Resilience & availability readiness
We get your company ready for what your financial-sector customers in the EU and your enterprise customers in the US ask about resilience and availability: which services matter, how long each one can be down and how recovery is tested, with evidence you can share.
Your customers ask how your service recovers, and they want evidence
A bank in the EU sends a contract annex on resilience. A US customer asks for availability evidence. Both want to know which services matter, how long each one can be down and how you test that recovery works.
DORA, the EU regulation on digital operational resilience for the financial sector (Regulation (EU) 2022/2554), reaches a supplier outside the EU only through the contract with its financial-entity customer (arts. 28 and 30), unless the European Supervisory Authorities designate that supplier as a critical information and communication technology (ICT) third-party service provider (art. 31).
In the US, a customer may ask for a System and Organization Controls (SOC) 2 report that covers the availability criteria (A1.1 to A1.3) of the Trust Services Criteria of the American Institute of Certified Public Accountants (AICPA). That report is the result of an examination performed by a certified public accountant (CPA) firm.
If you hold or are pursuing ISO/IEC 27001, the international standard for information security management, its control A.5.30, ICT readiness for business continuity, asks for ICT readiness to be planned, implemented, maintained and tested based on your business continuity objectives and ICT continuity requirements.
Gradiente prepares your company and its evidence. The SOC 2 report is issued by the CPA firm after its examination, and ISO/IEC 27001 certification by an accredited certification body.
With that base, you answer each customer with evidence of how your services recover.
What you receive
- DORA contract-readiness memoYour customer's clauses, read against DORA: the minimum terms for every ICT services contract (art. 30(2)) and the additional ones when your service supports a critical or important function (art. 30(3)), mapped to what you already have in place.
- Availability gap reportA short business impact analysis (BIA) of the services your customers contract, with the recovery time objective (RTO) and the recovery point objective (RPO) of each one; where your evidence stands against SOC 2 criteria A1.1 to A1.3 and ISO/IEC 27001 control A.5.30; and what to close first.
- Recovery test plan & evidence packWhat gets tested, in which scenario and in what order, and the dated evidence each test leaves: scope, conditions, result and corrective actions.
- Customer questionnaire responsesAnswers to your customers' resilience and availability questions, each one backed by the evidence that supports it.
How it works
-
We agree on the scope with you: which services your customers contract, which customer requests you need to answer, and whether SOC 2, ISO/IEC 27001 or both apply.
-
We read your customers' contract clauses and questionnaires and run the short business impact analysis of the services in scope.
-
We measure the gap against the applicable clauses and criteria and agree with you on what to close first.
-
We prepare the recovery test plan. Your engineering team or your provider runs the technical recovery tests; we design them, observe them and document their evidence.
-
We prepare the answers to your customers' questionnaires and, if you decide, we repeat the test cycle each year: your team runs the tests and we document their evidence.
What defines the scope
- How many of the services your customers contract are in scope.
- Whether the work covers SOC 2, ISO/IEC 27001 or both.
- How many customer contracts and questionnaires you need to answer.
- Whether our support for the yearly tests is added.
How to engage
The readiness assessment has a fixed fee, and closing the gaps it finds is a separate project. After that, if you decide, we support the yearly tests and document their evidence as an annual program.
References
- DORA · Regulation (EU) 2022/2554 · arts. 28, 30 and 31
- AICPA Trust Services Criteria · A1.1 to A1.3
- ISO/IEC 27001:2022 · A.5.30
Related services
Governance, risk and compliance
ISO/IEC 27001, ISO/IEC 42001 and ISO 22301: from zero to prepared for certification with an accredited body.
ISO readiness
Governance, risk and compliance
Chief information security officer (CISO), data protection officer (DPO) and governance, risk and compliance (GRC).
Fractional compliance
AI
Which AI your company uses, what data it touches, its risks and the gap against ISO/IEC 42001.
AI governance readiness
Let's talk about what your customers are asking.
In 30 minutes we review where you stand and suggest where to start.