Skip to main content

Register, testing and exit

DORA support: tooling the technical evidence.

The Digital Operational Resilience Act (DORA) translates into a register of information, controls, tests and exit procedures. Once your legal and control functions have confirmed the scope, we prepare these technical deliverables.

Describe your DORA project

Am I in scope?

Confirm the scope before preparing the deliverables.

  • To be confirmed

    Does your activity fall within a covered financial category?

    The entity category and the applicable regime are confirmed by your legal counsel and control functions.

  • To be confirmed

    Does your activity involve crypto-asset services?

    The exact nature of the services and the status of the entity feed into the qualification of the scope.

  • To be confirmed

    Should a proportionality regime be examined?

    The entity category, headcount, balance sheet and turnover document this analysis.

  • Possible indirect exposure

    Do you provide digital services to a financial entity?

    Technical requirements can be passed down by contract even when the entity does not fall directly within the scope of the regulation.

Confirmation: Your legal counsel and control functions own the qualification of the scope and of the applicable regime.

Scope of our work

CTN Solutions implements the technical layer of DORA: register tooling, test infrastructure, exit runbooks and technical contract annexes. The regulatory qualification of your entity, the legal interpretation of the texts and any attestation of compliance remain with your legal counsel and control functions.

Requirement and deliverable

For each requirement, a technical deliverable.

Register of information

Requirement to address

List the arrangements with information and communication technology (ICT) providers using the templates of Implementing Regulation (EU) 2024/2956.

CTN Solutions deliverable

We structure the Data Point Model (DPM), consolidate the sources and document the checks set out in the taxonomy and validation rules of the European Banking Authority (EBA).

Contractual provisions

Requirement to address

Link the ICT services, the critical or important functions and the technical conditions set out in the contracts.

CTN Solutions deliverable

We prepare the technical annexes on services, location, auditability, testing and exit conditions.

Resilience testing

Requirement to address

Organise tests suited to the systems concerned and to the applicable regime.

CTN Solutions deliverable

We prepare the environment, the resilience scenarios, the authorised datasets and the record of results within the agreed scope.

Exit strategies

Requirement to address

Document the dependencies, the reversibility conditions and the decisions needed for an orderly exit.

CTN Solutions deliverable

We produce exit procedures with preconditions, execution sequence, controls and validation criteria.

From contract to export, a register you can check.

How the register of information is produced

Contractual sources are consolidated into a structured register, put through the agreed quality checks, then prepared in the format confirmed for the submission concerned.

Step by step

  1. Your legal and control functions confirm the entities, functions and arrangements to enter in the register.
  2. We consolidate the contractual sources into a traceable register model.
  3. We run the agreed quality checks and record the gaps to be corrected by the data owners.
  4. We prepare the export in the format confirmed for the submission concerned, with its generation and review procedure.

Deliverables, required data and responsibilities.

Technical deliverables

  • Structured register of information with documented quality checks
  • Export generation and review procedure
  • Resilience testing environment and scenarios
  • Exit procedures and technical annexes for review by your designated functions

Data and owners

  • Scope and applicable regime confirmed by your legal counsel and control functions
  • Inventory of providers and contracts
  • Map of critical or important functions approved by their owners
  • Authorised access to the systems and document sources

Separate scopes

  • Missing contractual data, to be completed by its owners
  • Recurring operation of the arrangements, scoped separately after handover

Scope to define

Describe your DORA project.

Tell us the activity concerned, the state of the register, the next internal or submission deadline and the critical functions already identified. We use this to define the scope, the sources and the technical deliverables of the engagement.

Describe what you need to achieve, the system concerned and what prevents progress today.

Security check

The check loads when you start the form.

Without JavaScript, use the email link below to send your request.