DORA is in its first real enforcement cycle. PCI DSS 4.0.1 is fully mandatory.
The Digital Operational Resilience Act has applied since 17 January 2025. The second annual Register of Information cycle closed on 31 March 2026 and supervisors have said in public that incomplete or untraceable registers are an enforcement priority. On the card side, the 51 future-dated PCI DSS 4.0 requirements have been mandatory since 31 March 2025, and the PCI Security Standards Council ran a request for comments on v4.0.1 from 3 June to 20 July 2026, the first step towards the next revision.
3,383 major ICT incidents in year one
The ESAs' first annual DORA incident overview counted 3,383 major incidents reported by financial entities; roughly a third had cross-border effects, and system failures and external events outnumbered cyberattacks.
NIS2 national deadlines land
Financial entities covered by both regimes must show one control set serving DORA, NIS2 and ISO 27001, not three parallel programmes. See NIS2 readiness.
Why financial compliance ends up in spreadsheets
A DORA programme lives on registers: ICT assets, ICT third-party arrangements with their subcontractor chains, critical or important functions, incidents classified under the RTS thresholds, and the results of resilience testing. A PCI DSS programme lives on recurring evidence: quarterly ASV scans, semi-annual firewall rule reviews, annual penetration tests, daily log review, and the targeted risk analyses that v4.0 introduced. Both are exactly what a GRC platform is for.
Yet the SaaS platform has a problem of its own making. Under DORA Article 28 and the EBA outsourcing guidelines, a cloud service holding your ICT risk register, incident records and control evidence is an ICT third-party service provider. It needs its own due diligence, contractual clauses under Article 30, an entry in the Register of Information, exit planning and, for many entities, a data-residency answer. The tool meant to reduce third-party risk becomes a third-party risk. So risk teams keep the master register in Excel, exchange it by email and rebuild it every March.
The spreadsheet tax in finance: parallel workbooks for DORA, PCI and ISO 27001 that share 60% of their controls; evidence collected three times; a Register of Information reassembled from contract folders every year; and an incident timeline nobody can produce inside the four-hour initial notification window.
VEDVERA for DORA
VEDVERA is a signed SharePoint Framework package deployed into your own Microsoft 365 tenant. It creates the lists and libraries a DORA programme needs and runs in the browser against your SharePoint, in the signed-in user's context. There is no VEDVERA cloud and no vendor database, so VEDVERA is not an ICT third-party service provider in your data flow, and it does not go on your register.
- ICT risk management framework (Articles 5 to 16): the DORA control set loaded at deployment and mapped to your ISO 27001 Annex A and NIS2 Article 21 controls, so shared controls are implemented and evidenced once.
- ICT third-party inventory: providers, contracts, the critical or important functions they support and their subcontractor chain kept as structured records with owners and review dates, so the annual Register of Information is built from live data rather than reassembled from folders.
- Incident records with classification fields aligned to the major-incident criteria, timeline, actor and timestamp in the append-only audit trail, and the evidence attached for the initial, intermediate and final reports.
- Resilience testing evidence: vulnerability assessments, scenario tests and threat-led penetration testing artefacts stored with freshness dates and linked to the controls they prove.
- Board reporting: the management body's oversight duty under Article 5 answered with a one-click board PDF from the live dashboard.
VEDVERA for PCI DSS v4.0.1
- All 12 requirements and their sub-requirements as controls with implementation statements, owners, status and linked evidence, including the requirements that became mandatory on 31 March 2025 such as 6.4.3 payment-page script management and 11.6.1 change and tamper detection.
- Customised approach and targeted risk analyses recorded against the control they justify, with review dates.
- Recurring PCI duties on the calendar: quarterly ASV scans and wireless scans, semi-annual firewall and router rule reviews, annual penetration tests, annual policy and training sign-offs, daily log review attestations. Each has an owner and a reminder; the freshness clock shows what your QSA will find stale.
- Scope documentation: the cardholder data environment, connected systems and third parties recorded in the inventory, so scoping is a view, not a diagram nobody updates.
- QSA and internal audit role: read-only, evidence-centric access with the audit trail shared as a view.
The duties calendar: where finance programmes are won or lost
Most PCI and DORA findings are not missing controls; they are controls whose evidence expired. VEDVERA ships with 45 recurring duties and adds the framework-specific ones during configuration: the quarterly scan, the annual register submission preparation, the semi-annual rule review, the testing programme. Owners get reminders, the dashboard shows what is late by department, and the board report shows the trend. Try the free compliance calendar generator to see the duties for your framework mix.
Inside the tool




Screens show the VEDVERA demo workspace (a fictional client).
Spreadsheets vs SaaS GRC vs VEDVERA for financial entities
| Question your supervisor or QSA asks | Excel and email | SaaS GRC platform | VEDVERA by ITSECOPS |
|---|---|---|---|
| Where do the ICT risk register, incidents and evidence live? | Shared drives, mailboxes | Vendor cloud, often outside the EU | Your Microsoft 365 tenant, in your Microsoft geography |
| Is the tool an ICT third-party provider under DORA? | No | Yes: due diligence, Article 30 clauses, register entry, exit plan | No. It runs on infrastructure you already registered |
| Data behind the Register of Information | Rebuilt every year | Module, extra cost | Live inventory with owners and review dates |
| Recurring PCI duties with reminders | None | Yes | Yes, owner reminders and freshness clock |
| One control set for DORA, PCI, ISO 27001, NIS2 | Three or four workbooks | Yes, priced per framework | Yes, included; shared controls collapsed |
| Licence model | Free, paid in hours | Per user, per framework, annual uplift | One-time deployment per organisation |
| Hosting | Included in Microsoft 365 | In the subscription | $0, SharePoint is already in your licence |
| Identity, MFA, Conditional Access, PIM | Entra ID | Vendor login, SSO as add-on | Entra ID, already enforced |
| Exit | Keep the files | Export, lose history; exit plan required | Nothing to export; the lists are yours |
$0 hosting, your security policy already applied
SharePoint Online is part of every Microsoft 365 Business and Enterprise plan. VEDVERA runs there, so there is no server, no database, no SaaS subscription and no hosting line on the invoice. Because every record is a SharePoint record, your existing controls apply automatically: Entra ID single sign-on, MFA, Conditional Access and device compliance, role-based access through SharePoint groups, PIM for admins, Purview audit, retention labels, DLP and eDiscovery. Microsoft's own SOC 2 and ISO 27001 attestations already cover the platform underneath.
Not on Microsoft 365? VEDVERA is also available as a standalone web application installed on your own Linux server behind your own identity provider, and on SharePoint Server on-premises. Same product, same one-time licence; deployment is scoped during discovery.
What VEDVERA costs for a financial entity
One-time deployment fee per organisation covering installation in your tenant, DORA and PCI DSS configuration, mapping to ISO 27001 or NIS2 where in scope, policy library seeding, dashboard set-up, optional spreadsheet migration and hand-over. Twelve months of maintenance, updates and support by ITSECOPS are included; renewal from year two is optional. No per-user, per-month or per-framework charges: invite every control owner, the internal auditor, the QSA and the board reader without changing the bill. Compare against per-seat SaaS with the 3-year GRC cost calculator.
The compliance tool should not be the next entry on your Register of Information.
Run it where your data already lives, under the controls you already evidence.
Sources: Regulation (EU) 2022/2554 (DORA), Articles 5 to 16, 17 to 23, 28 to 30; ESAs' first annual overview of major ICT incidents (3 June 2026); national competent authority Register of Information collections closed 31 March 2026; PCI DSS v4.0.1 (June 2024) and the 31 March 2025 future-dated requirement deadline; PCI SSC request for comments, 3 June to 20 July 2026. VEDVERA supports your programme; it does not replace your supervisor's judgement or your QSA's assessment.
Frequently asked
In most readings, yes. A cloud service that stores and processes your ICT risk register, incident records and control evidence is providing an ICT service, so it needs due diligence, the Article 30 contractual provisions, an entry in your Register of Information and an exit strategy. VEDVERA avoids this because it runs inside your own Microsoft 365 tenant on infrastructure you have already assessed and registered; ITSECOPS holds no data.
VEDVERA keeps the data behind it: ICT third-party providers, contracts, the critical or important functions they support, subcontractor chains, owners and review dates, as structured records with an audit trail. Your annual submission is prepared from that live inventory in the format your national competent authority requires, instead of being reassembled from contract folders each March.
PCI DSS v4.0.1, including the 51 requirements that became mandatory on 31 March 2025. Each requirement and sub-requirement is a control with an implementation statement, owner, status, linked evidence and, where you use it, the customised approach and targeted risk analysis records.
Yes. Shared controls are collapsed into one workstream, evidence is collected once and reused, and each framework view shows its own coverage. Adding a framework later reuses what exists and carries no licence charge.
In your own Microsoft 365 tenant's SharePoint lists and libraries, in your tenant's Microsoft geography, with Microsoft's EU Data Boundary where applicable. Encryption, backup, retention labels, DLP and eDiscovery are Microsoft 365 native. There is no VEDVERA cloud.
They are added as Auditors: read-only across the portal, evidence-centric views and the ability to mark evidence Verified. Roles map to SharePoint groups, so a reader cannot write even through the REST API, and the append-only audit trail can be shared as a view.
Nothing. It runs on the SharePoint Online included in your Microsoft 365 licence, or on your own SharePoint Server or Linux server. The only charge is the one-time deployment fee, which includes twelve months of ITSECOPS maintenance.
Yes. The commercial model is per organisation, not per user, so a 30-person e-money institution pays one deployment fee and invites everyone. Deployment takes weeks, and the same portal grows into ISO 27001 or SOC 2 when customers ask.