Home › VEDVERA › DORA and PCI DSS GRC

DORA · PCI DSS v4.0.1 · EBA outsourcing · ISO 27001 · NIS2 · runs in your own tenant

The GRC tool for DORA and PCI DSS that does not become another ICT third party on your register.

Financial entities are asked to prove ICT resilience continuously, yet most run DORA and PCI DSS out of spreadsheets, because every SaaS compliance platform is itself an ICT service provider to assess, contract, register and report. VEDVERA removes the contradiction. It is deployed inside the Microsoft 365 tenant your bank, fintech, insurer or payment firm already governs, so the ICT risk register, the data behind the Register of Information, incident records and PCI DSS 4.0.1 evidence stay in your own environment, under your own identity policy, at $0 hosting.

Updated 24 September 2026 · By ITSECOPS, CISA-certified compliance consultants

Why this matters in September 2026

DORA is in its first real enforcement cycle. PCI DSS 4.0.1 is fully mandatory.

The Digital Operational Resilience Act has applied since 17 January 2025. The second annual Register of Information cycle closed on 31 March 2026 and supervisors have said in public that incomplete or untraceable registers are an enforcement priority. On the card side, the 51 future-dated PCI DSS 4.0 requirements have been mandatory since 31 March 2025, and the PCI Security Standards Council ran a request for comments on v4.0.1 from 3 June to 20 July 2026, the first step towards the next revision.

3 JUN 2026

3,383 major ICT incidents in year one

The ESAs' first annual DORA incident overview counted 3,383 major incidents reported by financial entities; roughly a third had cross-border effects, and system failures and external events outnumbered cyberattacks.

OCT 2026

NIS2 national deadlines land

Financial entities covered by both regimes must show one control set serving DORA, NIS2 and ISO 27001, not three parallel programmes. See NIS2 readiness.

Why financial compliance ends up in spreadsheets

A DORA programme lives on registers: ICT assets, ICT third-party arrangements with their subcontractor chains, critical or important functions, incidents classified under the RTS thresholds, and the results of resilience testing. A PCI DSS programme lives on recurring evidence: quarterly ASV scans, semi-annual firewall rule reviews, annual penetration tests, daily log review, and the targeted risk analyses that v4.0 introduced. Both are exactly what a GRC platform is for.

Yet the SaaS platform has a problem of its own making. Under DORA Article 28 and the EBA outsourcing guidelines, a cloud service holding your ICT risk register, incident records and control evidence is an ICT third-party service provider. It needs its own due diligence, contractual clauses under Article 30, an entry in the Register of Information, exit planning and, for many entities, a data-residency answer. The tool meant to reduce third-party risk becomes a third-party risk. So risk teams keep the master register in Excel, exchange it by email and rebuild it every March.

The spreadsheet tax in finance: parallel workbooks for DORA, PCI and ISO 27001 that share 60% of their controls; evidence collected three times; a Register of Information reassembled from contract folders every year; and an incident timeline nobody can produce inside the four-hour initial notification window.

VEDVERA for DORA

VEDVERA is a signed SharePoint Framework package deployed into your own Microsoft 365 tenant. It creates the lists and libraries a DORA programme needs and runs in the browser against your SharePoint, in the signed-in user's context. There is no VEDVERA cloud and no vendor database, so VEDVERA is not an ICT third-party service provider in your data flow, and it does not go on your register.

  • ICT risk management framework (Articles 5 to 16): the DORA control set loaded at deployment and mapped to your ISO 27001 Annex A and NIS2 Article 21 controls, so shared controls are implemented and evidenced once.
  • ICT third-party inventory: providers, contracts, the critical or important functions they support and their subcontractor chain kept as structured records with owners and review dates, so the annual Register of Information is built from live data rather than reassembled from folders.
  • Incident records with classification fields aligned to the major-incident criteria, timeline, actor and timestamp in the append-only audit trail, and the evidence attached for the initial, intermediate and final reports.
  • Resilience testing evidence: vulnerability assessments, scenario tests and threat-led penetration testing artefacts stored with freshness dates and linked to the controls they prove.
  • Board reporting: the management body's oversight duty under Article 5 answered with a one-click board PDF from the live dashboard.

VEDVERA for PCI DSS v4.0.1

  • All 12 requirements and their sub-requirements as controls with implementation statements, owners, status and linked evidence, including the requirements that became mandatory on 31 March 2025 such as 6.4.3 payment-page script management and 11.6.1 change and tamper detection.
  • Customised approach and targeted risk analyses recorded against the control they justify, with review dates.
  • Recurring PCI duties on the calendar: quarterly ASV scans and wireless scans, semi-annual firewall and router rule reviews, annual penetration tests, annual policy and training sign-offs, daily log review attestations. Each has an owner and a reminder; the freshness clock shows what your QSA will find stale.
  • Scope documentation: the cardholder data environment, connected systems and third parties recorded in the inventory, so scoping is a view, not a diagram nobody updates.
  • QSA and internal audit role: read-only, evidence-centric access with the audit trail shared as a view.

The duties calendar: where finance programmes are won or lost

Most PCI and DORA findings are not missing controls; they are controls whose evidence expired. VEDVERA ships with 45 recurring duties and adds the framework-specific ones during configuration: the quarterly scan, the annual register submission preparation, the semi-annual rule review, the testing programme. Owners get reminders, the dashboard shows what is late by department, and the board report shows the trend. Try the free compliance calendar generator to see the duties for your framework mix.

Inside the tool

Risk register and heatmap
VEDVERA ICT risk register with 5x5 heatmap
Inventory and third parties
VEDVERA inventory of platforms, devices, SIEM and third-party services
Evidence recipes and freshness
VEDVERA evidence recipes with freshness clock
Approvals
VEDVERA policy approval workflow

Screens show the VEDVERA demo workspace (a fictional client).

Spreadsheets vs SaaS GRC vs VEDVERA for financial entities

Question your supervisor or QSA asksExcel and emailSaaS GRC platformVEDVERA by ITSECOPS
Where do the ICT risk register, incidents and evidence live?Shared drives, mailboxesVendor cloud, often outside the EUYour Microsoft 365 tenant, in your Microsoft geography
Is the tool an ICT third-party provider under DORA?NoYes: due diligence, Article 30 clauses, register entry, exit planNo. It runs on infrastructure you already registered
Data behind the Register of InformationRebuilt every yearModule, extra costLive inventory with owners and review dates
Recurring PCI duties with remindersNoneYesYes, owner reminders and freshness clock
One control set for DORA, PCI, ISO 27001, NIS2Three or four workbooksYes, priced per frameworkYes, included; shared controls collapsed
Licence modelFree, paid in hoursPer user, per framework, annual upliftOne-time deployment per organisation
HostingIncluded in Microsoft 365In the subscription$0, SharePoint is already in your licence
Identity, MFA, Conditional Access, PIMEntra IDVendor login, SSO as add-onEntra ID, already enforced
ExitKeep the filesExport, lose history; exit plan requiredNothing to export; the lists are yours

$0 hosting, your security policy already applied

SharePoint Online is part of every Microsoft 365 Business and Enterprise plan. VEDVERA runs there, so there is no server, no database, no SaaS subscription and no hosting line on the invoice. Because every record is a SharePoint record, your existing controls apply automatically: Entra ID single sign-on, MFA, Conditional Access and device compliance, role-based access through SharePoint groups, PIM for admins, Purview audit, retention labels, DLP and eDiscovery. Microsoft's own SOC 2 and ISO 27001 attestations already cover the platform underneath.

Not on Microsoft 365? VEDVERA is also available as a standalone web application installed on your own Linux server behind your own identity provider, and on SharePoint Server on-premises. Same product, same one-time licence; deployment is scoped during discovery.

What VEDVERA costs for a financial entity

One-time deployment fee per organisation covering installation in your tenant, DORA and PCI DSS configuration, mapping to ISO 27001 or NIS2 where in scope, policy library seeding, dashboard set-up, optional spreadsheet migration and hand-over. Twelve months of maintenance, updates and support by ITSECOPS are included; renewal from year two is optional. No per-user, per-month or per-framework charges: invite every control owner, the internal auditor, the QSA and the board reader without changing the bill. Compare against per-seat SaaS with the 3-year GRC cost calculator.

Verdict

The compliance tool should not be the next entry on your Register of Information.

Run it where your data already lives, under the controls you already evidence.

Sources: Regulation (EU) 2022/2554 (DORA), Articles 5 to 16, 17 to 23, 28 to 30; ESAs' first annual overview of major ICT incidents (3 June 2026); national competent authority Register of Information collections closed 31 March 2026; PCI DSS v4.0.1 (June 2024) and the 31 March 2025 future-dated requirement deadline; PCI SSC request for comments, 3 June to 20 July 2026. VEDVERA supports your programme; it does not replace your supervisor's judgement or your QSA's assessment.

Frequently asked

In most readings, yes. A cloud service that stores and processes your ICT risk register, incident records and control evidence is providing an ICT service, so it needs due diligence, the Article 30 contractual provisions, an entry in your Register of Information and an exit strategy. VEDVERA avoids this because it runs inside your own Microsoft 365 tenant on infrastructure you have already assessed and registered; ITSECOPS holds no data.

VEDVERA keeps the data behind it: ICT third-party providers, contracts, the critical or important functions they support, subcontractor chains, owners and review dates, as structured records with an audit trail. Your annual submission is prepared from that live inventory in the format your national competent authority requires, instead of being reassembled from contract folders each March.

PCI DSS v4.0.1, including the 51 requirements that became mandatory on 31 March 2025. Each requirement and sub-requirement is a control with an implementation statement, owner, status, linked evidence and, where you use it, the customised approach and targeted risk analysis records.

Yes. Shared controls are collapsed into one workstream, evidence is collected once and reused, and each framework view shows its own coverage. Adding a framework later reuses what exists and carries no licence charge.

In your own Microsoft 365 tenant's SharePoint lists and libraries, in your tenant's Microsoft geography, with Microsoft's EU Data Boundary where applicable. Encryption, backup, retention labels, DLP and eDiscovery are Microsoft 365 native. There is no VEDVERA cloud.

They are added as Auditors: read-only across the portal, evidence-centric views and the ability to mark evidence Verified. Roles map to SharePoint groups, so a reader cannot write even through the REST API, and the append-only audit trail can be shared as a view.

Nothing. It runs on the SharePoint Online included in your Microsoft 365 licence, or on your own SharePoint Server or Linux server. The only charge is the one-time deployment fee, which includes twelve months of ITSECOPS maintenance.

Yes. The commercial model is per organisation, not per user, so a 30-person e-money institution pays one deployment fee and invites everyone. Deployment takes weeks, and the same portal grows into ISO 27001 or SOC 2 when customers ask.

VEDVERA hexagon logoVEDVERAGRC PLATFORM BY ITSECOPS

Ready for a walkthrough
in your own tenant?

Tell us your frameworks and estate. A CISA-certified ITSECOPS consultant replies within one business day with a walkthrough slot, the deployment scope for your tenant and a written quote. No newsletter, no phone call unless you ask for one.

What happens next: a consultant replies by email within 1 business day with slots and a written scope. No phone call unless you ask for one. No newsletter.

Book a walkthrough in your tenant