Skip to content

Business solution

DORA ICT-vendor evidence

Prepare reusable ICT-vendor evidence for customers operating under DORA.

The DORA solution helps an ICT provider organise identity, service, resilience and supporting evidence into a reusable review pack for financial-sector customers and their procurement or risk workflows.

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal.

For agent operators

Why it matters when the subject is an AI agent.

If you supply an agent, or an agent platform, to banks, insurers or investment firms in the EU, you sit in their ICT third-party picture. Their reviews will ask who operates the agent, what it depends on and how changes are evidenced. This solution organises those answers around the agent's persistent identity.

The questions it helps answer

  • What do our financial-sector customers need from us as an ICT provider?
  • How do we stop answering the same resilience questionnaire from scratch?

Fit

Who it is for, and what changes.

Best for

  • Technology suppliers selling ICT services — agents included — into EU-regulated financial entities.
  • Teams repeatedly answering the same vendor-risk and operational-resilience questions.
  • Providers that want a structured evidence pack rather than a loose collection of attachments.

Outcomes

  • Faster preparation for customer ICT-vendor reviews.
  • More consistent evidence across repeated questionnaires and procurement cycles.
  • A clearer link between the supplier identity, the service and its supporting evidence.

Inside

What is included, and how it works.

What is included

  • Structured DORA-oriented vendor evidence organisation.
  • Reusable identity and service context from the ECZ-ID estate.
  • Evidence packaging suitable for customer review workflows.
  • Paths for managed and enterprise depth where the requirement is larger.

How it works

  1. Define the ICT service and the customer review context.
  2. Map the evidence you already hold and identify material gaps.
  3. Organise eligible evidence into a reusable review structure.
  4. Maintain the evidence set as the service and supplier relationship change.

Boundaries

What the FREE Passport already gives you, and what this never does.

Already included free

Nothing of this product is part of the free Passport — but the persistent ECZ-ID, the accountable operator and the public Resolver record it builds on always are.

£0 · No card required · Permanent, not a trial.

What it never does

  • ECZ-ID supports evidence preparation and review; it does not certify DORA compliance.
  • The regulated entity and its advisers remain responsible for their own legal and risk conclusions.
  • Identifying an agent is not controlling it. ECZ-ID does not authorise, restrict, supervise, pause or stop what an agent does — its operator and the party relying on it stay responsible for that.

Related

Read next.

  • Counterparty

    DCI — Digital Counterparty Infrastructure

    DCI combines identity, public proof and reusable evidence around the digital surface a counterparty actually encounters — such as a website, API, portal or machine service.

    Boundary: DCI is identity and evidence infrastructure; it is not a counterparty risk score or approval.

  • Software supply chain

    SBOM & software-composition evidence

    The SBOM solution organises software-component, dependency and provenance evidence around the digital product being supplied, so reviewers can understand what is in scope and what changed.

    Boundary: An SBOM describes composition and evidence; it is not a declaration that software is secure.

Every Agent product

Start with the identity. Add DORA ICT-vendor evidence when it earns its place.

£0 · No card required · Permanent, not a trial.