Supplier criticality, recovery objectives, dependency maps and incident playbooks live in-platform - so when the regulator clock starts, the evidence pack is already assembled.
The DORA major-ICT-incident reporting window. Most resilience evidence is reconstructed from email threads during the incident - by the time the regulator deadline hits, the report is incomplete. In-platform, the pack auto-assembles inside the window.
When a major incident hits a critical supplier, the regulator clock starts and the evidence has to follow within hours - not the days it takes to reconstruct it from inboxes and shared drives. The two columns below set the scramble most teams know against the continuous evidence model that replaces it.
Major incident at a supplier. The 72-hour clock starts. Risk, legal and ops teams scramble. Evidence reconstructed from inboxes. Regulator deadline missed. Penalty assessed.
Supplier criticality, recovery objectives, dependency maps and incident playbooks all live in-platform. When the clock starts, 90% of the evidence pack is already assembled.
NIS2, DORA and the UK NIS Regulations each demand the same things in different words: a complete register of critical ICT third parties, tested recovery objectives and evidence ready inside the reporting window. The capabilities below are how E2ERisk has those obligations met before an incident ever begins.
ICT third-party register with all 19 DORA RTS fields, pre-mapped.
Sector obligations + critical-supplier flagging per Annex I + II.
Major-incident report auto-assembled within the regulator window.
RTO / RPO / MTPD per supplier, tested and timestamped with evidence.
GDPR + DPA + NIS + DORA references on every record. No silos.
Resilience compliance comes down to a handful of figures that decide whether a report lands on time. The four below - the 72-hour DORA window, the 19 RTS register fields, the NIS2 sector count and a pack assembled ready for the regulator - are the ones this module is built around.
Regulator-ready resilience is a continuous loop, not a report written under pressure. The five stages below - scope, register, test, detect and report - run in-platform so that when an incident classification starts the clock, the evidence pack has already been building underneath every prior step.
Resilience evidence only counts if it ties back to the regime holding you to account. Each record in the platform carries its references, so the same work satisfies DORA, NIS2, the UK NIS Regulations, ISO 22301, NCSC CAF v4.0 and BS 65000 at once - the six regimes set out below.
Resilience obligations do not stop when an incident closes - they run before, during and after it. The three modes below cover the full arc: operational monitoring and drill cadence day to day, the 72-hour incident pack when the clock starts, and lessons-learned with remediation tracking once the regulator follow-up lands.
Continuous monitoring + drill cadence + auto-evidence.
72-hour incident pack + escalation runbooks + regulator templates.
Lessons-learned + remediation tracking + regulator follow-up.
We’ll map your top-five ICT third parties against DORA RTS requirements.