The Digital Operational Resilience Act expects EU financial entities to hold a complete register of every ICT third-party arrangement — and to report major incidents on a clock measured in hours. Polestead is built for both.
The whole ERP vendor master is ingested and classified. Coverage is the platform's default, so the register is complete by construction.
CIIC schedules the ~4-hour initial notification and the intermediate and final reports, and drafts each submission.
Tiering by six access vectors surfaces critical providers and concentration the moment the register is classified.
After a major incident is classified, DORA expects a first notification in roughly four hours, then an intermediate report as things stabilize and a final report with root cause. CIIC keeps all three clocks and produces the submissions per your competent authority. EU baseline shown — verify national specifics. Dataset last verified July 2026. Not legal advice.
It ingests your entire vendor master and classifies every record by exposure, so the register is complete by construction rather than sampled.
Yes — CIIC schedules the ~4-hour initial notification and the intermediate and final reports from the moment of classification, and drafts the submissions.
No. It's operational tooling; the dataset is verified against primary sources with last-verified dates. Confirm applicability and national specifics with counsel.