DORA, Regulation (EU) 2022/2554
DORA logging and ICT resilience for Windows estates, without adding a vendor dependency.
DPLens collects Windows security telemetry and delivers it to your SIEM through outages, with no cloud control plane and no licensing service in the path. That supports DORA's detection and logging expectations and keeps the agent simple to assess as an ICT third party.
- Detection
- Logging
- Continuity
- ICT third-party risk
In short
DPLens supports DORA logging and ICT resilience on Windows: it collects the logs financial entities need to detect anomalous activity and investigate incidents, and delivers them through outages with a disk-backed cache, failover and a tamper-evident record of its own changes. For ICT third-party risk, it is self-hosted software with no connection back to its vendor, verifiable releases and open output formats. Your ICT risk management framework, incident classification and reporting stay with you.
This page relates DPLens features to DORA as we read it. It is not legal or regulatory advice. Your compliance function, counsel and competent authority decide what your obligations are and whether you meet them. DPLens Ltd holds no certification, and using DPLens does not confer one.
The regulation
What DORA asks for
A paraphrase of the provisions that touch logging and log collection.
Art. 6
An ICT risk management framework
A documented framework of strategies, policies, procedures, protocols and tools to protect ICT assets. The regulatory technical standards on the ICT risk management framework (Commission Delegated Regulation (EU) 2024/1774) add detail, including on logging and on ICT change management.
Art. 9–10
Protection and detection
Measures that protect the security and integrity of data, including in transit, and mechanisms that promptly detect anomalous activity, with several layers of control and defined alert thresholds.
Art. 11–12, 17
Response, recovery and incident management
Business continuity and recovery arrangements, backups, and a process to detect, manage, record and learn from ICT-related incidents.
Art. 28
ICT third-party risk
Manage the risk from ICT third-party service providers as part of the framework, keep a register of information about those arrangements, and have exit strategies for them.
Control map
DORA mapping
| Requirement | How DPLens supports it | What you do |
|---|---|---|
| Art. 10 Detection of anomalous activity | Collects any Windows Event Log channel, log files, inbound syslog and NetFlow/IPFIX, plus scheduled file integrity monitoring, and delivers them to your SIEM. Collection coverage shows a source that is producing nothing. | Detection rules, alert thresholds and the people who respond to them |
| Logging (RTS on the ICT risk management framework) | Reliable collection with timestamps normalised to UTC; logs leave the host as they are collected; every drop counted and attributed | A logging policy: what to log, for how long, and how logs are protected in your SIEM |
| Art. 9 Protection of data in transit | TLS with certificate validation on by default; mutual TLS where the receiver requires it; masking before egress | Use TLS on every destination that supports it |
| Art. 11–12 Continuity and recovery | Per-destination disk cache, ordered failover with failback, delivery to several destinations at once, and a pause-collection policy that holds events in Windows rather than losing them. Configuration is held centrally in DPLens Manager. | Size caches for your tolerance, back up configuration, and test recovery |
| Change management (RTS) | Changes are staged, the full configuration is validated before it applies, a failed apply can be rolled back, and every apply is recorded in the tamper-evident audit trail | Your change approval process, and keeping configuration under change control |
| Art. 17 Incident management | Delivers the host evidence an investigation needs; the agent's own audit log shows who changed collection and when | Incident classification and reporting under Articles 18 and 19 |
| Art. 28 ICT third-party risk | No telemetry, no licensing service, no cloud control plane, and upgrades only when you roll them out, with DPLens Manager or your own tools. Signed releases with checksums and CycloneDX and SPDX SBOMs. Output in open formats (syslog, Snare, NDJSON, OpenTelemetry's OTLP) eases exit. | Your register of information, contract terms and exit plan, and deciding how licensed self-hosted software is recorded there |
Concentration and dependency
Running independently of its vendor
Once installed, the agent needs nothing from us to keep running. The licence is verified offline, upgrades happen only when you roll out a package you have downloaded and verified, and the agent connects only to your destinations (and, if you add the optional public-IP enrichment, to an endpoint you choose). DPLens Manager, which gives you central configuration, fleet health monitoring, deployment and upgrades, is self-hosted and air-gap capable too.
The one date to plan for is licence renewal. The agent warns 30 days before a licence expires and allows 7 days' grace after it, with every step recorded in the audit trail. Track renewal dates alongside your other contracts.
Because output is standard syslog, Snare, NDJSON or OTLP to an OpenTelemetry Collector, you can change SIEM and keep the agent, or change agent and keep the SIEM. For offline operation in practice, see air-gapped log collection; for how the software is built and signed, see the Trust Centre; and for the logging controls themselves, see Windows Event Log collection.
FAQ
Questions financial entities ask
Does DORA apply to UK firms?
DORA is EU law. It applies to in-scope financial entities in the EU, including EU subsidiaries of UK groups. Firms regulated only in the UK work to the UK's own operational resilience rules instead; ask your compliance team which applies to you.
Is DPLens Ltd an ICT third-party service provider to us?
That depends on how DORA's definitions apply to your arrangement, which is for you and your counsel. What we can tell you is factual: the software is self-hosted, sends no data to us and needs no service from us to run.
What happens to logs during a SIEM outage?
On TCP and TLS destinations, events queue in that destination's disk cache and are delivered when it recovers. If the cache fills, the policy you chose applies: pause collection, drop oldest or drop newest. Every drop is counted.
Can we evidence who changed log collection?
Yes. Every configuration apply and rollback is recorded in the tamper-evident audit trail with the account and a UTC time, and the console shows whether it verifies.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.