TPRM per EBA guidelines
Contract register with 19 EBA mandatory fields, subcontractor chains, AI-assisted contract analysis, concentration-risk heatmap, exit strategies. Outsourcing register on demand.
DORA has required resilient ICT operations since January 2025, with documented third-party risk and concentration risk analysis. Our vCISO leads your DORA implementation and works with OdySecure, the security platform by Cybervize. The TPRM module is aligned with the EBA draft CP/2025/12 (not final); MaRisk and NIS-2 run in the same control set.
Book the DORA classificationFour areas where your vCISO avoids duplicate work because OdySecure serves the requirements in parallel.
Contract register with 19 EBA mandatory fields, subcontractor chains, AI-assisted contract analysis, concentration-risk heatmap, exit strategies. Outsourcing register on demand.
ICT risk management framework, incident classification, resilience testing, critical functions, supplier impact analysis. Covered through the ISMS and TPRM modules.
Templates for BaFin filings, documented board involvement, compliance status against DORA and MaRisk. Consolidated at group, subsidiary and tenant level.
From the financial sector, Annex 1 to the German BSIG covers credit institutions, trading venues and central counterparties, and these are as a rule also subject to DORA. § 28 Abs. 6 Nr. 1 BSIG exempts them from named duties, not from the status. § 33 BSIG is not on the exemption list: registration remains, provided the company counts as an essential or important entity under the BSIG. Insurers and payment institutions, conversely, do not become Annex 1 entities merely because DORA applies to them. The assessment runs per legal entity, not per group: a carved-out IT or SOC company carries its own classification. The platform serves both regimes from a single control mapping.
Financial services typically start with a focused initial call on the DORA and NIS-2 position.
Free initial call: DORA scope, EBA outsourcing obligations, BaFin reporting paths and a path recommendation.
Learn moreA senior CISO fills the CISO role permanently, with the platform included. For organisations without an in-house CISO.
Learn moreFor a temporary gap, for example ahead of an audit, an Interim CISO fills the role. €8,000 to €15,000 per month, project-based.
Learn moreISMS, compliance and evidence from a single platform. Multi-entity, multi-country, multilingual.
Learn moreFor DORA-regulated firms, each legal entity has to be checked for a parallel classification under § 28 BSIG. Where that classification exists, registration under § 33 BSIG remains required. Where the carve-out in § 28 Abs. 6 Nr. 1 BSIG does not apply either, the full NIS-2 programme comes on top: gap assessment, roadmap, implementation via the platform. Fixed price from 4,500 euros.
Learn moreFour arguments from the regulated financial context.
“Alexander Busse supported us with Cybervize as Interim CISO in the DORA implementation and the ISO 27001 audit. We achieved both.” (Lorenz Jüngling, Co-CEO & Managing Director, Moonfare; translated from the German original)
Platform evidence is built for the audit situation: timestamp, owner and version on every entry.
Contract register with 19 EBA mandatory fields, subcontractor chains, documented due diligence, concentration risk and exit strategies. Outsourcing register on demand.
Local LLMs for contract analysis and measure generation. In Sovereign mode, the default, no data is shared with external model providers; BYOK and Managed are available as alternatives. GDPR-compliant, hosting in Germany.
OdySecure has a TPRM module aligned with the EBA draft CP/2025/12 (not final) that captures the 19 mandatory fields in the outsourcing register.
Not in substance. § 28 Abs. 6 Nr. 1 of the German BSIG exempts DORA financial entities from §§ 30, 31, 32, 35, 36, 38 and 39 BSIG: ICT risk management and incident reporting run under DORA via BaFin. That is statutory non-application, not mere overlap in substance, and it does not touch any status as an entity. What remains is registration under § 33 BSIG, provided your company counts as an essential or important entity under the BSIG; entity type and size thresholds decide that. DORA alone does not make a company an Annex 1 entity. Management responsibility does not fall away either: DORA assigns it to the management body itself, including regular ICT risk training. The platform maps both regimes from one control set, so reporting does not have to run in parallel.
Contract register with 19 EBA mandatory fields, subcontractor chains, AI-assisted contract analysis, concentration-risk heatmap, documented exit strategies. Outsourcing register on demand for the regulator.
Multi-entity architecture for group structures, subsidiaries and international sites. Consolidated supervisory report at group, subsidiary and tenant level.
AI models are self-operated in Sovereign mode, with no data sharing with external model providers; alternatively BYOK or Managed, where you define the data flow. Bring your own API keys (OpenAI, Azure, Anthropic, Ollama) or managed service with German data residency. GDPR-compliant with anonymisation and scheduled deletion.
API integration with existing GRC and reporting tools (RSA Archer, MetricStream, ServiceNow GRC). Three migration scenarios: co-existence, gradual replacement, full migration. Reports can be exported automatically into supervisory workflows.
Free initial call with indicative classification on DORA scope, NIS-2 status, EBA outsourcing obligations and path recommendation. Ideally with IT risk management plus compliance present.
Book the DORA classificationExperienced C-level security leadership, 2 to 6 days a month, with the platform as the working tool.
Learn moreImmediate security expertise for transition phases and critical projects.
Learn moreAnalysis of your IT security posture with an actionable roadmap.
Learn more