
Compliance framing
DORA ICT Third-Party Risk
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
- Reproduce audit export in trial
- Download trust pack for binders
- Regional hub cross-links
European Union DORA ICT register inputs and honest vendor limitations.
European Union financial sector buyers register Trustholm as ICT third-party with trust pack artifacts-DORA compliance is the financial entity program outcome.
Framework evidence framing before detailed tables below.

Compliance framing
Map Trustholm capabilities to your assessor program with honest Shipped/Gap rows-not vendor certification claims.
This page describes product capabilities for your control matrix. Trustholm does not hold SOC 2, ISO 27001, IRAP, Essential Eight, CMMC, Cyber Essentials, NIS2, or framework certification badges.
The Digital Operational Resilience Act (DORA) imposes ICT third-party risk management on EU financial entities and critical ICT providers in scope of RTS/designation. MSPs serving financial sector clients may introduce Trustholm as an ICT third-party service supporting script orchestration. Trustholm does not claim DORA compliance certification or financial entity status.
Buyers typically require: subprocessors list, architecture overview, security questionnaire pre-fill, incident notification terms, and exit/transition assumptions. Trustholm publishes honest Shipped/Gap evidence tables and downloadable trust materials at /trust/downloads-including EU-focused summaries where noted.
Enterprise onboarding covers SLA, support tiers, data processing terms, and subprocessors change notification. Standard trial terms are not a substitute for financial-sector contract schedules-engage sales and security@trustholm.com for regulated procurement.
Financial entities run scenario testing, backup restoration, and failover exercises on their operating model. Trustholm documents platform architecture and maintenance windows; customers document RTO/RPO assumptions for dependencies on our SaaS availability. We do not substitute for your ICT risk management framework required under DORA.
MSPs maintain the register of ICT third-party providers visible to the financial entity. Attach Trustholm vendor pack entries with honest gap disclosure (SIEM connector backlog, WORM audit immutability backlog). When clients ask for DORA certification slogans, redirect to contractual artifacts and your own ICT risk assessment of the subprocess.
Pair this page with GDPR processor framing and EU trust downloads. Trial evaluations should export audit evidence and capture IAM configuration within the first week for ICT risk file completeness.
Limitations: DORA outcomes depend on entity classification, contract tier, and supervisory expectations-marketing pages cannot certify your compliance program.
Financial sector MSPs: Maintain a version-controlled ICT register entry for Trustholm with last-reviewed date and link to trust hub Shipped/Gap exports. Review EU vendor pack quarterly when subprocessors list changes.
| Topic | Evidence | Status | Notes |
|---|---|---|---|
| ICT third-party register | Subprocessors, architecture overview, trust pack downloads | Shipped | - |
| Contractual ICT risk clauses | Enterprise DPA and SLA discussions during onboarding | Partial | - |
| Operational resilience testing | Customer-run DR/IR exercises; we document RPO/RTO assumptions | Partial | - |
| DORA compliant vendor badge | Not claimed-financial entity owns ICT risk management outcome | Gap | - |
We do not claim DORA compliance certification. We supply ICT third-party register inputs and contractual terms during enterprise onboarding.
Subprocessors list, architecture overview, security questionnaire pre-fill, and honest Shipped/Gap tables at /trust/downloads.
Customers run scenario tests on their operating model. We document maintenance and architecture; you document dependency RTO/RPO.
As an ICT subprocess with vendor pack attachments and gap disclosure-not as a certified DORA provider.
Yes-see EU GDPR/DORA summary at /trust/downloads alongside general trust materials.
Financial entities and their ICT contract terms define notification chains. Enterprise contracts document support escalation-not marketing pages alone.