Skip to main content

DORA Compliance — Digital Operational Resilience Act

Last updated: April 2026

This document describes how FeatureSignals supports financial entities subject to the EU Digital Operational Resilience Act (DORA), which took effect January 17, 2025.

Applicability

DORA applies when FeatureSignals is used by financial entities (banks, insurance companies, investment firms, payment institutions, crypto-asset service providers) as an ICT third-party service provider.

Article 5 — ICT Risk Management Framework

Risk Identification

RequirementImplementation
ICT asset inventoryAll infrastructure components documented
ICT risk assessmentRisk register maintained (see ISO 27001 docs)
Dependency mappingSub-processor list with data flow documentation
Threat landscape monitoringCVE monitoring, security advisories

Risk Protection and Prevention

RequirementImplementation
Access controlRBAC with four roles, per-environment permissions
AuthenticationMFA (TOTP), SSO (SAML/OIDC), password policies
EncryptionTLS 1.3 in transit, AES-256 at rest
Vulnerability managementAutomated scanning (govulncheck, npm audit, Trivy)
Change managementGit-based workflow, CI/CD with automated testing

Detection

RequirementImplementation
Anomaly detectionLogin attempt monitoring, rate limiting alerts
Logging and monitoringStructured logging (slog), audit trail, health checks
Integrity monitoringSHA-256 chain hashing on audit entries

Response and Recovery

RequirementImplementation
Incident response planDocumented with severity levels and SLAs
Business continuityGraceful degradation (eval path survives failures)
Disaster recoveryDatabase backups, multi-region capability
Communication planCustomer notification timelines documented

Article 11 — ICT-related Incident Management

Incident Classification

SeverityCriteriaResponse Time
CriticalService unavailable, data breachImmediate
MajorPartial degradation, suspected breach30 minutes
MinorVulnerability found, policy violation4 hours

Incident Reporting

For major ICT-related incidents, FeatureSignals provides:

  • Initial notification within 4 hours of classification
  • Intermediate report within 72 hours
  • Final report within 1 month

Article 12 — Digital Operational Resilience Testing

Testing Program

Test TypeFrequencyScope
Vulnerability scanningEvery CI runFull codebase and dependencies
Penetration testingAnnualExternal-facing APIs and dashboard
Scenario-based testingSemi-annualTabletop exercises for incident response
Backup recovery testingQuarterlyDatabase restore verification

Threat-Led Penetration Testing (TLPT)

For financial entities subject to TLPT requirements:

  • FeatureSignals cooperates with TLPT exercises conducted by customers
  • On-premises deployment available for entities requiring full testing control
  • API documentation and architecture details available under NDA

Article 28 — ICT Third-Party Risk

Contractual Provisions

FeatureSignals Enterprise agreements include:

ProvisionCommitment
Service level descriptionsAvailability targets, performance SLAs
Data processing locationsSub-processor list with locations
Data protectionEncryption standards, access controls
Audit rightsCustomer may audit compliance annually
Subcontracting controlsSub-processor notification and approval
Exit strategyData export, transition assistance
Incident notificationTimelines per classification above

Information Register

FeatureSignals maintains an information register for DORA Article 28(3) containing:

  • All contractual arrangements with ICT sub-service providers
  • Types of ICT services provided
  • Criticality assessment of each service

Article 30 — Key Contractual Provisions

For customers classified as financial entities, our Enterprise agreement addresses:

  1. Clear description of all ICT services — Feature flag management, evaluation API, dashboard, SDKs
  2. Locations of data processing — Documented in sub-processor list
  3. Data security provisions — Encryption, access control, audit logging
  4. Service availability guarantees — Uptime SLA with monitoring
  5. Cooperation with competent authorities — Compliance with supervisory requests
  6. Exit and transition — Full data export capability, transition period

Resilience by Design

FeatureSignals' architecture inherently supports operational resilience:

CapabilityImplementation
Stateless serversHorizontal scaling, zero-downtime deployments
Evaluation cacheFlag evaluation continues during database outages
Graceful degradationEvaluation API unaffected by webhook/metrics failures
Self-hosted optionFull control over infrastructure and uptime
No vendor lock-inOpen source, OpenFeature compatible, standard SQL database

Contact

For DORA compliance inquiries: compliance@featuresignals.com