DORA

DORA: inventory and monitor your exposed ICT assets

In force since January 2025, the EU's Digital Operational Resilience Act requires financial entities to manage ICT risk rigorously: asset identification, continuous vulnerability management, resilience testing. Purplemet addresses these specific requirements for your web perimeter — continuously, without intrusion, without configuration.

Zero configuration
Non-intrusive
Continuous monitoring

DORA at a glance

What DORA requires,
in three points

  1. Applicable since 17 January 2025 Regulation (EU) 2022/2554 applies to banks, insurers, asset managers, investment and payment service providers… and their critical ICT third parties.
  2. ICT risk management at the core Identify and inventory the assets and functions supported by information systems, detect vulnerabilities, monitor continuously, and test resilience — up to threat-led penetration testing (TLPT) for the most critical entities.
  3. Third-party ICT risk A register of information on providers, and ongoing oversight of ICT outsourcing risk across the value chain.

Where Purplemet fits

We address specific DORA requirements on your web perimeter

No tool "makes you DORA compliant" on its own — compliance spans governance, contracts, incident management and more. On the specific perimeter of your web attack surface, however, Purplemet addresses identifiable requirements.

  • ICT asset identification DORA expects an inventory of the assets and systems supporting your functions. Purplemet continuously discovers your exposed web applications — including those deployed by a subsidiary or a provider, or forgotten after a project. Your web asset inventory stops being declarative: it is observed and kept current.
  • Vulnerability management Purplemet inventories the technology stack of each exposed application (frameworks, CMS, libraries — and their versions) and continuously matches it against published vulnerabilities: you know the same day whether a component of your perimeter is affected by a new CVE.
  • Digital operational resilience testing Purplemet prepares and focuses your tests — penetration tests and, where applicable, TLPT — by identifying the applications and components most at risk: every day of expert time is invested where it counts.
  • Web services operated by third parties Web applications built or hosted by your providers are part of your attack surface. Purplemet makes visible the actual state of these exposed assets, complementing your contractual oversight of ICT third partie
Faq

Common questions about DORA and Web ASM

Does Purplemet make me DORA compliant?

No — no tool can, and we don't claim to. DORA covers governance, provider contracts, incident reporting and resilience testing. Purplemet addresses specific requirements of the ICT risk management pillar on the web perimeter: the identification of exposed assets and the continuous management of their vulnerabilities, in particular.

Who is in scope of DORA?

Financial entities in the broad sense — credit institutions, insurers, asset managers, investment, payment and crypto-asset service providers — as well as their critical ICT third-party providers. The regulation has applied since 17 January 2025.

What is the link between DORA and the web attack surface?

ICT asset identification and vulnerability management — two central DORA requirements — presuppose knowing precisely which applications your organization exposes on the internet and which technologies run on them. That is what web attack surface management does.

Your facility's internet exposure, under control —
for good.

Your facility's internet exposure,under control — for good.