Compliance/DORA/Cybersecurity

DORA compliance for Cybersecurity

Cybersecurity vendors serving financial-entity customers are third-party ICT providers under DORA Art. 28. The customer's register of information requires per-vendor + per-system evidence.

Updated 15 May 2026·Primary application·Primary source ↗

What applies

Articles + provisions of Regulation (EU) 2022/2554 — Digital Operational Resilience Act most directly engaged by Cybersecurity deployments:

  • Art. 28

What this looks like in Cybersecurity

Cybersecurity vendors serving financial-entity customers are third-party ICT providers under DORA Art. 28. The customer's register of information requires per-vendor + per-system evidence.

Flagship exampleSOC platform's financial-sector customer requests Art. 28 evidence: per-tenant audit bundle answers.

Where Promethean's evidence layer fits

The substrate emits specific evidence kinds that map to DORA obligations. Most directly relevant for Cybersecurity:

For the full sector view including LLM-feature catalogue, tier recommendation, and reviewer-gate examples, see the Cybersecurity sector page.

Adjacent cells

Same regulation, other sectors

Other regulations for Cybersecurity