gateDORA forensically seals that an ICT third-party onboarding passes six clusters, ICT risk management, incident reporting, TLPT, third-party register, subcontracting consent, and concentration risk, before the provider is connected. Support for financial entities, never a replacement for a regulator's own recognition as evidence.
DORA requires seamless control over ICT third-party providers, from the register duty to concentration risk review. gateDORA checks all six clusters before every onboarding, not only at the next audit.
Every cluster is dispositive (material_block_mode: true), a hit blocks bindingly, not merely for documentation.
All values on this page are fictional test data and serve only to illustrate the gate logic.
| Scenario | C1 | C2 | C3 | C4 | C5 | C6 | Verdict | Latency |
|---|---|---|---|---|---|---|---|---|
| Cloud provider, TLPT current, register complete, concentration risk low | PASS | PASS | PASS | PASS | PASS | PASS | DORA_SEALED | 478ms |
| Critical ICT provider without register entry | PASS | PASS | PASS | FAIL | not evaluated | not evaluated | BLOCK_DR4_REGISTER_ENTRY_MISSING | 401ms |