Overview
The Cyber and Operational Resilience (COR) Compliance Package is a comprehensive toolkit designed to help customers better manage third-party risk. The package was built to meet increased oversight and due diligence requirements set forth by the Digital Operational Resilience Act (DORA) regulation in the European Union (EU). Under the DORA regulations, financial entities in the EU, including regulated Crypto Asset Providers, must manage third-party risks related to Information and Communication Technology (ICT) vendors, especially those supporting critical or important functions within the financial institutions.
Should you consider Fireblocks a third-party ICT provider, the COR Compliance Package provides an enhanced solution for effectively meeting your DORA obligations. Some key components are shown below.
Pre-drafted legal addendum
Simplify regulatory compliance with a ready-to-use legal addendum based on the contractual arrangements outlined in Article 30 of DORA. This includes Fireblocks’ commitments toward you in the areas of incident reporting, business continuity procedures, audit rights, personnel training, procedures, and more.
Periodic reporting
A comprehensive reporting framework based on the requirements of DORA. Stay informed and monitor Fireblocks’ performance and service, such as periodic updates on ICT service metrics, ICT support level metrics, and ICT security reporting.
Annual reporting and security kit
Gain comprehensive tools and insights to maintain your security posture and demonstrate compliance. This includes an extensive Fireblocks Information Security Management System overview, reporting on BCP and Emergency Plan Testing, and Pen Testing executive summaries. All applicable Fireblocks certifications, including SOC 2, CCSS, and ISO certifications are also included.
As-needed notifications
Receive timely alerts for incidents regarding thresholds laid out in DORA regulations for ICT-related security incidents, compliance requirement changes, or any operational updates.
Annual Fireblocks-hosted security pooled audit
Includes access for one participant to a multi-day, in-person event for comprehensive operational insights into Fireblocks’ security practices, including:
- Deep-dive operational understanding
- Exclusive ICT security sessions
- Unique walkthroughs of security processes
- Direct engagement with senior Fireblocks security personnel
- Follow-up period for additional inquiries
Contact your Customer Success Manager to learn more.
FAQ
-
When can we expect to receive the periodic and/or annual reports?
We aim to have our reporting available to you 30 days from the end of the reporting period, which is the end of a quarter or year.
-
Does Fireblocks report anything directly to the regulators?
Fireblocks does not by default report or share information directly with regulators. Any information sharing falls under either i) an enforcement or regulatory investigation initiated by the regulator or ii) a customer audit.
-
What can we expect from the Annual Security Pooled Audit event?
The event is designed to serve as grounds for a pooled audit by you, where you can send internal or external auditors to report back with an official audit report.
On top of “regular” audit content, the event includes exclusive content that is not otherwise shareable and allows you to engage directly with senior Security personnel.