Table of Contents
How SurePay can help you be DORA complaint
- Bidisha Roy
- Utrecht
EU standard for ICT (third party) risk management
To boost the resilience of the financial sector, on 17 January 2025, the European law, known as DORA (Digital Operational Resilience Act) came into effect. DORA brought in uniform laws for financial entities regarding IT security, risk management and incident response – including IT risk management of services delivered by third parties. DORA sets an EU-wide technical standard for managing IT security risks and dependence on third parties, ensuring that the European financial sector remains resilient in the event of severe operational disruption.
DORA: a chain responsibility
DORA applies to financial entities and their critical third-party ICT service providers. We use the regulations as standard for our IT security risk management, information security management systems, and incident response procedures. We consider digital operational resilience a chain responsibility: a joint effort where customers can rely on our robust IT security risk and incident response management to meet their own regulatory requirements.
SurePay: reliance on continuity of VOP service
Non-compliance with DORA could lead to penalties and sanctions. Moreover, as of 9 October 2025, the Instant Payments Regulation came into effect. With this regulation, the EU emphasises the importance of VOP services, as it has become mandatory for payment service providers to use Verification Of Payee (VOP) services as part of the payment process. VOP services help to prevent payment fraud and misdirected payments and are there to make online payments more secure. SurePay is the pioneer of VOP services in the EU and had already been ahead of this development. As any disruption of such services would lead to non-compliance for its customers, SurePay has transitioned its technology and ICT risk management fit for purposes to safeguard reliance for its customers on continuity of delivered VOP services.
How SurePay can help you become DORA compliant
DORA introduced many requirements where, as your service provider, SurePay can help. By keeping your payments process secure, we give clients peace of mind about third party security vulnerabilities. We set DORA-equivalent standards and requirements on sound security risk management, and we expect the same from those we do business with.
Our clients can rely on two key-attributes to ensure digital operational resilience is both delivered and maintained:
- A robust security and risk posture
- Cooperation, consultation and transparency
Here’s how we do it.
Robust security and risk management framework
Our customers should not need to worry about how their data is handled. All they need to know is it is held and processed in a secure, controlled and confidential environment. To achieve this, SurePay has a state-of-the-art Information Security Risk Management (ISMS) in place, which includes:
Standards, procedures and measurements in place to identify, mitigate, monitor, report and remediate on security risks – which are appropriately documented and implemented in line with the ISO 27001 standard
A robust security incident management system
A ‘battle-tested’ disaster recovery plan
We also carry out periodic testing of our business continuity and disaster recovery plans to ensure they remain fit for purpose. This includes:
Performing regular testing of recovery plans for all services/products offered to its customers. These plans address timely recovery of products/services offered to the customer in accordance with agreed contractual requirements. SurePay has implemented multi-availability zones and multi-region setups in AWS for our critical services to meet agreed availability requirements.
Keeping track of our third party’s ICT risk management. We perform due diligence with subcontractors and vendors, or request evidence of security audit results (e.g. ISO 27001, ISAE 3000, SOC or any equivalent) demonstrating IT security standards are being met.
Obtaining the SOC 2 Type 2attestation every year, confirming our robust standards and the effectiveness from our ISMS by the (external) auditor. This SOC 2 Type 2 attestation is a standard that is underlined by the auditors who rely on it during the annual account audits.
Cooperation, consultation and transparency
Because achieving DORA compliance is a joint effort, we work closely with our customers to support their compliance journey. We take a proactive, consultative approach to maximize knowledge sharing, efficiency, and speed, allowing us to adapt quickly to future changes. We also integrate our customers’ insights on security risk mitigation to refine our own ICT risk management framework and VOP services. We are committed to transparency, helping our customers with their information needs by providing evidence of our IT security standards and supporting auditor inquiries. In the unlikely event of a security incident, we keep impacted clients fully informed with transparent reports on root causes, analysis, resolutions, and lessons learned, and we hold our business partners to these same high standards. Our customers tell us that this open partnership builds the confidence they need to optimize their own processes.
Final steps to support your DORA compliance
SurePay would take these final three steps to ensure that our customers meet the DORA requirements.
1. Communication
To prove that SurePay is the VOP service provider of choice, we will:
- Provide evidence of the appropriate ICT framework in place, in line with ISO standards, and by means of the SOC 2 type 2 attestation This verifies our effectiveness in monitoring, identifying, responding, treating and reporting on information security risks;
- Maintain transparency on both our policies and procedures to keep clients’ data secure, and any incidents related to their services to ensure minimal impact
- Respond to any information request within a reasonable timeframe.
2. Fine-tuning contracts
Contractual agreements with SurePay clients and relevant subcontractors will be reviewed and fine-tuned to ensure they are ‘DORA-proof’ and include all necessary details to assure our customers and SurePay’s third party risk can be properly managed.
3. Contingency planning for alternative solutions
SurePay is proactively investigating alternatives for our key subcontractors, such as cloud providers. This includes evaluating in-house solutions and establishing clear contingency plans to pivot to alternative providers when necessary.
While we already maintain a robust ICT risk management and incident response framework, this customer-centric approach elevates our security mitigation processes even further. We also conduct thorough due diligence and regular performance evaluations of our subcontractors.
As we approach the final stages of delivering a DORA-compliant service, our customers can rest assured that we are fully positioned to fulfill our value chain responsibilities. We are here not only to support your DORA compliance journey but to accelerate it, unlocking new potential for your business growth.