DORA, Regulation (EU) 2022/2554

DORA logging and ICT resilience for Windows estates, without adding a vendor dependency.

DPLens collects Windows security telemetry and delivers it to your SIEM through outages, with no cloud control plane and no licensing service in the path. That supports DORA's detection and logging expectations and keeps the agent simple to assess as an ICT third party.

  • Detection
  • Logging
  • Continuity
  • ICT third-party risk

In short

DPLens supports DORA logging and ICT resilience on Windows: it collects the logs financial entities need to detect anomalous activity and investigate incidents, and delivers them through outages with a disk-backed cache, failover and a tamper-evident record of its own changes. For ICT third-party risk, it is self-hosted software with no connection back to its vendor, verifiable releases and open output formats. Your ICT risk management framework, incident classification and reporting stay with you.

Not legal or audit advice.

This page relates DPLens features to DORA as we read it. It is not legal or regulatory advice. Your compliance function, counsel and competent authority decide what your obligations are and whether you meet them. DPLens Ltd holds no certification, and using DPLens does not confer one.

Last reviewed 1 October 2026.

The regulation

What DORA asks for

A paraphrase of the provisions that touch logging and log collection.

Art. 6

An ICT risk management framework

A documented framework of strategies, policies, procedures, protocols and tools to protect ICT assets. The regulatory technical standards on the ICT risk management framework (Commission Delegated Regulation (EU) 2024/1774) add detail, including on logging and on ICT change management.

Art. 9–10

Protection and detection

Measures that protect the security and integrity of data, including in transit, and mechanisms that promptly detect anomalous activity, with several layers of control and defined alert thresholds.

Art. 11–12, 17

Response, recovery and incident management

Business continuity and recovery arrangements, backups, and a process to detect, manage, record and learn from ICT-related incidents.

Art. 28

ICT third-party risk

Manage the risk from ICT third-party service providers as part of the framework, keep a register of information about those arrangements, and have exit strategies for them.

Control map

DORA mapping

DORA provisions mapped to DPLens capabilities and what you do
RequirementHow DPLens supports itWhat you do
Art. 10 Detection of anomalous activityCollects any Windows Event Log channel, log files, inbound syslog and NetFlow/IPFIX, plus scheduled file integrity monitoring, and delivers them to your SIEM. Collection coverage shows a source that is producing nothing.Detection rules, alert thresholds and the people who respond to them
Logging (RTS on the ICT risk management framework)Reliable collection with timestamps normalised to UTC; logs leave the host as they are collected; every drop counted and attributedA logging policy: what to log, for how long, and how logs are protected in your SIEM
Art. 9 Protection of data in transitTLS with certificate validation on by default; mutual TLS where the receiver requires it; masking before egressUse TLS on every destination that supports it
Art. 11–12 Continuity and recoveryPer-destination disk cache, ordered failover with failback, delivery to several destinations at once, and a pause-collection policy that holds events in Windows rather than losing them. Configuration is held centrally in DPLens Manager.Size caches for your tolerance, back up configuration, and test recovery
Change management (RTS)Changes are staged, the full configuration is validated before it applies, a failed apply can be rolled back, and every apply is recorded in the tamper-evident audit trailYour change approval process, and keeping configuration under change control
Art. 17 Incident managementDelivers the host evidence an investigation needs; the agent's own audit log shows who changed collection and whenIncident classification and reporting under Articles 18 and 19
Art. 28 ICT third-party riskNo telemetry, no licensing service, no cloud control plane, and upgrades only when you roll them out, with DPLens Manager or your own tools. Signed releases with checksums and CycloneDX and SPDX SBOMs. Output in open formats (syslog, Snare, NDJSON, OpenTelemetry's OTLP) eases exit.Your register of information, contract terms and exit plan, and deciding how licensed self-hosted software is recorded there

Concentration and dependency

Running independently of its vendor

Once installed, the agent needs nothing from us to keep running. The licence is verified offline, upgrades happen only when you roll out a package you have downloaded and verified, and the agent connects only to your destinations (and, if you add the optional public-IP enrichment, to an endpoint you choose). DPLens Manager, which gives you central configuration, fleet health monitoring, deployment and upgrades, is self-hosted and air-gap capable too.

The one date to plan for is licence renewal. The agent warns 30 days before a licence expires and allows 7 days' grace after it, with every step recorded in the audit trail. Track renewal dates alongside your other contracts.

Because output is standard syslog, Snare, NDJSON or OTLP to an OpenTelemetry Collector, you can change SIEM and keep the agent, or change agent and keep the SIEM. For offline operation in practice, see air-gapped log collection; for how the software is built and signed, see the Trust Centre; and for the logging controls themselves, see Windows Event Log collection.

FAQ

Questions financial entities ask

Does DORA apply to UK firms?

DORA is EU law. It applies to in-scope financial entities in the EU, including EU subsidiaries of UK groups. Firms regulated only in the UK work to the UK's own operational resilience rules instead; ask your compliance team which applies to you.

Is DPLens Ltd an ICT third-party service provider to us?

That depends on how DORA's definitions apply to your arrangement, which is for you and your counsel. What we can tell you is factual: the software is self-hosted, sends no data to us and needs no service from us to run.

What happens to logs during a SIEM outage?

On TCP and TLS destinations, events queue in that destination's disk cache and are delivered when it recovers. If the cache fills, the policy you chose applies: pause collection, drop oldest or drop newest. Every drop is counted.

Can we evidence who changed log collection?

Yes. Every configuration apply and rollback is recorded in the tamper-evident audit trail with the account and a UTC time, and the console shows whether it verifies.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.