How does Cyber Crucible support EU financial entities under DORA?

Short answer: Cyber Crucible is an ICT third-party service provider in DORA terms, and it supports a financial entity's DORA obligations — contractual controls, incident information, and resilience testing — while reducing ICT third-party risk because it never collects the entity's data. DORA applies from 17 January 2025. Cyber Crucible does not claim to be "DORA compliant" on a customer's behalf; compliance is the financial entity's, and Cyber Crucible supplies the support and evidence its program needs.

How it supports the entity's DORA program

The honest boundary

DORA also allows the European Supervisory Authorities to designate critical ICT third-party service providers (CTPPs) for direct EU oversight. Cyber Crucible is not designated as a CTPP and does not represent itself as one. It supports the financial entity's obligations; it does not assume them.


Revision #2
Created 2026-07-23 15:19:06 UTC by Dennis Underwood
Updated 2026-07-23 18:20:30 UTC by Dennis Underwood