How Didit Meets DORA: ICT Third-Party Risk for Identity
Blog post from Didit
The Digital Operational Resilience Act (DORA), effective from January 2025, mandates that financial entities in the EU are directly responsible for the operational resilience of their ICT third parties, such as identity verification providers. This regulation requires financial entities to ensure their providers are resilient and to document proof for regulatory purposes. Didit, an identity verification provider, supports compliance with DORA by offering certifications including ISO/IEC 27001:2022 and SOC 2 Type 1, which align with DORA's ICT risk management expectations. Didit's unified API facilitates resilience, monitoring, and reporting, consolidating critical functions with one provider, thereby simplifying due diligence and compliance processes. DORA emphasizes the importance of maintaining a register of ICT arrangements, performing due diligence, and securing specific contractual rights, with the provider obligated to provide evidence of resilience.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.