Visibility That Powers DORA Compliance
The Digital Operational Resilience Act calls for improved operational resilience. The road to compliance starts with knowing your digital exposure and the supplier connections behind it.

How ThingsRecon Supports
ThingsRecon Capabilities Mapped to DORA Requirements
Our discovery data feeds your DORA compliance program by enhancing visibility across ICT assets, third parties, and external exposures that inform DORA reviews. See how we support each requirement.
Requirement
Article 8(4): Identify all information and ICT assets and map their configuration and interdependencies.
Article 8(6): Maintain inventories, update them periodically, and whenever any major changes occur.
delivers
Automated Asset Discovery and SupplyChain Mapping continuously identify domains, IPs, APIs, certificates, and connections, including third-party and forgotten infrastructure.
Requirement
Article 8: Continuously identify allsources of ICT risk.
Article 9: Continuously monitor andcontrol ICT security and functioning.
Article 10: Have mechanisms topromptly detect anomalous activities.
delivers
Continuous external discovery of both your own attack surface and your connected vendors, including shadow IT and unmanaged assets, helps maintain real-time visibility into exposure to identify anomalies.
Requirement
Article 28: Maintain a register of all contractual arrangements with ICT third-party service providers.
Article 30: Ensure contractual rights for monitoring, auditing, and obtaining information from providers.
delivers
Supply chain discovery gives actionable visibility into vendor and supplier risk, with Digital Proximity scoring to understand how deeply each is integrated and what impact they could have.
Requirement
Article 18: Classification of ICT related incidents and cyber threats.
Article 24: A risk-based approach
to conducting digital operational resilience testing.
delivers
A risk scoring engine with 100+ cyber hygiene indicators, including missing or misconfigured HTTP headers, weak or outdated SSL/TLS protocols, insecure forms, supports evidence-based prioritisation and mitigation efforts.
Requirement
Article 17: Track, log, and classify ICT-related incidents. Identify, document, and address root causes to prevent recurrence. Put in place early warning indicators.
delivers
Contextual risk reports and remediation recommendations show which assets, vendors, or misconfigurations are most critical, helping you act before incidents happen.
Requirement
Article 19: Reporting of major
ICT-related incidents and voluntary notification of significant cyber threats.
Article 20: Standardized
reporting templates.
delivers
Reporting insights plug into GRC, SIEM, or EASM workflows to streamline documentation, support audits, and board or executive reporting.
Requirement
Articles 28 30: Understand the
location of service providers and their subcontractors.
Article 29: Assess ICT concentration risk.
delivers
Geo located scanning and global points of presence help respect data residency requirements and support compliance with specific sovereignty needs.
Frequently asked questions
EASM can support DORA by maintaining an up-to-date view of internet-facing ICT assets and externally observable exposure. Continuous discovery helps regulated organisations identify unknown systems, monitor changes, improve vulnerability scope and collect evidence that supports ICT risk management, testing and incident readiness. DORA also places substantial emphasis on ICT third-party risk. Traditional EASM may show supplier-hosted assets without explaining the full dependency or contractual context, so it should be complemented with supply chain intelligence and governance records. ThingsRecon connects external asset discovery with supplier relationships and Digital Proximity, helping teams understand which external dependencies sit closest to critical services. It supports evidence; it does not replace legal, governance or operational compliance work.
Digital operational resilience is an organisation’s ability to continue delivering critical services through technology failures, cyber incidents and third-party disruption, then recover within acceptable limits. It depends on more than prevention. Organisations need visibility of assets and dependencies, tested response plans, continuity measures, clear ownership and evidence that controls work under stress. Supplier and fourth-party relationships are central because a service can fail even when the organisation’s own systems remain secure. External discovery and supply chain mapping help expose dependencies that may be absent from internal inventories, while continuous monitoring shows when the risk landscape changes. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert.
GRC-ready security reports present findings in a form that governance, risk and compliance processes can use, with clear scope, evidence, ownership, priority, status and historical context. They should support control testing, risk acceptance, remediation tracking and audit review without requiring teams to reinterpret raw technical output. ThingsRecon provides configurable, evidence-based reporting that connects external assets and suppliers to business context and ongoing changes. The reports support GRC workflows, while the organisation remains responsible for its control framework and regulatory conclusions. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert.
DORA doesn't name "fourth parties" directly, but Article 30 requires contracts with ICT providers to state whether subcontracting of a critical function is permitted and under what conditions. Article 29 also covers concentration risk, which is exactly where fourth-party exposure tends to build up.
A SIG questionnaire can provide structured supplier assurance and help collect detailed information about controls, governance and security practices. It does not by itself demonstrate continuous oversight. Regulatory programmes still need to connect the answers to supplier criticality, supporting evidence, monitoring, remediation and current risk decisions.
Useful supplier-oversight evidence is traceable, dated, and connected to a documented control or risk decision. Depending on the programme, this can include questionnaires, contracts, certifications, review records, technical findings, monitoring history, remediation tickets, exceptions, approvals and evidence of reassessment. The strongest record shows what was reviewed, who owned the decision and what happened when the supplier risk changed.
Some questionnaire answers can be checked against external evidence. Examples include internet-facing assets, certificates, DNS configuration, exposed services, software fingerprints, security headers and observable supplier relationships. Internal controls such as access governance, network segmentation and recovery procedures usually require supplier evidence or internal validation. External monitoring is therefore most useful as an independent layer of assurance around claims that can be observed from outside.
DORA applies to the financial entities listed in Article 2 of Regulation (EU) 2022/2554, including banks, payment institutions, investment firms, insurers, crypto-asset service providers and several other regulated financial-sector entities. The Regulation also creates obligations and an oversight framework relevant to ICT third-party service providers. Article 2 contains specific exclusions, so organisations should confirm scope against their legal entity type and applicable national framework.
The DORA register of information is the structured record financial entities must maintain and update under Article 28(3) for contractual arrangements involving ICT services. It supports ICT third-party risk management and supervisory reporting. Commission Implementing Regulation (EU) 2024/2956 provides the standard templates and defines the ICT service supply chain, including ranks for direct providers and subcontractors.
DORA addresses indirect ICT dependencies through its rules on subcontracting. Article 29 requires financial entities to assess risks arising when ICT services supporting critical or important functions are subcontracted and to consider whether long or complex subcontracting chains could weaken effective monitoring. The required depth depends on the service, the contractual chain and its relevance to critical or important functions.
Critical ICT third-party service providers are providers designated by the European Supervisory Authorities under Article 31 using criteria such as their systemic impact, the importance of the financial entities that rely on them and the availability of alternatives. Designated providers are subject to the EU-level Oversight Framework led by a Lead Overseer.
A security rating gives a supplier a single score, often a letter grade, based on scan data alone. A DORA or NIS2-ready tool goes further: it maps how deeply that supplier's systems touch your critical operations and ties specific findings to the regulatory article they affect, so the output functions as evidence, not just a grade.
No. Both regulations ask for the same underlying capability: continuous, evidence-based visibility into third-party and supply chain risk. A tool that maps findings to specific articles across both frameworks, rather than treating them as separate checklists, can serve a financial entity under DORA and a broader NIS2-scoped organization at the same time.
Continuously, not annually. ENISA's technical implementation guidance for NIS2 requires a live, updated register of suppliers reflecting ongoing risk management activity. DORA's oversight provisions expect the same standard. A once-a-year questionnaire cannot produce evidence for the other 364 days of the year.
No single tool does. Compliance is a governance and operational outcome involving procurement, legal, and executive sign-off, not just software. What a tool can do is provide the visibility, prioritization, and evidence trail that make the rest of that governance work possible.
.png)
.png)
.png)