- The headline sells the outcome Article 28(8) asks for: an exit plan that has been tested, with the evidence on file. The quote itself is in the next section.
- The hero line under the CTAs is our level guidance (Resilience Pro or Continuity, plus an Exit Exercise), framed as guidance and repeated with prices further down.
- The visual is the deliverable: one application's Article 28 evidence file, with every document from the proof ladder. Names, dates and figures are fictional and labelled as such.
- Production's evidence pack page had live template text in its "How it works" section ("Explain in one or two concise sentences how your solution transforms users' challenges…"). Redirect that URL here.
Your DORA exit plan. Tested, and on file.
Article 28(8) expects exit plans for ICT services that support critical or important functions to be documented and sufficiently tested. Codekeeper rebuilds the software without the vendor and gives you dated evidence for your Article 28 file.
Our guidance for critical or important functions: Resilience Pro or Continuity, plus an Exit Exercise. See the levels
- Trusted by 3,500+ teams
- ISO/IEC 27001:2022 certified
- Ready for a DORA Article 28 file
Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors
- Article 28(8) is the exact string in MESSAGING.md §7. Recital 74 was read on EUR-Lex (Regulation (EU) 2022/2554, HTML text) and replaces production's claim that "Article 30 sets the contractual requirements … exit strategies, tested contingency plans". We couldn't read Article 30 through our tools, so it isn't cited.
- Dates fixed. Production says DORA "entered into force on 10 January 2023". EUR-Lex's notice for 32022R2554 gives 16 January 2023 (20 days after publication in the Official Journal on 27 December 2022, per Article 64). The application date, 17 January 2025, is shown in EUR-Lex's metadata for the act. Our fetch tool couldn't reach the text of Article 64 itself, so legal should confirm both dates against it.
- Removed: production's fines ("2% of annual worldwide turnover or €10 million", "€1 million for senior executives", "€5 million" and, on the pack page, "1% of daily worldwide turnover"). EUR-Lex's own summary of DORA says competent authorities impose "the administrative penalties and remedial measures determined by national law", so a single DORA fine figure would mislead, and we couldn't read the penalty articles themselves. Also removed: the 24 October 2024 delegated-acts date, the "five pillars" (named differently in two places on production) and "at least annually" testing, none of which we could verify.
What DORA asks
Exit plans that are documented, and tested.
For ICT services that support critical or important functions, DORA expects an exit plan that would work. A written plan is the start. Testing it is what Article 28(8) adds.
“Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically.”
“Such contractual arrangements should also provide for dedicated exit strategies to enable, in particular, mandatory transition periods during which ICT third-party service providers should continue providing the relevant services…”
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
The gap
A written exit plan isn't a tested one.
An exit plan describes what would happen if a provider failed. Testing shows whether it would work. Codekeeper gives you the second, from a real rebuild.
An exit plan on file
- ×Names the provider and describes the recovery
- ×Signed off at the annual review
- ×Nobody has rebuilt the software without the vendor
- ×Missing files come to light when you need them
An exit plan with evidence
- The software rebuilt from the deposit, with no help from the vendor
- Missing items flagged, so the depositor can add them
- Business functions tested by people who didn't write the software
- Dated documents for your Article 28 file
How it works
From your list of critical services to evidence on file.
Name the services
Add the applications that support critical or important functions, from a vendor or built in-house.
Attach the protection
Resilience Pro or Continuity for each one. The deposit syncs daily from the vendor's repositories.
Rebuild and file
Run up to four rebuilds a year. Each successful run issues a dated Recoverability Certificate.
Exercise the exit
Add an Exit Exercise to test the business functions you nominate, with a DORA annex in the report.
Evidence for Article 28
What each document adds to your file.
Every document is dated and tied to one application, so your file shows what was tested, how and when.
| What your Article 28 file needs | Codekeeper evidence |
|---|---|
| An exit plan that's comprehensive and documented | Exit workbookBuild stepsSBOMResilience Pro and Continuity (also Escrow Pro). The recovery process step by step, and the components the application needs. |
| Proof the software can be rebuilt without the provider | Recoverability CertificateRun reportResilience Pro and Continuity (also Escrow Pro). AI agents rebuild the deposit in a sealed sandbox, with no help from the vendor. |
| Proof the business functions work after an exit | Tested Exit ReportDORA annexExit Exercise, an add-on to any plan. A clean-room rebuild by our specialists, tested against the functions you nominate. |
| Tested and reviewed periodically | Dated Recoverability CertificatesFour rebuilds a year included in Resilience Pro and Continuity, run when you choose. Either party can request an Exit Exercise when the plan needs exercising again. |
| The deposit is held, checked and current | Software Resilience CertificateVault reportEvery protection. Deposits sync daily through integrations. |
| A plan for the live service during an exit | Live environment mapContinuity. We map where the application runs at setup, keep the map current, and if the vendor stops we keep the live environment paid and switched on for an agreed period while we recover. |
Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.
Exit Exercise
When the plan needs exercising, not just a rebuild.
Our specialists rebuild the application by hand in a clean room, from the deposit alone, and test the business functions you nominate. The Tested Exit Report records the result, with an annex mapped to DORA.
- The original developers aren't involved
- Either party to the agreement can request one
- Pass or fail per function, the gaps found and the date
- The timeline is agreed at scoping
Example report. Names and contents are fictional and vary by application.
Our guidance
For critical or important functions.
Choose the protection by who runs the recovery and whether the service has to stay on. Add the Exit Exercise when your exit plan needs exercising, not just a rebuild.
Resilience Pro
From$649per application per month
Proven before we need it.
- The deposit comes to Codekeeper and we run the recovery
- Agentic Verification: 4 rebuilds a year, on supported technology stacks
- Recoverability Certificate, run report, SBOM and Exit workbook
- A deployable copy
Continuity
From$1,449per application per month
Full continuity.
- Everything in Resilience Pro
- The live environment mapped at setup and kept current
- Kept paid and switched on for an agreed period while we recover
- Bills recharged at cost
Exit Exercise
From$12,000
Your exit plan, exercised.
- Clean-room rebuild by our specialists, from the deposit alone
- Tests of the business functions you nominate
- No involvement from the original developers
- Tested Exit Report with a DORA annex
This is our guidance, not a compliance promise: your assessment of each function decides. Setup is $499 per arrangement for Resilience Pro and $999 for Continuity. Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on. Prefer to run the recovery yourself? Escrow Pro produces the same Recoverability Certificate. See full pricing
Who it's for
Whoever has to show the exit works.
Financial entities in scope
Banks, insurers, investment firms, payment and e-money institutions, and the other entities listed in Article 2(1).
ICT providers to financial entities
Your customers have to plan their exit from you. Show them the deposit builds, with Escrow Pro, before they ask.
Risk, resilience and audit teams
The people who compile the Article 28 file and need dated evidence, not just a policy.
Sample evidence pack
See what your auditor would receive.
An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.
- Recoverability Certificate
- Run report
- SBOM and Exit workbook excerpts
Questions
DORA, answered.
What is DORA?
The Digital Operational Resilience Act, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It covers how financial entities manage ICT risk, including the risk that comes from ICT third-party service providers.
When did DORA come into force?
It entered into force on 16 January 2023, twenty days after publication in the Official Journal, and has applied since 17 January 2025.
Who does DORA apply to?
Article 2(1) lists the entities in scope. They include credit institutions, payment and electronic money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, managers of alternative investment funds, insurance and reinsurance undertakings, and institutions for occupational retirement provision. The list also includes ICT third-party service providers.
What does Article 28(8) ask for?
For ICT services supporting critical or important functions: “Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically.”
What counts as a critical or important function?
Article 3(22) defines it as “a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities…”, and the definition goes on to cover functions whose failure would impair compliance with the entity's authorisation or other obligations.
How often should we test our exit plans?
Article 28(8) says exit plans shall be “sufficiently tested and reviewed periodically”. How often is for you and your assessor to judge. Resilience Pro and Continuity include four rebuilds a year, run when you choose, and an Exit Exercise can be added whenever the plan needs exercising.
Will this make us DORA compliant?
Codekeeper gives you evidence for your Article 28 file: certificates, run reports, SBOMs, Exit workbooks and Tested Exit Reports with a DORA annex. Whether it meets a specific requirement is for you and your assessor to decide.
Our critical provider is a SaaS vendor. Does this still work?
Yes. SaaS applications have their own price row. We hold the code, infrastructure, data exports and the access needed to bring the service back, and rebuilds run on supported technology stacks.
What happened to the DORA Evidence Pack?
It's part of this page now. The sample evidence pack shows the documents an Agentic Verification run produces, and the Exit Exercise adds a Tested Exit Report with a DORA annex.
Put a tested exit plan on file.
We'll map your critical or important functions to the applications behind them, and the evidence each one needs.