Skip to main content

How does Cyber Crucible support EU financial entities under DORA?

Short answer: Cyber Crucible is an ICT third-party service provider in DORA terms, and it supports a financial entity's DORA obligations — contractual controls, incident information, and resilience testing — while reducing ICT third-party risk because it never collects the entity's data. DORA applies from 17 January 2025. Cyber Crucible does not claim to be "DORA compliant" on a customer's behalf; compliance is the financial entity's, and Cyber Crucible supplies the support and evidence its program needs.

How it supports the entity's DORA program

  • ICT risk reduction. No customer content, credentials, or keys are collected, and protection runs locally — shrinking the third-party attack surface DORA targets.
  • Contractual controls. Cyber Crucible can accommodate the contractual provisions DORA expects for ICT third-party arrangements (security, incident cooperation, audit and information rights, subcontracting transparency).
  • Incident cooperation. A documented breach-response process provides prompt, evidence-grade information, and a committed notification timeframe is available by contract to support the entity's incident-reporting duties.
  • Resilience. Endpoint protection continues during a management-backend outage, which supports operational-resilience objectives.

The honest boundary

DORA also allows the European Supervisory Authorities to designate critical ICT third-party service providers (CTPPs) for direct EU oversight. Cyber Crucible is not designated as a CTPP and does not represent itself as one. It supports the financial entity's obligations; it does not assume them.