The Cyber and Operational Resilience (COR) Compliance Package is a toolkit that helps you manage third-party risk associated with using Fireblocks. It is built to meet the oversight and due diligence requirements of the EU's Digital Operational Resilience Act (DORA), which requires financial entities, including regulated Crypto Asset Providers, to manage risk from Information and Communication Technology (ICT) vendors supporting critical or important functions.
If Fireblocks is a third-party ICT provider for you under DORA, this package is built to help you meet those obligations.
What is included
- Pre-drafted legal addendum: a ready-to-use addendum based on the contractual arrangements in DORA Article 30, covering Fireblocks' commitments on incident reporting, business continuity, audit rights, personnel training, and more.
- Periodic reporting: a reporting framework covering ICT service metrics, ICT support level metrics, and ICT security reporting.
- Annual reporting and security kit: an overview of Fireblocks' Information Security Management System, BCP and Emergency Plan testing reports, penetration testing executive summaries, and Fireblocks' certifications (SOC 2, CCSS, and ISO).
- As-needed notifications: alerts for incidents meeting DORA's thresholds for ICT-related security incidents, along with compliance requirement changes and operational updates.
- Annual Fireblocks-hosted security pooled audit: access for one participant to a multi-day, in-person event covering deep-dive operational understanding, exclusive ICT security sessions, walkthroughs of security processes, direct engagement with senior Fireblocks security personnel, and a follow-up period for further questions.
Contact your Customer Success manager to learn more.
FAQ
The questions below are the ones readers ask most often.
When can we expect the periodic and annual reports?
Within 30 days of the end of the reporting period (the end of a quarter or year).
Does Fireblocks report anything directly to regulators?
Not by default. Information sharing only happens as part of a regulator-initiated enforcement or investigation, or a customer audit.
What can we expect from the Annual Security Pooled Audit event?
It is designed to serve as the basis for a pooled audit: you can send internal or external auditors to attend and report back with an official audit report. Beyond standard audit content, it includes exclusive material not otherwise shared, plus direct engagement with senior security personnel.