Skip to content

SSPM for DORA: Automating the ICT Third-Party Register of Information

By Black Cat Security Team · Updated August 14, 2026

DORA (EU Regulation 2022/2554) has applied since January 2025. Financial entities must annually submit a Register of Information (Registre d’Information) to their regulator — in France, via OneGate to the ACPR or AMF — listing every ICT third-party arrangement and its criticality. The register’s hardest section is usually the ICT-provider inventory: which SaaS and AI vendors are actually in use, kept accurate under a spreadsheet that goes stale the moment it's filled in.

Black Cat SSPM maps 58 controls to DORA, including the Register of Information requirement itself (DORA-28.2), and generates the ICT-provider section directly from a read-only scan of your connected SaaS estate — regenerable at every filing cycle.

DORA requirements mapped to your SaaS estate

Based on DORA (EU Regulation 2022/2554) and Black Cat's DORA framework mapping
DORA article areaWhat it requiresHow Black Cat SSPM covers it
ICT third-party risk & Register of Information (Art. 28)Maintain and annually submit a register of all ICT third-party arrangements — provider, criticality, data categories, dependencies.Read-only discovery of your connected SaaS and AI-vendor estate generates the ICT-provider section of the Register of Information, regenerable at every filing cycle. Mapped to control DORA-28.2.
ICT asset identification (Art. 8)Maintain a current inventory of ICT assets and the business functions they support.Continuous SaaS connector and identity inventory, refreshed on every scan.
Identity & access management (Art. 9)Strong authentication, least-privilege access, privileged-access management.MFA-posture, admin/privileged-role, and session-management checks across every connected SaaS app.
Detection (Art. 10)Logging and audit trails to support incident detection.Scheduled drift and finding alerts (custom CEL rules) plus audit-log export. Not real-time behavioral detection — see caveat below.
Incident classification & reporting readiness (Art. 17–19)Classify and report major ICT-related incidents to the competent authority within strict deadlines.Finding history and audit-log export feed your incident-classification and reporting workflow.

Why the Register of Information is the hard part

DORA applies since January 2025, and the next Registre d’Information collection cycle lands in spring 2027. Supervisors have publicly flagged widespread data-quality issues in the registers submitted so far — largely because the ICT-provider section is compiled manually, and shadow SaaS and AI tools that nobody declared don't make it into the spreadsheet. A read-only OAuth scan discovers what's actually connected, not what was remembered.

What Black Cat SSPM covers today

The DORA framework page lists the full set of 58 controls Black Cat maps policy evaluations to — including DORA-28.2, the Register of Information control itself. Every scan re-evaluates your posture and refreshes the ICT-provider export.

What we don't claim

Black Cat SSPM covers the SaaS-posture and third-party-inventory slice of DORA — it is not a full ICT risk-management, resilience-testing, or incident-reporting platform, and detection is scheduled policy evaluation, not real-time behavioral monitoring. Treat it as the automated ICT-provider inventory feeding your broader DORA program, not a replacement for it.

Frequently asked questions

What is DORA and who does it apply to?

The Digital Operational Resilience Act (EU Regulation 2022/2554) has applied since January 2025 to financial entities — banks, insurers, investment firms, payment institutions, and others — and, indirectly, to their critical ICT third-party providers.

What is the Registre d’Information (Register of Information)?

It’s the annual filing financial entities submit — in France, via OneGate to the ACPR or AMF — listing every ICT third-party arrangement, its criticality, and its dependencies. It’s required under DORA Article 28, and supervisors have publicly highlighted data-quality issues in registers submitted since the requirement took effect.

How does Black Cat SSPM help build the Registre d’Information?

A read-only scan of your connected SaaS and AI-vendor estate discovers what’s actually in use — including tools nobody formally declared — and exports the ICT-provider section in the expected format, regenerable at each filing cycle instead of maintained by hand in a spreadsheet.

Does Black Cat SSPM replace a full DORA compliance program?

No. DORA covers ICT risk management broadly — resilience testing, governance, incident response. Black Cat SSPM covers the SaaS-posture and third-party-inventory slice, mapped to 58 DORA controls including the Register of Information (DORA-28.2).

Can I see my DORA gap before I buy?

Yes — run a free posture scan. It connects with read-only-by-default access to one SaaS tenant and gives you an immediate view of your third-party SaaS/AI inventory and DORA-relevant posture.

Competitor information on this page is drawn from publicly available sources (vendor websites, product pages, and independent press coverage) as of the date noted next to each claim, and is believed accurate at time of writing. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Vendor offerings change over time — verify current details directly with the vendor before making a purchasing decision.

See your own SaaS posture in 10 minutes

Run a free posture scan — no credit card required, read-only-by-default OAuth access you can revoke any time.

Run a free posture scan