DORA Article 28: Documenting Microsoft as a Critical ICT Third Party on Azure
How to register Microsoft as a critical ICT third party under DORA Article 28, run the criticality test, and review Azure contracts against Article 30. For ICT risk leads.
How to register Microsoft as a critical ICT third party under DORA Article 28, run the criticality test, and review Azure contracts against Article 30. For ICT risk leads.
DORA Article 11 requires a continuous ICT risk-management framework tied to your live Azure tenant: current asset register, per-workload recovery objectives, and Microsoft on your Article 28 register. What DNB actually asks to see.
A CNAPP tells you which resources are exploitable right now. It does not tell you whether your architecture should have been built that way. This is where runtime detection ends and design-time assessment begins.
A fair read on Microsoft Defender for Cloud NIS2 compliance: strong first-party standards, real gating and scope limits. For security leads. With a coverage table.