Digital Operational Resilience Act (DORA)
The Digital Operational Resilience Act has applied since 17 January 2025. It establishes ICT risk and operational-resilience requirements for regulated financial entities. It also establishes direct oversight for ICT third-party providers formally designated as critical.
When a financial entity uses Ver.iD as an ICT service provider, the financial entity remains responsible for its DORA obligations. It may require Ver.iD to provide specific contractual commitments, security evidence, incident support, and operational-resilience information.
As of this page's review date, Ver.iD is not included in the European Supervisory Authorities' list of designated critical ICT third-party providers. Ver.iD is therefore not currently subject to the direct DORA oversight framework for critical providers.
Certified security foundation
Ver.iD's ISO 27001 and NEN 7510 certifications provide an independently audited foundation for information security, risk management, incident management, supplier management, and business continuity.
These certifications support DORA-related customer requirements, but they do not by themselves establish DORA compliance or provide a DORA certification.
Assessment
| Phase | Status | Description |
|---|---|---|
| DORA assessment | In progress | Map DORA customer requirements against the existing ISO 27001 and NEN 7510 controls, contracts, and evidence. |
The assessment covers:
- Contract terms, service levels, and customer audit rights.
- Security, availability, backup, recovery, and resilience evidence.
- Incident notification and assistance for affected customers.
- Service, data-location, and subcontractor information.
- Exit support, data return, and service transition.
Status
Ver.iD is assessing how its certified controls and services support the DORA obligations of financial-sector customers. Ver.iD does not claim a separate DORA certification or designation as a critical ICT third-party provider.
Last reviewed: 20 August 2026