors designated as Critical ICT Third-Party Providers are additionally subject to direct ESA oversight. The exact obligations depend on the service relationship and whether the service supports a critical or important function.<\/p>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><b>Insight 2. Productivity software can still be operationally critical.<\/b><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Communication and collaboration tools should not be excluded from DORA scoping merely because they are categorized internally as productivity applications. If they are provided as ICT services under a contractual arrangement, they should be assessed within the institution&#8217;s ICT third-party risk framework.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Article 28 requires financial entities to maintain a Register of Information for contractual arrangements on the use of ICT services provided by ICT third-party service providers. Whether a communication platform supports a critical or important function affects the depth of additional contractual and risk-management requirements, but the Register is not limited only to critical services.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">DORA vs. NIS2: What Is the Difference?<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA and <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/nis2-compliance\" target=\"_blank\" rel=\"noopener\">NIS2<\/a> both address cybersecurity and operational resilience, but they have different scopes and legal structures. Financial entities can encounter both frameworks, although DORA contains sector-specific ICT risk requirements designed specifically for the financial sector.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Area<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>DORA<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>NIS2<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Primary scope<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Financial entities and ICT third-party risk within the financial sector<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A broader range of essential and important entities across multiple sectors<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Legal instrument<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">EU regulation that applies directly<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">EU directive implemented through national legislation<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Main emphasis<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Digital operational resilience, ICT risk, resilience testing, incident reporting, and ICT third-party risk<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Cybersecurity risk-management measures, incident reporting, governance, and <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/best-secure-collaboration-apps\" target=\"_blank\" rel=\"noopener\">supply-chain security<\/a><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Third-party framework<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Includes detailed contractual requirements, the Register of Information, and direct oversight of designated CTPPs<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Requires appropriate supply-chain and supplier-security risk management<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Resilience testing<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Contains a dedicated digital operational resilience testing framework and TLPT requirements for selected entities<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Requires cybersecurity risk-management measures but does not use the same DORA-specific testing structure<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">For financial entities, DORA acts as the more specific framework for the ICT risk areas it harmonizes. Organizations should still map their wider regulatory obligations rather than assuming that compliance with one framework automatically satisfies every requirement of the other.<\/p>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Five Core Areas Commonly Used to Summarize DORA<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA is commonly summarized through five core operational areas. This editorial structure helps explain how the regulation affects ICT governance, incident reporting, resilience testing, third-party risk, and information sharing, including the use of communication and collaboration tools.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Pillar<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>What It Requires?<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Implications for Communication Platforms<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>ICT risk management<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A governance framework covering identification, protection, detection, response, and recovery for ICT risk, with the management body responsible for defining, approving, overseeing, and implementing the framework<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Communication platforms within scope should be assessed against the institution&#8217;s ICT risk-management framework, with controls proportionate to their role, risks, and the functions they support<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>ICT incident management and reporting<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Classification and reporting of major ICT-related incidents according to DORA and the applicable classification criteria and reporting requirements<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">An outage or breach affecting a communication platform may become reportable if it meets DORA&#8217;s criteria for a major ICT-related incident; crisis communication planning should also account for loss of the primary channel<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Digital operational resilience testing<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A risk-based resilience testing programme; certain financial entities identified under Article 26 must perform Threat-Led Penetration Testing at least every three years, with the competent authority able to adjust the frequency<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">If a communication platform underlies a critical or important function, it may fall within the systems and ICT services considered for the relevant resilience testing or TLPT scope<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>ICT third-party risk management<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">A Register of Information for contractual arrangements on ICT services, baseline contractual clauses for ICT services, enhanced requirements for services supporting critical or important functions, and exit strategies where Article 28 requires them<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">This pillar can apply to video conferencing and messaging services when they are supplied to a financial entity as ICT services; enhanced requirements depend on the criticality of the supported function<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Information sharing<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Voluntary arrangements between financial entities to share cyber threat intelligence, indicators of compromise, and lessons learned from incidents<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Where threat intelligence is exchanged through <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/enterprise-meeting-software\" target=\"_blank\" rel=\"noopener\">communication tools<\/a>, the institution should apply confidentiality and access controls appropriate to the sensitivity of the information shared<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">What DORA Does Not Require?<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA sets outcomes and governance requirements for digital operational resilience, but several common assumptions go beyond what the regulation actually requires.<\/p>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\"><strong>DORA does not require every ICT system to be self-hosted.<\/strong> Organizations may use cloud, on-premises, or hybrid architectures provided the applicable ICT risk and third-party requirements are addressed.<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>DORA does not make every communication platform a critical service.<\/strong> Criticality depends on the role of the ICT service and the function it supports within the financial entity.<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>DORA does not classify every major technology vendor as a Critical ICT Third-Party Provider.<\/strong> CTPP status follows the formal designation process under Article 31.<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>DORA does not create a universal product certification called &#8220;DORA compliant.&#8221;<\/strong> Compliance applies to the financial entity&#8217;s governance, processes, controls, testing, contracts, and ICT-service management.<\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><strong>DORA does not eliminate responsibility when ICT operations are outsourced.<\/strong> Financial entities remain responsible for managing ICT third-party risk.<\/li>\n<\/ul>\n<\/div>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><strong>Insight 3. DORA regulates resilience outcomes and governance, not one preferred deployment architecture.<\/strong><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Cloud and self-hosted environments can both form part of a DORA-aligned ICT architecture. The relevant question is whether risks, dependencies, continuity, testing, contractual obligations, monitoring, and exit scenarios are understood and controlled.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">DORA Requirements by Communication Platform Function<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">A communication platform can interact with several DORA requirements at the same time. The relevant assessment depends on how the platform is actually used inside the financial entity.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Platform Function<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>DORA Relevance<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Practical Control to Evaluate<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong><a href=\"https:\/\/trueconf.com\/features\/collaboration\/office-chat-app.html\" target=\"_blank\" rel=\"noopener\">Internal messaging<\/a><\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">ICT risk, incident coordination, retention, third-party risk<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Access control, message retention, audit logs, identity integration<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Video conferencing<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Business continuity, incident response, service availability<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Redundancy, media routing, fallback communication, recording governance<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>File exchange<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Data protection, ICT risk, <a href=\"https:\/\/trueconf.com\/blog\/news\/security-fixes-updates-and-advisories\" target=\"_blank\" rel=\"noopener\">incident investigation<\/a><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Storage location, permissions, retention, <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/data-leakage-prevention-best-practices\" target=\"_blank\" rel=\"noopener\">malware controls<\/a><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong><a href=\"https:\/\/trueconf.com\/docs\/server\/en\/admin\/introduction\/\" target=\"_blank\" rel=\"noopener\">Directory integration<\/a><\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Access management and operational governance<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Provisioning, deprovisioning, role management, authentication dependencies<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Crisis communication<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Article 14 communication planning and operational continuity<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Availability during incidents, alternate channels, defined escalation paths<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong><a href=\"https:\/\/trueconf.com\/features\/integration.html\" target=\"_blank\" rel=\"noopener\">External integrations<\/a><\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">ICT third-party dependencies and operational risk<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Dependency mapping, contractual ownership, failure scenarios, exit planning<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">ICT Third-Party Risk Management and the Register of Information<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46644 size-full\" title=\"Third-party risk management\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/06\/secure-enter-1.svg\" alt=\"Third-party risk management\" width=\"561\" height=\"335\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">ICT third-party risk management is a major part of DORA. Article 28 of DORA requires financial entities to maintain a Register of Information covering contractual arrangements on the use of ICT services provided by ICT third-party service providers. The detailed templates capture information about the financial entity, provider, contractual arrangement, service, locations, and whether the supported function is critical or important.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">The European Supervisory Authorities use Register of Information data as part of the designation process for Critical ICT Third-Party Providers. On 18 November 2025, the ESAs published the first list of designated CTPPs after assessing providers against the criteria in Article 31 and the related delegated framework, including systemic impact, support for critical or important functions, and substitutability.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Designated CTPPs are subject to direct oversight by a Lead Overseer within the ESA framework, including examinations, information requests, recommendations, and follow-up activities provided for by DORA.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Article 30 sets baseline contractual requirements for ICT services and additional clauses where the service supports a critical or important function, including detailed service levels, reporting obligations, security and contingency requirements, audit and access rights, and transition provisions.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Separately, Article 28 requires documented exit strategies for ICT services supporting critical or important functions so that contractual arrangements can be exited without undue disruption.<\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">What Belongs in a DORA ICT Service Assessment?<\/h2>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Assessment Area<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>What to Record or Verify<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Why It Matters<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Service purpose<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">How the messaging or conferencing platform is used<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Determines business relevance and criticality<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Supported function<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Whether the ICT service supports a critical or important function<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Triggers additional risk, contractual, testing, and exit-planning considerations<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Provider relationship<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Hosting, licensing, maintenance, support, updates, managed services<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Identifies the actual third-party dependency model<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Data locations<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Relevant processing and storage locations<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Supports dependency and concentration assessment<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Subcontracting<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Relevant subcontractors and supply-chain dependencies<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Extends the risk picture beyond the primary vendor<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Exit path<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Data portability, transition period, alternative system, migration dependencies<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Reduces disruption if the service must be replaced<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><b>Insight 4. Critical provider status and individual service criticality are different concepts.<\/b><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>CTPP designation is based on DORA&#8217;s Article 31 criteria, including systemic impact, the importance of the functions supported, and substitutability. Broad use across the financial sector can therefore contribute to concentration and systemic-dependency considerations, but designation is not based on market success alone.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Separately, each financial entity must determine whether a particular ICT service supports one of its own critical or important functions. Procurement teams should not infer the importance of an internal service solely from the regulatory status or market position of its vendor.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">DORA Implementation and Oversight Status<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA has been applicable since 17 January 2025. The regulatory framework includes the operational Register of Information process, adopted technical standards and implementing acts, and an active ESA oversight framework for designated Critical ICT Third-Party Providers. The first CTPP list was published on 18 November 2025, and the oversight framework provides for examinations and related activities under the Lead Overseer structure.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">For financial entities, competent authorities have the supervisory, investigatory, sanctioning, and remedial powers set out in Article 50. DORA does not establish one uniform EU-wide maximum administrative fine for financial entities; Member States provide the applicable penalty rules.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Separate periodic penalty-payment provisions apply to Critical ICT Third-Party Providers in the context of ESA oversight. Financial entities should therefore be able to evidence how ICT services are recorded, risk-assessed, contracted, tested, and monitored in accordance with the requirements applicable to the specific service and supported function.<\/p>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Five Steps to DORA Compliance for Communication and Collaboration Tools<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">A practical review of communication and collaboration tools can follow the sequence below, while the institution&#8217;s full DORA programme should address all applicable requirements across the regulation.<\/p>\n<ol>\n<li class=\"primary-medium-text ui-mb-xs-1\"><b>Inventory every communication and collaboration tool actually in use<\/b>, including tools adopted informally by individual desks or departments outside a formal procurement process, since an unlisted tool is an unlisted risk regardless of how it was acquired.<\/li>\n<li class=\"primary-medium-text ui-mb-xs-1\"><b>Determine how each tool is used and whether it supports a critical or important function<\/b>, using the institution&#8217;s DORA classification process rather than assuming that data sensitivity alone determines criticality.<\/li>\n<li class=\"primary-medium-text ui-mb-xs-1\"><b>Populate the Register of Information for relevant contractual ICT-service arrangements<\/b> using the required templates and data fields. Where the service supports a critical or important function, apply the additional risk-management, contractual, and exit-planning requirements.<\/li>\n<li class=\"primary-medium-text ui-mb-xs-1\"><b>Build and rehearse an incident response and alternate communication plan<\/b> that assumes the primary communication platform itself is the thing that has failed, not just a system it happens to report on.<\/li>\n<li class=\"primary-medium-text ui-mb-xs-1\"><b>Include relevant communication services in resilience testing<\/b> where they support the functions being tested. For entities identified under Article 26, TLPT must cover several or all critical or important functions and the relevant underlying ICT systems and services, with a baseline frequency of at least every three years that the competent authority may adjust.<\/li>\n<\/ol>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Primary Communication Failure: A DORA Scenario Often Missed<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">Many incident-response plans assume that corporate chat, email, or conferencing will remain available during a cyber incident. DORA&#8217;s resilience logic makes that assumption worth testing.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">A ransomware event, identity-provider failure, cloud outage, denial-of-service attack, network isolation event, or compromised collaboration environment can remove the exact channel the incident team planned to use.<\/p>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Failure Scenario<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Operational Impact<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Resilience Question<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Cloud collaboration outage<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Incident team loses its primary chat or meeting environment<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Is there an independently available fallback channel?<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Identity provider failure<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Users cannot authenticate to multiple dependent services<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Can emergency communications operate without the failed identity path?<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Public connectivity loss<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">External cloud tools become unavailable from affected sites<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Can internal teams continue communicating inside the corporate network?<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Compromised collaboration environment<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Primary communication channel becomes untrusted<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Is there a separate trusted environment for incident coordination?<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Vendor service termination<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Access or functionality may be lost during transition<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Does the exit strategy include communication continuity?<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><strong>Insight 5. The communication platform can be both an incident-management tool and the failed ICT service.<\/strong><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>A DORA-oriented continuity plan should therefore test not only how teams communicate during failures elsewhere in the infrastructure, but also how they coordinate when their normal communication system is unavailable or untrusted.<\/em><\/p>\n<\/div>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">How On-Premises Communication Infrastructure Can Affect DORA Risk?<\/h2>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-46482\" title=\"On-premises deployment\" src=\"https:\/\/trueconf.com\/blog\/wp-content\/uploads\/2026\/02\/secure-shield.svg\" alt=\"On-premises deployment\" width=\"396\" height=\"324\" \/ loading=\"lazy\"><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">A financial institution running video conferencing and messaging on <a href=\"https:\/\/trueconf.com\/products\/server\/video-conferencing-server.html\" target=\"_blank\" rel=\"noopener\">TrueConf Server<\/a> on infrastructure it operates directly has a different dependency model from an institution using a vendor-operated shared cloud service. This can reduce reliance on external hosting, but it does not remove the need to assess any ICT services obtained from the software vendor or other providers.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Self-hosting may simplify some data-location, hosting, and subprocessor dependencies because communication data can remain on infrastructure controlled by the institution. However, an on-premises software deployment can still involve contractual ICT services such as licensing, support, maintenance, updates, or integrations.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Those arrangements should be assessed for Register of Information and third-party risk requirements based on their actual scope. Exit-strategy obligations also depend on whether an ICT service supports a critical or important function and on the contractual relationship involved.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">An on-premises deployment can give the institution direct access to its own platform logs and infrastructure during an incident, which may support investigation and continuity planning. TrueConf Server can also operate without a persistent internet connection, allowing an organization to design an internal communication path that does not depend on public internet availability.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">Whether a particular incident is reportable still depends on DORA&#8217;s major-incident classification criteria.<\/p>\n<\/div>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><b>Insight 6. Self-hosting changes concentration risk rather than eliminating third-party risk.<\/b><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>DORA requires financial entities to plan how they can exit ICT-service arrangements supporting critical or important functions without undue disruption. For a self-hosted deployment, the transition risk may differ from that of a vendor-operated cloud service because hosting and data custody can remain under the institution&#8217;s control.<\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>The relevant risk posture should therefore be assessed from the actual architecture, contracts, support model, integrations, and functions supported rather than from the deployment label alone.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Public Cloud vs. Self-Hosted Communication Under DORA<\/h2>\n<table style=\"overflow-x: auto; display: block;\">\n<thead>\n<tr>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Assessment Area<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong>Vendor-Operated Cloud<\/strong><\/p>\n<\/th>\n<th style=\"padding: 8px 16px; text-align: left; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\"><strong><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/sovereign-collaboration-platform\" target=\"_blank\" rel=\"noopener\">Self-Hosted Communication<\/a><\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Hosting dependency<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Core service depends on provider infrastructure<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Core application can run on infrastructure controlled by the institution<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Data location<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Depends on provider architecture and available regions<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Defined by the institution&#8217;s infrastructure design<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Operational responsibility<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">More responsibility delegated to provider<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">More responsibility retained by internal IT<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Incident access<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Depends on provider tooling, logs, and cooperation<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Direct access to locally operated infrastructure can be available<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Public internet dependency<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Normally required for service access<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Can be reduced where the platform supports <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/sovereign-video-conferencing\" target=\"_blank\" rel=\"noopener\">private-network operation<\/a><\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Third-party risk<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Hosting, software, support, operations, and subprocessors may be bundled into the service<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Hosting dependency can be reduced, but software, support, updates, and integrations may remain third-party services<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text ui-mb-xs-1\"><strong>Exit strategy<\/strong><\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">May require data export and migration away from provider infrastructure<\/p>\n<\/td>\n<td style=\"padding: 8px 16px; border-bottom: 1px solid #F7F9FC; vertical-align: middle;\">\n<p class=\"primary-smallest-text\">Hosting and some data custody can remain under customer control, although software transition still requires planning<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Evaluating TrueConf in a DORA-Oriented Communication Architecture<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">TrueConf is not a DORA compliance product, and deploying TrueConf does not make an organization DORA compliant. Its relevance comes from the architecture available to <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/enterprise-collaboration-software\" target=\"_blank\" rel=\"noopener\">financial institutions<\/a> that want messaging and video communication to operate on infrastructure they control.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><strong>Best for:<\/strong> financial institutions that need customer-controlled video conferencing and messaging, private-network operation, direct infrastructure administration, or an internal communication path that can continue without persistent access to a public communication cloud.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><strong>Strengths:<\/strong> on-premises deployment, <a href=\"https:\/\/trueconf.com\/enterprise-communication-solution.html\" target=\"_blank\" rel=\"noopener\">messaging and conferencing<\/a> in one system, local control over platform infrastructure, internal operation without persistent public internet connectivity, direct access to customer-operated infrastructure and logs, and integration with <a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/unified-communications-for-enterprise\" target=\"_blank\" rel=\"noopener\">enterprise communication environments<\/a>.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><strong>Limitations:<\/strong> self-hosting transfers more infrastructure responsibility to the financial institution. Capacity planning, redundancy, backup, monitoring, patch management, disaster recovery, and administrative security still need to be designed and operated correctly. Software support, licensing, updates, and integrations may also remain relevant ICT third-party relationships under DORA.<\/p>\n<div style=\"display: flex; align-items: center; justify-content: space-between; flex-wrap: wrap; gap: 12px; background: #00B3CD; border-radius: 12px; padding: 12px 16px;\">\n<h3 class=\"primary-small-text white-text\">Boost your team\u2019s productivity with TrueConf Server Free!<\/h3>\n<div class=\"button-group-container button-group-container--center\"><a class=\"default-button default-button--sm default-button--orange default-button--rounded default-button--truncate default-button__download-icon default-button--left-icon white-icon\" role=\"link\" href=\"https:\/\/trueconf.com\/products\/tcsf\/trueconf-server-free.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><br \/>\n<span class=\"default-button__text white-text\">Dowload<\/span><br \/>\n<\/a><\/div>\n<\/div>\n<div class=\"accent-note accent-note--special accent-note--line ui-mb-sm-1\">\n<p class=\"primary-medium-text ui-mb-xs-3\"><em><strong>Insight 7. A lower external dependency footprint can increase internal operational responsibility.<\/strong><\/em><\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><em>Moving communications from a provider-operated cloud to customer infrastructure changes the location of operational risk. Some external hosting dependencies may decrease, while internal requirements for patching, resilience, backup, monitoring, and recovery become more important. DORA evaluation should account for both sides of that tradeoff.<\/em><\/p>\n<\/div>\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">DORA Communication Platform Buyer Checklist<\/h2>\n<ul class=\"ui-list ui-list--medium\" style=\"margin-bottom: 18px;\">\n<li class=\"ui-list__item ui-list__item--disc\"><em>Is the communication service recorded in the organization&#8217;s ICT-service inventory and Register of Information where required?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Does the platform support a critical or important function?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Where are messages, files, recordings, logs, and user data processed and stored?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Which vendor, hosting, support, maintenance, update, and integration dependencies exist?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Can administrators obtain sufficient logs and evidence during an ICT incident?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Can communication continue if public internet connectivity, a cloud provider, or the primary identity system becomes unavailable?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Has the platform been included in relevant continuity and resilience testing?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Are audit, access, notification, service-level, contingency, and transition obligations addressed contractually where applicable?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Is there an alternate communication method if the primary platform itself fails?<\/em><\/li>\n<li class=\"ui-list__item ui-list__item--disc\"><em>Is there an exit strategy for relevant ICT-service arrangements supporting critical or important functions?<\/em><\/li>\n<\/ul>\n<div class=\"accent-note ui-mb-sm-1\">\n<h2 class=\"h4--main h4--thick black-text ui-mb-xs-3 ui-mt-md-1\">Conclusion: DORA and Resilient Communication Planning<\/h2>\n<p class=\"primary-medium-text ui-mb-sm-1\">DORA requires financial entities to treat ICT resilience as an ongoing governance, risk-management, testing, incident-management, and third-party-risk discipline.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\"><a href=\"https:\/\/trueconf.com\/blog\/reviews-comparisons\/communication-software\" target=\"_blank\" rel=\"noopener\">Communication systems<\/a> are relevant when they form part of the ICT environment used to support financial services, incident response, or critical or important functions. Their treatment under DORA depends on the role they play, the architecture in which they operate, and the contractual ICT-service relationships involved.<\/p>\n<p class=\"primary-medium-text ui-mb-sm-1\">For financial institutions evaluating communication platforms, the practical questions are therefore whether the service can be inventoried and governed, how incidents can be investigated and communicated, how continuity is maintained, what third-party dependencies exist, and how the platform fits into the institution&#8217;s resilience-testing and exit-planning framework.<\/p>\n<\/div>\n<div style=\"background: #00B3CD; border-radius: 12px; padding: 24px;\">\n<h2 class=\"h4--main h4--thick white-text center-text ui-mb-xs-3\">Empower your video conferencing experience with TrueConf!<\/h2>\n<div class=\"button-group-container button-group-container--center\"><a class=\"primary-smallest-text to-page to-page--rarr white-icon white-text\" role=\"link\" href=\"https:\/\/trueconf.com\/products\/server\/video-conferencing-server.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Learn more<\/a><\/div>\n<\/div>\n<section id=\"faq\">\n<h2 class=\"h3--main h3--thick black-text ui-mb-md-1\">FAQ<\/h2>\n<div class=\"faq__container ui-mb-md-1\">\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">What is the DORA regulation?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">DORA, Regulation (EU) 2022\/2554, establishes EU-wide digital operational resilience requirements for financial entities. It covers ICT risk management, major ICT-related incident reporting, resilience testing, ICT third-party risk management, and voluntary information sharing. TrueConf can form part of a DORA-oriented communication architecture when its messaging or conferencing services are included in the institution&#8217;s ICT governance framework.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">When did DORA become applicable across the European Union?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">DORA has applied across the EU since 17 January 2025. National competent authorities supervise financial entities, while the European Supervisory Authorities operate the oversight framework for designated Critical ICT Third-Party Providers. If TrueConf is used by a financial entity, its role should be assessed under the requirements relevant to the service and supported function.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">How is DORA different from NIS2?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">DORA is a directly applicable EU regulation focused on digital operational resilience in the financial sector, while NIS2 is a directive covering cybersecurity risk across a broader range of sectors. A financial institution using TrueConf should assess the platform against the specific ICT and communication requirements that apply under its overall regulatory framework.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Does DORA apply to messaging and video conferencing platforms?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">Communication platforms can fall within DORA-related ICT risk and third-party risk processes when they are used as ICT services by a financial entity. If TrueConf supports incident response or a critical or important function, its architecture, dependencies, continuity, logs, and relevant contractual arrangements should be included in the appropriate assessment.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">What is the DORA Register of Information, and can it apply to video conferencing platforms?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">The Register of Information is the structured record financial entities maintain for contractual arrangements involving ICT services provided by ICT third parties. A video conferencing or messaging platform such as TrueConf can be relevant where licensing, support, maintenance, hosting, updates, or other ICT services form part of the contractual arrangement.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Does DORA require financial institutions to use self-hosted communication platforms?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">No. DORA does not prescribe one mandatory deployment model for communication systems. TrueConf can be relevant where a financial institution prefers customer-controlled infrastructure, but the organization still needs to evaluate risk management, continuity, testing, operational responsibility, and third-party dependencies.<\/p>\n<\/div>\n<\/div>\n<div class=\"faq__item\">\n<p class=\"faq__question h4--main h4--thick black-text hyphens--auto margin--not\">Can TrueConf make an organization DORA compliant?<\/p>\n<div class=\"faq__answer\">\n<p class=\"primary-medium-text margin--not\">No single communication product can make a financial institution DORA compliant. TrueConf can support a customer-controlled communication architecture, but DORA compliance also depends on governance, ICT risk management, incident processes, resilience testing, contracts, third-party risk management, documentation, and organizational controls.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/section>\n<div class=\"accent-note accent-note--special ui-mb-sm-1\">\n<p class=\"primary-medium-text\"><strong><i>About the Author<\/i><\/strong><br \/>\n<i>Diana Shtapova is a product specialist and technology writer with three years of experience in the unified communications industry. At TrueConf, she leverages her deep product expertise to create clear and practical content on video conferencing platforms, collaboration tools, and enterprise communication solutions. With a strong background in product research and user-focused content development, Diana helps professionals and businesses understand core product features, adopt new technologies, and unlock the full potential of modern collaboration software.<\/i><\/p>\n<p><a class=\"primary-small-text to-page to-page--rarr cyan-icon\" role=\"link\" href=\"https:\/\/www.facebook.com\/shtapovadiana\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\"><i>Connect with Diana on Facebook<\/i><\/a><\/p>\n<\/div>\n<p><script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What is the DORA regulation?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"DORA, Regulation (EU) 2022\/2554, establishes EU-wide digital operational resilience requirements for financial entities. It covers ICT risk management, major ICT-related incident reporting, resilience testing, ICT third-party risk management, and voluntary information sharing. TrueConf can form part of a DORA-oriented communication architecture when its messaging or conferencing services are included in the institution's ICT governance framework.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"When did DORA become applicable across the European Union?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"DORA has applied across the EU since 17 January 2025. National competent authorities supervise financial entities, while the European Supervisory Authorities operate the oversight framework for designated Critical ICT Third-Party Providers. If TrueConf is used by a financial entity, its role should be assessed under the requirements relevant to the service and supported function.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"How is DORA different from NIS2?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"DORA is a directly applicable EU regulation focused on digital operational resilience in the financial sector, while NIS2 is a directive covering cybersecurity risk across a broader range of sectors. A financial institution using TrueConf should assess the platform against the specific ICT and communication requirements that apply under its overall regulatory framework.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does DORA apply to messaging and video conferencing platforms?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Communication platforms can fall within DORA-related ICT risk and third-party risk processes when they are used as ICT services by a financial entity. If TrueConf supports incident response or a critical or important function, its architecture, dependencies, continuity, logs, and relevant contractual arrangements should be included in the appropriate assessment.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"What is the DORA Register of Information, and can it apply to video conferencing platforms?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"The Register of Information is the structured record financial entities maintain for contractual arrangements involving ICT services provided by ICT third parties. A video conferencing or messaging platform such as TrueConf can be relevant where licensing, support, maintenance, hosting, updates, or other ICT services form part of the contractual arrangement.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does DORA require financial institutions to use self-hosted communication platforms?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"No. DORA does not prescribe one mandatory deployment model for communication systems. TrueConf can be relevant where a financial institution prefers customer-controlled infrastructure, but the organization still needs to evaluate risk management, continuity, testing, operational responsibility, and third-party dependencies.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Can TrueConf make an organization DORA compliant?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"No single communication product can make a financial institution DORA compliant. TrueConf can support a customer-controlled communication architecture, but DORA compliance also depends on governance, ICT risk management, incident processes, resilience testing, contracts, third-party risk management, documentation, and organizational controls.\"\n      }\n    }\n  ]\n}\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Digital Operational Resilience Act (DORA), Regulation (EU) 2022\/2554, establishes EU-wide requirements for the digital operational resilience of financial entities. It covers ICT risk management, major ICT-related incident reporting, resilience testing, ICT third-party risk, and voluntary information sharing, with additional oversight applying to designated critical ICT third-party service providers. DORA has applied since 17 January [&hellip;]<\/p>\n","protected":false},"author":78,"featured_media":49612,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[32],"tags":[386,393],"class_list":["post-48828","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-reviews-comparisons","tag-security","tag-unified-communications","wpautop"],"_links":{"self":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48828","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/users\/78"}],"replies":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/comments?post=48828"}],"version-history":[{"count":28,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48828\/revisions"}],"predecessor-version":[{"id":49611,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/posts\/48828\/revisions\/49611"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/media\/49612"}],"wp:attachment":[{"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/media?parent=48828"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/categories?post=48828"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trueconf.com/blog\/wp-json\/wp\/v2\/tags?post=48828"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}