Skip to content
ECZ-IDService & Workload

Regulated finance · ECZ-ID Service & Workload

DORA ICT-vendor evidence

Prepare reusable ICT-vendor evidence for customers operating under DORA.

The DORA solution helps an ICT provider organise identity, service, resilience and supporting evidence into a reusable review pack for financial-sector customers and their procurement or risk workflows.

Type
Solution
Price
Not restated on this site; TrustOps publishes the current price and availability
Acquired and paid in
TrustOps
Operated in · proved by
Dashboard · Resolver

The problem

Why it matters.

Financial entities must identify and evidence the ICT services they rely on. Providers of hosted services answer the same questions about ownership, locations, change and resilience for every bank and insurer — from documents that go stale with the next migration.

Built for

  • Technology suppliers selling ICT services into EU-regulated financial entities.
  • Teams repeatedly answering the same vendor-risk and operational-resilience questions.
  • Providers that want a structured evidence pack rather than a loose collection of attachments.

What changes

  • Faster preparation for customer ICT-vendor reviews.
  • More consistent evidence across repeated questionnaires and procurement cycles.
  • A clearer link between the supplier identity, service surface and supporting evidence.

What you receive

Concrete deliverables, not a vague trust score.

  • Structured DORA-oriented vendor evidence organisation.
  • Reusable identity and service context from the ECZ-ID estate.
  • Evidence packaging suitable for customer review workflows.
  • Paths for managed and enterprise depth where the requirement is larger.
An ICT-service evidence pack
Supplier
Your organisation and its Parent tier
ICT service
The logical service in scope, with its ECZ-ID
Runtime context
Declared providers, regions and dependencies, where you supply them
Evidence
Eligible identity, change and resilience evidence, organised
Gaps
Material gaps identified, not filled by assumption
Boundary
Supports evidence preparation — does not certify DORA compliance

Illustrative structure. Runtime detail stays in the private pack; the Resolver shows only published fields.

How it works

A short path from need to something usable.

  1. Define the ICT service and the customer review context.

  2. Map the evidence you already hold and identify material gaps.

  3. Organise eligible evidence into a reusable review structure.

  4. Maintain the evidence set as the service and supplier relationship change.

How it relates to your Passport

DORA evidence uses the same foundation as every Passport: the supplier's Parent, the service's enduring ECZ-ID and the evidence around it. For service and workload providers the service is usually the ICT service in scope, so it is often the first thing a regulated customer asks about.

Use cases

  • A hosted-service provider answering a bank's ICT third-party review with one reusable evidence structure.
  • Showing that a service kept the same identity and accountable organisation through a cloud migration.
  • Keeping supplier evidence current as providers, regions and dependencies change.

Tiers and price

Price and availability

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. This site does not restate this product's price; TrustOps publishes its current tiers, price and availability, and shows them before anything is bought.

How it is arranged

  1. TrustOps acquires

    TrustOps publishes the tiers and holds payment and entitlement whenever it is offered.

  2. Dashboard operates

    Once you hold it, it appears in your Dashboard, where you operate it.

  3. Resolver proves

    Public facts stay on the Resolver; holding it never changes what a record proves.

Privacy, security and evidence

What is collected, published and kept.

  • The regulated entity and its advisers remain responsible for their own legal and risk conclusions.
  • Evidence publication requires your consent.
  • ECZ-ID does not certify DORA compliance.

Boundaries

The claims stop here.

  • ECZ-ID supports evidence preparation and review; it does not certify DORA compliance.
  • The regulated entity and its advisers remain responsible for their own legal and risk conclusions.

Integrations and questions

Works with what you already run.

  • Parent VERIFIED or ASSURED: each DORA tier requires one, and its price includes it.
  • LedgerCore for append-only evidence records.
  • Your existing vendor-risk questionnaires and procurement portals.
Does this make my service DORA compliant?
No. ECZ-ID supports evidence preparation and review. It does not certify compliance.
Why does DORA matter for services and workloads?
Because the service is usually the ICT service in scope. Regulated customers need to know which organisation is accountable for it and how it changes; the evidence structure answers that without certifying anything.
Does it replace our own register or risk assessment?
No. The regulated entity and its advisers remain responsible for their own register, legal conclusions and risk decisions.