Effective from: September 2026
This Statement is published voluntarily by Cardway Technologies OÜ in its capacity as an ICT third-party service provider within the meaning of Recital 63 and Article 3(21) of Regulation (EU) 2022/2554 ("DORA"). Cardway Tech is not a financial entity within the scope of Article 2(1) of DORA and is not directly subject to DORA's regulatory obligations. This Statement is intended to assist Cardway Tech's regulated financial entity clients and partners in fulfilling their ICT third-party risk management obligations under DORA Articles 28–30.
Cardway Technologies OÜ ("Cardway Tech", "we", "our", or "us") is a technical service provider (TSP) offering payment orchestration and gateway integration services. Cardway Tech is not a licensed payment institution or electronic money institution and is not a financial entity directly subject to Regulation (EU) 2022/2554 (DORA) under Article 2(1) thereof.
However, as a provider of ICT services to regulated financial entities, Cardway Tech falls within the definition of an ICT third-party service provider under DORA Article 3(21) and Recital 63. Accordingly, Cardway Tech's regulated partners are required to apply the ICT third-party risk management provisions of DORA Articles 28–30 to their arrangements with Cardway Tech. This Statement is published to support those obligations.
Cardway Tech maintains an internal ICT risk governance framework consistent with the standards expected of ICT third-party service providers under DORA Article 28(1) and the EBA/ESAs Guidelines on ICT and Security Risk Management. The framework is overseen by senior management and the designated compliance function. Policies are reviewed at least annually and following material changes to the threat landscape or regulatory requirements.
ICT risk management documentation is available to regulated financial entity clients upon written request for the purposes of DORA Article 28(2) due diligence.
Cardway Tech maintains documented Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP), which are tested at least annually. Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined for critical services and are available to regulated financial entity clients upon request.
ICT-related incidents are classified, escalated, and reported in accordance with an internal Incident Management Policy. In the event of a major ICT incident affecting services provided to a regulated financial entity, Cardway Tech will notify the affected client within four (4) hours of incident identification and provide regular status updates until resolution, to support the client's obligations under DORA Articles 19–20.
Cardway Tech implements technical and organisational security measures including, but not limited to: advanced encryption of data in transit and at rest; multi-factor authentication for all administrative access; network segmentation and firewall controls; continuous monitoring and vulnerability management; and redundant cloud infrastructure across geographically separated environments.
Cardway Tech undergoes periodic security assessments and penetration testing. Summary results of such assessments are available to regulated financial entity clients upon request to support DORA Article 28(2) due diligence. Cardway Tech's sub-processors and cloud infrastructure providers are bound by equivalent security obligations under written agreements consistent with DORA Article 30.
Cardway Tech conducts risk-based due diligence and ongoing monitoring of all sub-processors and ICT subcontractors engaged in the delivery of services. Cardway Tech maintains a register of its material sub-processors, which is available to regulated financial entity clients upon written request.
Where Cardway Tech engages subcontractors for services supporting functions that a regulated financial entity client has designated as critical or important under DORA, Cardway Tech will: (i) notify the client in advance of any material changes to sub-processor arrangements; (ii) ensure subcontractors are bound by security and resilience obligations consistent with DORA Article 30(2)(a) and the applicable RTS (EU/2025/532, in force from 22 July 2025); and (iii) maintain continuity of service through its subcontractor chain.
Cardway Tech, as a non-regulated ICT third-party service provider, does not bear direct reporting obligations to competent authorities under DORA. Regulatory incident reporting obligations under DORA Articles 19–20 rest with Cardway Tech's regulated financial entity clients.
Cardway Tech undertakes to support its regulated clients in meeting those obligations by:
(i) notifying affected clients of major ICT-related incidents within four (4) hours of identification;
(ii) providing timely updates throughout the resolution process;
(iii) cooperating with client-initiated investigations and audits as required under DORA Article 30(2)(g);
(iv) maintaining incident logs available to clients upon request.
Notification and cooperation obligations applicable to Cardway Tech are set out in individual service agreements with regulated financial entity clients.
Cardway Tech is prepared to enter into DORA-compliant ICT service agreements with regulated financial entity clients. Such agreements incorporate, as applicable, the key contractual provisions required by DORA Article 30(2) and (3), including:
(a) description of services and subcontracting conditions;
(b) data location and processing geography;
(c) availability, integrity, and confidentiality provisions;
(d) data access, recovery, and return procedures;
(e) service level descriptions;
(f) incident assistance obligations;
(g) cooperation with competent authorities;
(h) termination rights and notice periods;
(i) audit and inspection rights.
Clients for whom Cardway Tech's services support critical or important functions under DORA may request inclusion of additional contractual provisions consistent with Article 30(3) and the applicable RTS (EU/2025/532).
To request a DORA-compliant service agreement or a completed ICT due diligence questionnaire, please contact: [email protected]
Cardway Tech is committed to the continuous improvement of its ICT risk management and operational resilience posture. Improvement activities include: annual review of BCP/DRP and security policies; periodic vulnerability assessments and penetration testing; monitoring of regulatory developments under DORA and related ESA guidelines; and engagement with regulated financial entity clients on their DORA due diligence requirements.
For inquiries related to operational resilience or compliance, please contact us at:
Cardway Technologies OÜ
Email: [email protected]
Website: https://carteza.com