DORA Art. 28 — ICT third-party risk management

DORA Art. 28: the infrastructure risk of your ICT third-party providers — visible in 90 seconds.

DORA Art. 28 requires financial entities to assess all ICT third-party providers for infrastructure risk and to document the results in a supervisor-ready form. CERTavia delivers the cryptographically verifiable evidence — without requiring the vendor's cooperation.

What DORA Art. 28 specifically requires

Four obligations. One technical answer.

Art. 28 DORA is not a general reference to duty-of-care obligations — it defines concrete requirements for the assessment and documentation of ICT third-party risk that must be demonstrably met to supervisory authorities.

Registration of all ICT third-party providers

Financial entities must maintain a complete register of their ICT third-party providers — including cloud services, software vendors and critical infrastructure partners. Every provider in the supply chain is relevant.

Risk assessment of the infrastructure

A security assessment of the infrastructure is required for every ICT third-party provider — not merely based on self-disclosure or certificates, but through verifiable technical review.

Documentation for supervisory authorities

The results of the risk assessment must be available in a form presentable to supervisory authorities (BaFin, EBA). Generic questionnaires or unverifiable vendor statements are not sufficient.

Annual review

Art. 28 DORA requires a regular, at least annual, repetition of the third-party assessment as well as an event-driven review following security-relevant incidents at the vendor.

The decisive difference

Without vendor consent — one-sided due diligence

CERTavia analyzes exclusively publicly accessible infrastructure parameters. No credentials, no cooperation from the vendor, no dependency on the third-party provider's goodwill. You retain control over your assessment.

What CERTavia checks

The SOVP scan evaluates public infrastructure parameters: DNS configuration and DNSSEC signatures, TLS certificate chain and expiry date, CAA records and certificate authority anchoring, HTTP security headers (HSTS, CSP, X-Frame-Options), as well as further publicly accessible signals of infrastructure hygiene. No login, no scanning of the internal network, no load placed on the vendor's systems.

What you receive

After the scan, you receive a CES score (Composite Evidence Score) with a clear CERTIFIED or FAILED verdict, a full PDF report with an individual assessment of every parameter checked, a Sovereign Vault URL — cryptographically signed and independently verifiable — and an immutable timestamp documenting the infrastructure state at the time of the check.

Use cases

Three DORA Art. 28 scenarios, one solution

Whether routine annual review, vendor onboarding or reactive control after an incident — CERTavia delivers the same cryptographically verifiable evidence.

Annual third-party assessment

Art. 28 DORA mandates the regular review of all ICT third-party providers. CERTavia enables the scalable annual review of your entire vendor portfolio — without questionnaire overhead on the vendor side, without coordination loops, with an immediately audit-ready result for every domain in your supply chain.

Onboarding new ICT suppliers

Before a new ICT third-party provider is added to your supply chain, DORA requires a risk assessment. With CERTavia you get an objective infrastructure picture of the prospective vendor in 90 seconds — independent of self-disclosures or presented certificates that do not reflect the actual infrastructure state.

Reactive review after a security incident

If an ICT third-party provider falls victim to a cyberattack or data breach, financial entities are required under DORA to reassess their own risk position. CERTavia delivers, within minutes, a current, cryptographically secured snapshot of the vendor infrastructure — as a basis for internal reporting processes and supervisory communication.

Frequently asked questions

Questions about DORA third-party evidence

Am I allowed to scan a third-party provider's infrastructure without their knowledge?

Yes. CERTavia analyzes exclusively publicly accessible infrastructure parameters: DNS configuration, TLS certificates, DNSSEC signatures and public HTTP headers. This is legally comparable to a traceroute or an SSL check — no credentials are needed, no special access is requested and no system of the vendor is placed under load. The vendor is neither contacted nor notified.

Is the CERTavia evidence usable for DORA supervisory authorities?

The Sovereign Vault provides a cryptographically signed, independently verifiable record of the infrastructure state at scan time. CERTavia is a technical evidence tool — not a regulatory opinion. Compliance teams should combine the evidence with their internal risk assessment and use it within their DORA reporting framework.

How does a vendor scan differ from a regular scan?

The underlying SOVP technology is identical. The difference lies in who commissions it: for a vendor scan, the financial institution commissions the scan of a third party's domain and receives the report and Sovereign Vault URL — the vendor is not involved in the process and receives no notification. For a regular scan, the domain owner commissions the review of their own infrastructure.

Take action now

DORA Art. 28 — third-party evidence at the push of a button.

Commission the vendor scan and receive a cryptographically signed infrastructure evidence record for your ICT third-party provider within 90 seconds.