Critical by Designation by Kai London
DORA reaches beyond regulated firms to the providers they depend on. If you supply ICT services to financial entities, the contractual demands have already changed — and designation as critical brings direct oversight. This book explains the regime from the provider's side of the relationship.
What the book covers
Designation and what follows
How a provider comes to be treated as critical, and the oversight relationship that results.
Contractual requirements
The provisions financial entities must obtain — service levels, access, audit, incident notification, termination — and how to negotiate them realistically.
Subcontracting chains
Disclosure, control and flow-down where material parts of the service are delivered by others.
Register of information
What customers must record, and the data a provider should be ready to supply consistently.
Resilience testing and evidence
Supporting customers' testing programmes without exposing the estate or duplicating effort endlessly.
Exit and substitutability
Credible exit plans, data portability and transition assistance obligations.
General guidance, not legal advice; take qualified advice on your own position. Independent, with no endorsement by or affiliation with any regulator, supervisory or oversight authority.
Who it is for
Cloud, SaaS and managed-service providers to financial institutions, their legal, commercial and compliance teams, and the third-party risk functions at financial entities on the other side.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.