NIS2 and DORA compliance support from your ICT provider

Pilae gives EU entities the contract terms, records and cooperation that NIS2 supply chain rules and DORA third-party risk rules expect from an ICT provider.

Talk to our teamRequest the security pack

NIS2
Directive (EU) 2022/2555
DORA
Regulation (EU) 2022/2554, applied since 17 January 2025
Pilae role
ICT third-party service provider
Hosting
Any of 12 Pilae Cloud regions, six in Switzerland and the EU, or your premises

What Pilae delivers for your NIS2 and DORA obligations

Both texts put the obligations on your entity and ask you to manage the risk your ICT providers bring. These are the parts that depend on us, and what we deliver for each.

Incident reporting support

We tell you about an incident affecting your service without undue delay, with the facts, timeline and impact you need for the reports your authority expects.

Register of information data

Our legal entity details, the services we provide, the functions they support, locations of data and processing, and every subcontractor in the chain.

Contract terms DORA art. 30 lists

Service description, locations, service levels, access and return of data, incident assistance, cooperation with authorities, audit and termination rights.

Exit strategies

A documented, tested exit for each app, with data in open formats and a transition period written into the contract.

Resilience testing

Monthly restore tests recorded in the console, and our participation in your own tests and scenarios on request.

Supply chain transparency

Each sub-processor disclosed to you in the DPA with its role and location. Changes notified in advance, with a right to object.

NIS2 supply chain security and your ICT providers

The NIS2 Directive asks essential and important entities to manage cybersecurity risk, including the risk that comes from their suppliers. Art. 21 names supply chain security among the measures. Art. 23 sets the reporting steps for a significant incident: an early warning within 24 hours, a notification within 72 hours and a final report within a month.

Both depend on your providers. You need to know how a provider secures its service, and you need its facts fast when something goes wrong. Pilae documents the first in the security page and the measures annex of our DPA. It commits to the second in your contract.

DORA ICT third-party risk requirements

DORA has applied to EU financial entities since 17 January 2025. Art. 28 asks you to keep a register of information on every ICT third-party arrangement and to have exit strategies for services that support critical or important functions. Art. 30 lists what the contract must contain.

Your contract with Pilae covers those terms: a clear description of the service, the locations of data and processing, service levels, access to and return of data, assistance with ICT incidents, cooperation with your competent authority, audit rights and termination rights. We deliver the data your register records and update it when anything changes. For groups also supervised in Switzerland, see FINMA outsourcing.

Incident reporting you can meet on time

Monitoring runs around the clock on every plan: probes every 60 seconds, machine metrics, and alerts that reach Pilae engineers at any hour. When an incident affects your service, we notify you without undue delay. You then receive the timeline, the impact and the actions taken as we learn them, so your report is ready before your deadline. The Enterprise plan adds around-the-clock incident response. For detection across your own estate, we also run Wazuh as a SIEM, and OpenBao keeps the secrets your services use in one audited place.

Exit strategies and resilience testing

An exit strategy that has never run is a document, not a strategy. Every app Pilae operates is open source or source-available, and exports are in open formats. Our exit plan service documents how each function moves, and we rehearse it with you.

Backups are tested every month. An engineer restores your apps from backup into an isolated environment and records the result in the console. On request we take part in your own scenario tests. Your data can stay in the EU on dedicated machines in an EU region such as Frankfurt or Gravelines, as described under data residency and GDPR.

For a proposal, see pricing or talk to us.

How we prepare your third-party risk file

  1. Map the functions

    With your team we list each app, the business function it supports and whether you classify it as critical or important.

  2. Fill the register

    We deliver the provider, service, location and subcontractor data your register of information records.

  3. Agree the contract

    The terms your framework requires, including audit rights, incident assistance, exit and termination, in one written agreement.

  4. Agree incident handling

    Contacts, notification channels and the information each notice carries, aligned with your reporting deadlines.

  5. Test

    Restore tests every month, and a rehearsal of the exit plan so your strategy is proven.

What your contract includes

Incident notification
Prompt notice of any incident affecting your service, with updates until it is closed and a final report.
Incident assistance
Help with classifying the incident and with the facts for each report to your authority.
Audit and access
Rights of information, inspection and audit for you, your auditors and your competent authority.
Service levels
99.9% monthly availability with service credits. Around-the-clock incident response on the Enterprise plan.
Locations
Every machine and backup target named per app, and not moved without your written agreement.
Exit and termination
Termination rights, a transition period, your data in open formats, then deletion with written confirmation.

The apps behind it

Questions

Does NIS2 or DORA apply to our organisation?

NIS2 applies to medium and large entities in the sectors its annexes list, and to some smaller ones designated by their Member State. DORA applies to EU financial entities such as banks, insurers, investment firms and payment institutions. Your legal team decides, and we supply the provider facts either answer needs.

How does Pilae help with incident reporting?

NIS2 asks for an early warning within 24 hours, a notification within 72 hours and a final report within a month. DORA sets its own deadlines for major ICT incidents. We notify you without undue delay, send the facts, timeline and impact as we learn them, and help you draft each report.

What do you give us for the DORA register of information?

Our legal entity details, the services we provide and the functions they support, where data is stored and processed, and each subcontractor with its role and location. We update it whenever something changes.

Is Pilae a critical ICT third-party provider under DORA?

No. Critical ICT third-party providers are designated by the European Supervisory Authorities, and Pilae has not been designated. Your contract still carries the terms DORA requires for services that support critical or important functions.

Can we exit without disruption?

Yes. Every app we operate is open source or source-available, and every export is in open formats. Your contract includes a documented exit plan and a transition period, and we rehearse the exit with you.

Does our data stay in the EU?

If you choose it, yes. Pilae Cloud has five EU regions, Frankfurt, Falkenstein, Gravelines, Amsterdam and Helsinki, with backups on a second site in the same jurisdiction. Zurich, six worldwide regions and your own premises are also available.

Related

Send us your third-party risk questionnaire.

An engineer answers it with the controls, locations and contract terms in place, and fills the provider data for your register.