NIS2 supply chain security and your ICT providers
The NIS2 Directive asks essential and important entities to manage cybersecurity risk, including the risk that comes from their suppliers. Art. 21 names supply chain security among the measures. Art. 23 sets the reporting steps for a significant incident: an early warning within 24 hours, a notification within 72 hours and a final report within a month.
Both depend on your providers. You need to know how a provider secures its service, and you need its facts fast when something goes wrong. Pilae documents the first in the security page and the measures annex of our DPA. It commits to the second in your contract.
DORA ICT third-party risk requirements
DORA has applied to EU financial entities since 17 January 2025. Art. 28 asks you to keep a register of information on every ICT third-party arrangement and to have exit strategies for services that support critical or important functions. Art. 30 lists what the contract must contain.
Your contract with Pilae covers those terms: a clear description of the service, the locations of data and processing, service levels, access to and return of data, assistance with ICT incidents, cooperation with your competent authority, audit rights and termination rights. We deliver the data your register records and update it when anything changes. For groups also supervised in Switzerland, see FINMA outsourcing.
Incident reporting you can meet on time
Monitoring runs around the clock on every plan: probes every 60 seconds, machine metrics, and alerts that reach Pilae engineers at any hour. When an incident affects your service, we notify you without undue delay. You then receive the timeline, the impact and the actions taken as we learn them, so your report is ready before your deadline. The Enterprise plan adds around-the-clock incident response. For detection across your own estate, we also run Wazuh as a SIEM, and OpenBao keeps the secrets your services use in one audited place.
Exit strategies and resilience testing
An exit strategy that has never run is a document, not a strategy. Every app Pilae operates is open source or source-available, and exports are in open formats. Our exit plan service documents how each function moves, and we rehearse it with you.
Backups are tested every month. An engineer restores your apps from backup into an isolated environment and records the result in the console. On request we take part in your own scenario tests. Your data can stay in the EU on dedicated machines in an EU region such as Frankfurt or Gravelines, as described under data residency and GDPR.
For a proposal, see pricing or talk to us.