DORA Art. 28: the infrastructure risk of your ICT third-party providers — visible in 90 seconds.
DORA Art. 28 requires financial entities to assess all ICT third-party providers for infrastructure risk and to document the results in a supervisor-ready form. CERTavia delivers the cryptographically verifiable evidence — without requiring the vendor's cooperation.
Four obligations. One technical answer.
Art. 28 DORA is not a general reference to duty-of-care obligations — it defines concrete requirements for the assessment and documentation of ICT third-party risk that must be demonstrably met to supervisory authorities.
Registration of all ICT third-party providers
Financial entities must maintain a complete register of their ICT third-party providers — including cloud services, software vendors and critical infrastructure partners. Every provider in the supply chain is relevant.
Risk assessment of the infrastructure
A security assessment of the infrastructure is required for every ICT third-party provider — not merely based on self-disclosure or certificates, but through verifiable technical review.
Documentation for supervisory authorities
The results of the risk assessment must be available in a form presentable to supervisory authorities (BaFin, EBA). Generic questionnaires or unverifiable vendor statements are not sufficient.
Annual review
Art. 28 DORA requires a regular, at least annual, repetition of the third-party assessment as well as an event-driven review following security-relevant incidents at the vendor.
Without vendor consent — one-sided due diligence
CERTavia analyzes exclusively publicly accessible infrastructure parameters. No credentials, no cooperation from the vendor, no dependency on the third-party provider's goodwill. You retain control over your assessment.
What CERTavia checks
The SOVP scan evaluates public infrastructure parameters: DNS configuration and DNSSEC signatures, TLS certificate chain and expiry date, CAA records and certificate authority anchoring, HTTP security headers (HSTS, CSP, X-Frame-Options), as well as further publicly accessible signals of infrastructure hygiene. No login, no scanning of the internal network, no load placed on the vendor's systems.
What you receive
After the scan, you receive a CES score (Composite Evidence Score) with a clear CERTIFIED or FAILED verdict, a full PDF report with an individual assessment of every parameter checked, a Sovereign Vault URL — cryptographically signed and independently verifiable — and an immutable timestamp documenting the infrastructure state at the time of the check.
Three DORA Art. 28 scenarios, one solution
Whether routine annual review, vendor onboarding or reactive control after an incident — CERTavia delivers the same cryptographically verifiable evidence.
Annual third-party assessment
Art. 28 DORA mandates the regular review of all ICT third-party providers. CERTavia enables the scalable annual review of your entire vendor portfolio — without questionnaire overhead on the vendor side, without coordination loops, with an immediately audit-ready result for every domain in your supply chain.
Onboarding new ICT suppliers
Before a new ICT third-party provider is added to your supply chain, DORA requires a risk assessment. With CERTavia you get an objective infrastructure picture of the prospective vendor in 90 seconds — independent of self-disclosures or presented certificates that do not reflect the actual infrastructure state.
Reactive review after a security incident
If an ICT third-party provider falls victim to a cyberattack or data breach, financial entities are required under DORA to reassess their own risk position. CERTavia delivers, within minutes, a current, cryptographically secured snapshot of the vendor infrastructure — as a basis for internal reporting processes and supervisory communication.
Questions about DORA third-party evidence
Am I allowed to scan a third-party provider's infrastructure without their knowledge?
Yes. CERTavia analyzes exclusively publicly accessible infrastructure parameters: DNS configuration, TLS certificates, DNSSEC signatures and public HTTP headers. This is legally comparable to a traceroute or an SSL check — no credentials are needed, no special access is requested and no system of the vendor is placed under load. The vendor is neither contacted nor notified.
Is the CERTavia evidence usable for DORA supervisory authorities?
The Sovereign Vault provides a cryptographically signed, independently verifiable record of the infrastructure state at scan time. CERTavia is a technical evidence tool — not a regulatory opinion. Compliance teams should combine the evidence with their internal risk assessment and use it within their DORA reporting framework.
How does a vendor scan differ from a regular scan?
The underlying SOVP technology is identical. The difference lies in who commissions it: for a vendor scan, the financial institution commissions the scan of a third party's domain and receives the report and Sovereign Vault URL — the vendor is not involved in the process and receives no notification. For a regular scan, the domain owner commissions the review of their own infrastructure.
DORA Art. 28 — third-party evidence at the push of a button.
Commission the vendor scan and receive a cryptographically signed infrastructure evidence record for your ICT third-party provider within 90 seconds.
This page serves technical orientation and does not constitute legal advice. Assessing specific regulatory obligations in an individual case is the responsibility of qualified legal and compliance advisors. CERTavia provides technical infrastructure validation based on the Sovereign Validation Protocol (SOVP, Patent Pending No. 64/005,737).