Free online trainings
24
Sep
Eramba Detailed Risk & Compliance Advanced
Regulation (EU) 2022/2554 - in force

DORA, pillar by pillar

Five pillars, and for each one an honest answer to the same question: what does eramba carry, and what stays yours? It is the governance brain, not the network.

  • Free CSV download
  • Every framework included
  • Flat annual fee
The five pillarsCarried in eramba
  1. 1ICT risk management frameworkArticles 5-16Risk · Policies
  2. 2ICT-related incident reportingArticles 17-23Incidents
  3. 3Digital operational resilience testingArticles 24-27Controls · Audits
  4. 4ICT third-party risk managementArticles 28-44Assessments · partly
  5. 5Information sharingArticle 45Evidence only

The Register of Information is filed by you, not by eramba. That is spelled out below.

What eramba carries, and what stays yours

Every pillar gets the same two columns. The right-hand column is the part no GRC tool does for you, and knowing it before an audit is worth more than a coverage percentage.

ICT risk management

Articles 5-16

A framework owned by the board that identifies, protects and recovers ICT assets.

eramba carries

  • Board accountability. ICT strategies in the Policy module; mandatory board training and policy acknowledgements in Awareness.
  • Asset context. Data, hardware and software linked to business units and processes, which is how a critical or important function gets defined.
  • Multi-method risk. Asset, third-party and business risk with your own matrix. The technical standards do not mandate a calculation method.

Stays yours

  • Asset discovery. eramba is not a network scanner. Sync it with your CMDB over the REST API.
  • Hardening. It cannot push a firewall rule or encrypt a drive. It audits that you did.

Incident reporting

Articles 17-23

Classifying and reporting major incidents inside very tight windows.

eramba carries

  • The lifecycle. Dynamic status moves an incident to major on its own when a field crosses your threshold.
  • The clock. Notifications fire from the date of classification, so the deadlines below arrive before the regulator does.
  • Machine intake. Your SIEM posts the incident over REST and the workflow starts without anyone typing.

Stays yours

  • Filing it. eramba does not e-file to the authority. You export and submit, which is what you want anyway - nobody sends a regulator an unreviewed report.

Resilience testing

Articles 24-27

Proving the systems survive a bad day, every year, and threat-led testing on top.

eramba carries

  • Audits and maintenance, kept apart. One proves the control works, the other keeps it running. Auditors ask for both.
  • The programme. Recurring audits across ICT controls, with evidence requests going out to technical owners automatically.
  • Findings to closure. A failed test opens a finding; the corrective action is a project with an owner and a deadline.

Stays yours

  • Scanning. eramba does not replace a vulnerability scanner. It consumes the results and tracks what you did about them.

Third-party risk

Articles 28-44

The supply chain, the contract clauses, and the register the authority asks for.

eramba carries

  • Assessments. Send any questionnaire to a vendor; the answers move the vendor's score and open findings where they should.
  • Register metadata. Vendor records with custom fields, including the fourth parties your provider depends on.
  • Contract lifecycles. Right-to-audit and exit clauses tracked, with notice months before renewal.

Stays yours

  • Discovery. It will not find the SaaS someone expensed last quarter. Import it, or connect procurement.
  • The filing itself. See the note further down this page.

Information sharing

Article 45

Voluntary exchange of threat intelligence inside the financial community.

eramba carries

  • Evidence of participation. Membership tracked as a third party, meeting minutes stored as evidence against the requirement.
  • Distribution. Lessons learned pushed to the technical teams through Awareness.

Stays yours

  • The feed. eramba is not a threat intelligence platform. It does not ingest STIX or TAXII and it will not block an address.

Three deadlines, counted from classification

The clock on a major incident starts when you classify it, not when you finish investigating.

4 hours

Initial notification. eramba notifies the owner from the classification date, by email or REST.

72 hours

Intermediate report. The incident record already holds the timeline you need.

1 month

Final report. Root cause, corrective actions and the project that closes them.

The Register of Information is not something we can file for you

Pillar 4 requires a register submitted every year and on request: fifteen linked files in a proprietary xBRL-CSV format set by the authorities, several hundred fields in total.

eramba holds the data - vendors, contracts, entities, functions, assessments - and exports it. Producing the regulator’s exact file, and submitting it, stays with you. Any tool that claims otherwise has not read the technical standards.

Fifteen files in total, from the reporting entity down to a look-up table that keeps the other fourteen consistent.

Three of the fifteen

RT.02.01

Contracts, general - 31 fields

RT.03.02

Provider identifiers, LEI and parent - 18 fields

RT.05.02

Critical subcontractors - 17 fields

DORA and eramba: resilience management - the full guide

Try it before you talk to anyone

Download the DORA package as a CSV and import it into the free Community edition. The guide summarises every article and names the module that carries it, so you can check our claims against your own scope.

Know the gaps before the supervisor does

Flat annual price. Unlimited users, unlimited frameworks, every module included. Your bill does not grow with your team.

  • 39,033 downloads last year
  • 641 enterprise users
  • 11 releases last year
  • Used for ISO, PCI and SOC 2 since 2015

Pricing

Flat annual price. Unlimited users, unlimited data, every module included. Your bill does not grow with your team.

Community

Free

Self-hosted. No user limit, no time limit.

Download

Enterprise on-premises

from 2500€/year

Runs on your infrastructure, with support and updates.

See pricing

Enterprise SaaS

from 5000€/year

Hosted and operated by eramba, in the EU.

See pricing

Contact us

A practitioner answers, not a sales sequence.