Boldo Logo

DORA compliance: resilience you can prove, register in hand

DORA requires you to know your ICT providers, the services they deliver and the functions that depend on them. Boldo links this information in a governed repository, to prepare the register and keep your mapping up to date.

The register is more than a list of providers

In force since 17 January 2025, DORA requires financial entities to manage the risks tied to information and communication technologies, including those carried by third-party providers.

The register of information documents the contractual arrangements covering the use of ICT services. To be usable, it must also be reconcilable with the business functions, applications and dependencies concerned.

The real challenge is therefore not only to produce a file by a given deadline. It is to keep the information reliable between two submissions and to explain the consequences of a failure.

The information to link over time

  • Third-party ICT service providers
  • The services delivered and the associated contracts
  • The entities and business functions that benefit from them
  • The applications and ICT assets concerned
  • The criticality of the services and the functions they support
  • The dependencies and concentrations to monitor
  • Censuswide for Veeam, 2025

    96%

    of EMEA financial organisations believe they still need to strengthen their resilience to meet DORA.

  • Censuswide for Veeam, 2025

    40%

    now make it their number one digital resilience priority.

A resilience requirement that goes beyond the register alone

DORA covers ICT risk management, the reporting of major incidents, resilience testing and the control of risks tied to third-party providers.

DORA — Digital Operational Resilience Act — logo on a blue EU-starred background

In particular, your organisation must be able to:

  • identify and manage ICT risks
  • know the critical or important functions and the assets that support them
  • keep an up-to-date register of the arrangements made with ICT service providers
  • analyse the potential consequences of an incident or a failure
  • report major incidents under the applicable terms
  • organise and document regular resilience tests

Boldo does not cover all of these obligations on its own. It structures an essential foundation of the framework: knowledge of the assets, functions, providers and their dependencies.

What Boldo helps you structure

Boldo links the data needed for your resilience mapping and for preparing the register of information, without replacing your regulatory submission tools.

  • Flat Boldo inventory screenshot in light mode listing applications with editor, criticality, hosting and status columns
    Providers and contracts

    Structure ICT providers, the services delivered, the contracts and the entities concerned in a shared base fed by files or by API.

  • Boldo impact analysis diagram showing how cyber threats (Denial of Service, Brute Force, Phishing) affect websites, CRM and business teams
    Functions and dependencies

    Link business functions to the applications, ICT assets and providers they depend on to understand the potential impacts of a failure.

  • Boldo asset detail page for 'Custom IAM Portal' showing criticality, functional and technical scores, and a DORA relationship diagram
    Criticality and resilience

    Document criticality, responsibilities, recovery objectives (RTO/RPO) and the other indicators useful to your analysis, following your organisation's metamodel.

Prepare and control your register of information

Boldo lets you structure ICT providers, services, contracts and their links to the functions and assets concerned.

You can then filter, control and export this data to prepare your regulatory register or to reconcile the information already maintained in your compliance tools.

Boldo does not replace the templates, taxonomies and submission channels mandated by your competent authority.

  • Identify the contracts and services associated with each provider
  • Link each service to the functions and entities that benefit from it
  • Detect missing or inconsistent information
  • Export the data needed for your preparation work
Register of information
Boldo inventory screenshot in dark mode showing applications with criticality, hosting, status and associated data flows
Resilience
Boldo dark mode screenshot of a CRM, ERP and Steering ecosystem diagram linking applications and teams

Analyse the dependencies behind every critical function

A list of suppliers is not enough to understand your exposure. A single function may depend on several applications, ICT services and providers, some of them shared with other activities.

Typed relationships let you start from a function, an asset or a supplier and walk through the dependencies that connect them.

Impact analysis stops being a one-off collection. It relies on a verifiable, reusable model.

  • Find the ICT assets that support a function
  • Identify the services delivered by a single provider
  • Spot sensitive dependencies and concentrations
  • Share a reading tailored to compliance, risk or IT

Connect your continuity work to the real IT landscape

A continuity plan cut off from the repository becomes hard to maintain and hard to check against real dependencies.

You can model your interruption scenarios, your continuity plans and the associated responsibilities, then link them to the functions, applications, assets and providers concerned.

Impact views, diagrams and dashboards then let you prepare resilience reviews from the same knowledge of the IT landscape.

Continuity
Boldo screenshot of a cyber risk analysis linking VPN, IAM Entra ID and Phished to threats affecting CRM Sales and Team Sales, with a Salesforce detail panel
Governance
Smart city business capability map with the ERP Finance panel open in Boldo

Keep the information current between deadlines

DORA compliance does not end when the register is submitted. Providers, contracts, services and dependencies keep evolving throughout the year.

In Boldo, every asset can have an identified owner and every change is versioned. Roles and access domains govern what the IT, risk, security, compliance or audit teams can view and edit.

The same base thus supports both the regulatory work and the CIO's day-to-day steering of the IT landscape.

Feed the repository from what already exists

The information required for DORA is often spread across supplier files, contract databases, a CMDB, questionnaires and compliance tools.

  • Files

    CSV / XLSX import

    Bring in existing providers, contracts, services and assets, then map the columns to the properties and relationships of your model.

  • Programmable

    REST API v1

    Build the synchronisations you need when certain sources must keep feeding your mapping and your controls.

  • Contribution

    Validation by teams

    Give each team the rights it needs to check and enrich the information within its scope.

A repository accessible to the IT, risk and compliance teams

  • Hosted in France at Scaleway
  • Metamodel adaptable to your assets, contracts, services and indicators
  • Roles and access domains to isolate sensitive scopes
  • Change history to track how the information evolves
  • Views understandable by technical and non-technical teams
  • Pricing from EUR 39 per editor per month

Need regulatory guidance? We can connect you with partner consultants who specialise in DORA initiatives.

Frequently asked questions about DORA and the register of information

Boldo structures an essential part of the knowledge the DORA framework requires: business functions, ICT assets, providers, services, contracts and their dependencies.

The platform does not replace the tools for incident reporting, test management or regulatory submission. It provides a living repository those processes can rely on.

A register that stays accurate between deadlines

A register to prepare, dependencies to map or information to make reliable: discover how to structure the knowledge your DORA work requires.

Contact us

30 minutes dedicated to your register and your mapping.

By submitting this form, you agree to our Privacy Policy.