Carteza
    • Platform
      • Payment Gateway
      • Payment Orchestration
      • Subscriptions
      • White Label
      • Payment links
    • Payment methods
      • Card Payments
      • International Payments
      • Bank Transfer
    • Industries
      • Ecommerce
      • Gaming
      • SaaS
      • Marketplace
      • Edu
  • Pricing
  • Partners
Telegram
Telegram

DORA / Operational Resilience Statement

Effective from: September 2026

This Statement is published voluntarily by Cardway Technologies OÜ in its capacity as an ICT third-party service provider within the meaning of Recital 63 and Article 3(21) of Regulation (EU) 2022/2554 ("DORA"). Cardway Tech is not a financial entity within the scope of Article 2(1) of DORA and is not directly subject to DORA's regulatory obligations. This Statement is intended to assist Cardway Tech's regulated financial entity clients and partners in fulfilling their ICT third-party risk management obligations under DORA Articles 28–30.

Cardway Technologies OÜ ("Cardway Tech", "we", "our", or "us") is a technical service provider (TSP) offering payment orchestration and gateway integration services. Cardway Tech is not a licensed payment institution or electronic money institution and is not a financial entity directly subject to Regulation (EU) 2022/2554 (DORA) under Article 2(1) thereof.

However, as a provider of ICT services to regulated financial entities, Cardway Tech falls within the definition of an ICT third-party service provider under DORA Article 3(21) and Recital 63. Accordingly, Cardway Tech's regulated partners are required to apply the ICT third-party risk management provisions of DORA Articles 28–30 to their arrangements with Cardway Tech. This Statement is published to support those obligations.

1. Governance and Risk Management

Cardway Tech maintains an internal ICT risk governance framework consistent with the standards expected of ICT third-party service providers under DORA Article 28(1) and the EBA/ESAs Guidelines on ICT and Security Risk Management. The framework is overseen by senior management and the designated compliance function. Policies are reviewed at least annually and following material changes to the threat landscape or regulatory requirements.

ICT risk management documentation is available to regulated financial entity clients upon written request for the purposes of DORA Article 28(2) due diligence.

2. Business Continuity and Incident Response

Cardway Tech maintains documented Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP), which are tested at least annually. Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO) are defined for critical services and are available to regulated financial entity clients upon request.

ICT-related incidents are classified, escalated, and reported in accordance with an internal Incident Management Policy. In the event of a major ICT incident affecting services provided to a regulated financial entity, Cardway Tech will notify the affected client within four (4) hours of incident identification and provide regular status updates until resolution, to support the client's obligations under DORA Articles 19–20.

3. ICT Security and Resilience

Cardway Tech implements technical and organisational security measures including, but not limited to: advanced encryption of data in transit and at rest; multi-factor authentication for all administrative access; network segmentation and firewall controls; continuous monitoring and vulnerability management; and redundant cloud infrastructure across geographically separated environments.

Cardway Tech undergoes periodic security assessments and penetration testing. Summary results of such assessments are available to regulated financial entity clients upon request to support DORA Article 28(2) due diligence. Cardway Tech's sub-processors and cloud infrastructure providers are bound by equivalent security obligations under written agreements consistent with DORA Article 30.

4. Third-Party and Supply Chain Risk

Cardway Tech conducts risk-based due diligence and ongoing monitoring of all sub-processors and ICT subcontractors engaged in the delivery of services. Cardway Tech maintains a register of its material sub-processors, which is available to regulated financial entity clients upon written request.

Where Cardway Tech engages subcontractors for services supporting functions that a regulated financial entity client has designated as critical or important under DORA, Cardway Tech will: (i) notify the client in advance of any material changes to sub-processor arrangements; (ii) ensure subcontractors are bound by security and resilience obligations consistent with DORA Article 30(2)(a) and the applicable RTS (EU/2025/532, in force from 22 July 2025); and (iii) maintain continuity of service through its subcontractor chain.

5. Incident Reporting

Cardway Tech, as a non-regulated ICT third-party service provider, does not bear direct reporting obligations to competent authorities under DORA. Regulatory incident reporting obligations under DORA Articles 19–20 rest with Cardway Tech's regulated financial entity clients.

Cardway Tech undertakes to support its regulated clients in meeting those obligations by:

(i) notifying affected clients of major ICT-related incidents within four (4) hours of identification;
(ii) providing timely updates throughout the resolution process;
(iii) cooperating with client-initiated investigations and audits as required under DORA Article 30(2)(g);
(iv) maintaining incident logs available to clients upon request.

Notification and cooperation obligations applicable to Cardway Tech are set out in individual service agreements with regulated financial entity clients.

6. Contractual Framework for Regulated Financial Entity Clients

Cardway Tech is prepared to enter into DORA-compliant ICT service agreements with regulated financial entity clients. Such agreements incorporate, as applicable, the key contractual provisions required by DORA Article 30(2) and (3), including:
(a) description of services and subcontracting conditions;
(b) data location and processing geography;
(c) availability, integrity, and confidentiality provisions;
(d) data access, recovery, and return procedures;
(e) service level descriptions;
(f) incident assistance obligations;
(g) cooperation with competent authorities;
(h) termination rights and notice periods;
(i) audit and inspection rights.

Clients for whom Cardway Tech's services support critical or important functions under DORA may request inclusion of additional contractual provisions consistent with Article 30(3) and the applicable RTS (EU/2025/532).

To request a DORA-compliant service agreement or a completed ICT due diligence questionnaire, please contact: [email protected]

7. Ongoing Improvement

Cardway Tech is committed to the continuous improvement of its ICT risk management and operational resilience posture. Improvement activities include: annual review of BCP/DRP and security policies; periodic vulnerability assessments and penetration testing; monitoring of regulatory developments under DORA and related ESA guidelines; and engagement with regulated financial entity clients on their DORA due diligence requirements.

Contact Information

For inquiries related to operational resilience or compliance, please contact us at:

Cardway Technologies OÜ
Email: [email protected] 
Website: https://carteza.com 

Carteza

Legal Information

  • AML
  • Cookie Policy
  • Privacy Policy
  • Terms of Service
  • DORA
  • About Us
  • Blog
[email protected]
Cardway Technologies OÜ (17593866)
Payment services are provided through licensed partners. Carteza delivers the technical infrastructure and payment orchestration layer via a single API.



© 2026 Carteza. All rights reserved.

This website uses cookies

Our website uses cookies to improve functionality and user experience, and to analyze traffic. By continuing to use our site, you agree to our use of cookies.

Get Custom Pricing

Share your requirements and we'll get back to you with custom payment terms.

Business type *

Select your Business type

E-commerce

SaaS

Marketplace

Subscription business

Crypto / Web3

Mobile app

Education

Other

Interesting Geo *

Select your Geo

Aland Islands

Albania

Andorra

Antigua and Barbuda

Argentina

Armenia

Australia

Austria

Azerbaijan

Bahamas

Bahrain

Bangladesh

Barbados

Belgium

Belize

Benin

Bermuda

Bhutan

Bosnia and Herzegovina

Botswana

Brazil

Brunei Darussalam

Bulgaria

Burundi

Cambodia

Canada

Cape Verde

Chad

Chile

China

Colombia

Comoros

Costa Rica

Croatia

Cyprus

Czech Republic

Denmark

Djibouti

Dominica

Dominican Republic

Ecuador

Egypt

El Salvador

Equatorial Guinea

Estonia

Eswatini

Ethiopia

Fiji

Finland

France

French Guiana

Gabon

Gambia

Georgia

Germany

Ghana

Greece

Greenland

Grenada

Guatemala

Guyana

Honduras

Hong Kong

Hungary

Iceland

India

Indonesia

Iraq

Ireland

Israel

Italy

Jamaica

Japan

Jordan

Kazakhstan

Kiribati

Kosovo

Kuwait

Kyrgyzstan

Latvia

Lesotho

Liberia

Liechtenstein

Lithuania

Luxembourg

Madagascar

Malawi

Malaysia

Maldives

Malta

Marshall Islands

Mauritania

Mauritius

Mayotte

Mexico

Micronesia

Moldova

Mongolia

Montenegro

Morocco

Nauru

Netherlands

New Zealand

Nicaragua

North Macedonia

Norway

Oman

Pakistan

Palau

Panama

Papua New Guinea

Paraguay

Peru

Philippines

Poland

Portugal

Puerto Rico

Qatar

Reunion

Romania

Rwanda

Saint Barthelemy

Saint Kitts and Nevis

Saint Lucia

Saint Martin (French part)

Saint Vincent and the Grenadines

Samoa

San Marino

Saudi Arabia

Senegal

Serbia

Seychelles

Sierra Leone

Singapore

Slovakia

Slovenia

Solomon Islands

South Korea

Spain

Sri Lanka

Suriname

Svalbard and Jan Mayen

Sweden

Switzerland

São Tomé and Príncipe

Taiwan

Tajikistan

Thailand

Timor-Leste

Togo

Tonga

Tunisia

Turkey

Turkmenistan

Tuvalu

Uganda

Ukraine

United Arab Emirates

United Kingdom

United States

Uruguay

Uzbekistan

Vatican City

Western Sahara

Zambia

Zimbabwe

0/300

Thank you — we'll be in touch within one business day.