Identity alongside DORA
Financial entities use QES and strong authentication for onboarding, loan files and board decisions. DORA governs ICT resilience; eIDAS governs trust services — both touch vendors, logging and incident reporting.
Contracts and chain
Map QTSPs and identity SaaS in the DORA ICT risk register. Exit and concentration risk apply to signing platforms too — test QES provider outage during closings.
Audit and supervision
Show QES processes linked to internal control and certificate/key incidents registered. Supervisors and ISO 27001 surveillance ask for the same evidence chain.
Checklist
- Inventory eID, QES and QTSP use
- Map vendors and trust list status
- Link to ISMS, GDPR and risk register
- Plan DPIA where wallet or identity data
- Test fallback and incident scenarios
Practical next step
For eIDAS 2.0 financial sector, ISO Ready links identity, trust and security measures in one ISMS — with actions, evidence and vendors toward audit. Run the readiness scan on iso-ready.nl.
More on eIDAS 2.0
- Eidas2 Compliance
- Dora Compliance
- Dora
- Qualified Electronic Signature
- Iso 27701 Privacy Management
- Iso Audit Evidence