Skip to main content
Les Assises 2026 · Monaco

Meet us at the Startup area, and at our workshop on Wednesday 7 October, 4:30 pm.

Book the workshop

BY INDUSTRY · BANKING & INSURANCE

DORA and NIS2 on one control set, without a second register.

Your supervisor reads the register of information against the incident reports and the list of critical functions, and expects them to agree. Mindlapse keeps the three on one living data set, with the management body’s accountability evidenced from it.

DORA · NIS2 · Register of information · Concentration risk · ACPR and AMF

ICT third-party providers · the register as a graph Illustrative data

ICT third-party providers · Trust Grade

Meridian Core Systems C
Helios Cloud Services D
Corvus Market Data A−

Initiatives

Register of information refresh

In progress

Concentration analysis (Art. 29)

Started

TLPT scoping from the value chain

Validated

Frameworks · critical or important function

DORA
ISO/IEC 27001

Critical or important function

Payment processing

Has initiative Uses framework Supports

The register of information is this graph, kept alive, not a spreadsheet exported in spring.

THE SITUATION

The register is a living object, not a spring campaign.

  1. The register is a spring campaign

    Exported once, four subcontracting levels deep, and inconsistent with the list of critical functions by summer.

  2. Concentration you cannot show

    Three critical functions on one cloud provider, and nobody added it up for Article 29.

  3. Three lines, three tools

    ISO controls in security, the operational risk register in risk, the DORA gap analysis in compliance; the board pack reconciles them by hand.

  4. Four hours from classification

    The DORA clock on a major incident starts before the incident cell has met.

WHO IS IN SCOPE

Who is in scope in banking and insurance?

In France the financial entities DORA names are supervised by the ACPR (banks, payment institutions, insurers and mutuals) and the AMF (asset managers and market infrastructures), which collect the register of information. For those entities DORA takes precedence over the NIS2 measures and incident duties, while group entities outside DORA stay under NIS2. ICT third-party providers to financial entities carry the contractual flow-down of Articles 28 to 30. The DORA page lists who the regulation applies to, article by article.

Written for

  • Banks and payment institutions DORA, supervised by the ACPR
  • Insurers and mutuals DORA, supervised by the ACPR
  • Asset managers and market infrastructures DORA, supervised by the AMF
  • ICT providers to financial entities The Article 28 to 30 flow-down

THE OBLIGATIONS MAP

What DORA asks, and what Mindlapse verifies.

EU rows first, the French specific tagged; every "verifies" cell is a product claim at ledger level, and no cell carries a date.

What DORA asks, and what Mindlapse verifies.
Regulation Obligation What Mindlapse verifies Surface
DORA Art. 5 · the management body owns ICT risk Resilience state, concentration and open decisions in board-grade views, each figure opening on its evidence Cyber Cockpit
DORA Art. 6 · an ICT risk framework reviewed yearly DORA and its RTS mapped to your control set; each control carries dated, reviewed evidence Control Atlas
DORA Art. 28(3) · the register of information The ICT third-party register as living data (contracts, criticality, dependencies), exportable in supervisory formats Supplier Hub
DORA Art. 29 · ICT concentration risk Concentration read on the activities each provider operates, flagged on the chain Concentration risk
DORA Art. 19 · major ICT incident reporting Classification against the criteria, then the cascade: assessment, draft, notification file, log Cyber Incidents
Arrêté contrôle interne FR Essential outsourced services (PSEE) under ACPR supervision The outsourcer assessed in the context of the service it runs; remediation as a joint action plan both sides accept, reject or counter-propose Supplier Hub

A QUARTER, THEN THE DAY THE SUPERVISOR ASKS

A normal quarter fires on attestations, not on a calendar; the request finds the three documents already agreeing.

Four moments of an ordinary quarter in a financial entity, and what the platform had already done; then the day the ACPR asks, in three steps.

A quarter in banking, then the request Illustrative data

A normal quarter

  1. WEEK 1

    The register needs refreshing.

    The refresh fired on an expiring attestation, not on a campaign; the providers it concerned were listed with what changed.

    Surface: Supplier Hub

  2. alert: WEEK 5

    Concentration review.

    One provider under four critical functions had been flagged on the chain, with the functions named.

    Surface: Concentration risk

  3. WEEK 9

    The TLPT findings arrive.

    Entered as risks and controls with owners, on the functions the test had been scoped from.

    Surface: TLPT engagements

  4. verified: WEEK 12

    The pack for the management body.

    Resilience state, concentration and the open decisions, exported from the live register.

    Surface: Cyber Cockpit

The day the supervisor asks

  1. THE REQUEST

    The ACPR asks for the register, the list of critical functions and last quarter’s incident reports, consistent with each other.

    All three were read from one data set, so they already agreed.

    Surface: Supplier Hub

  2. WHAT OPENS

    The register as living data, the functions on the chain, the incident records.

    Each incident record carried its cascade log: classification, assessment, draft, notification file.

    Surface: Cyber Incidents

  3. WHAT IS EXPORTED

    The register, the reports, the evidence.

    The register in supervisory formats, the supervisory reports produced from the module, the controls’ evidence from Audit mode.

    Surface: Reports

Illustrative quarter: the moments are fictional, the surfaces are the product’s.

FROM THE FIELD

Built with the people the supervisor writes to.

CYBER COLLECTIVE LAB · Edition 5

Compliance: NIS2, DORA and CRA - round table and field feedback

DORA and NIS2 as the round table framed them: where the two regimes overlap for a financial group, and what field teams had already reconciled.

2–3×
risk visibility across the organization
−50–70%
time-to-risk-decision
15–30%
cyber-budget optimization

Measured with our design-partner CISOs, figures under continuous validation.

FAQ

Banking and insurance ask

Can Mindlapse produce the register of information in the ITS template?

Not in the ITS template today. The register is living data, contracts, criticality and dependencies on the providers themselves, exported when you need it; the supervisory template is worked through on your scope during the session.

Who runs the TLPT, you or us?

Qualified testers test. Mindlapse manages the programme around them: scoping from your value chain, findings entered as risks and controls with owners, remediation tracked to verified closure, and the evidence trail the supervisor expects.

Can subsidiaries under different supervisors keep their autonomy?

Yes. Access is scoped by organization, each entity runs its own register and its own reviews, and the group reads a sub-consolidated view without touching the entity’s records.

Is DORA lex specialis over NIS2 for a financial group?

For the financial entities DORA names, yes: its ICT risk and incident-reporting requirements take precedence over the NIS2 measures and notification duties. Group entities outside DORA stay under NIS2, so the same control set has to answer both; the DORA and NIS2 pages carry the detail.

Which rating providers feed the Trust Grade?

SecurityScorecard, Bitsight and Scovery, beside your own assessment of the provider and the business impact of the service it runs. The weights are in the open and the grade is recomputed overnight.

RESILIENCE, EVIDENCED

Bring your register of information. Leave with it living.

A live session on your ICT third parties: register, concentration, TLPT programme, the board view.

Refusing is exactly as easy as accepting, and nothing is pre-selected. Your choice is kept for 6 months and can be changed at any time from the footer.

Strictly necessary

Always on

Stores your cookie choice in this browser so we can honour it on your next visit. No tracking identifier, no third party. Cannot be disabled.