NewEscrow Pro, Resilience, Continuity and Agentic Verification: from holding the code to proving it comes back.The new line-up is here.See what's new
Why this page looks like this. It replaces production's /solutions/dora and folds in /solutions/dora-evidence-pack, so DORA has one page and one story. Production promised "compliance and continuity under DORA", said "The DORA deadline is here" and ended on "bulletproof software resilience". All of that is gone.
  • The headline sells the outcome Article 28(8) asks for: an exit plan that has been tested, with the evidence on file. The quote itself is in the next section.
  • The hero line under the CTAs is our level guidance (Resilience Pro or Continuity, plus an Exit Exercise), framed as guidance and repeated with prices further down.
  • The visual is the deliverable: one application's Article 28 evidence file, with every document from the proof ladder. Names, dates and figures are fictional and labelled as such.
  • Production's evidence pack page had live template text in its "How it works" section ("Explain in one or two concise sentences how your solution transforms users' challenges…"). Redirect that URL here.
DORA · EU financial entities

Your DORA exit plan. Tested, and on file.

Article 28(8) expects exit plans for ICT services that support critical or important functions to be documented and sufficiently tested. Codekeeper rebuilds the software without the vendor and gives you dated evidence for your Article 28 file.

Our guidance for critical or important functions: Resilience Pro or Continuity, plus an Exit Exercise. See the levels

  • Trusted by 3,500+ teams
  • ISO/IEC 27001:2022 certified
  • Ready for a DORA Article 28 file
Social proof straight after the promise. These are the logos production already uses, loaded from codekeeper.co. Where an image can't load (for example in the preview), the name shows instead. Use the approved set only.

Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors

Airbus Bayer European Parliament General Motors Intuit Nestlé PepsiCo Pfizer
Step 1, the exposure: let the regulation set the bar, with sources. Two verbatim quotes, the agreed disclaimer and the key dates.
  • Article 28(8) is the exact string in MESSAGING.md §7. Recital 74 was read on EUR-Lex (Regulation (EU) 2022/2554, HTML text) and replaces production's claim that "Article 30 sets the contractual requirements … exit strategies, tested contingency plans". We couldn't read Article 30 through our tools, so it isn't cited.
  • Dates fixed. Production says DORA "entered into force on 10 January 2023". EUR-Lex's notice for 32022R2554 gives 16 January 2023 (20 days after publication in the Official Journal on 27 December 2022, per Article 64). The application date, 17 January 2025, is shown in EUR-Lex's metadata for the act. Our fetch tool couldn't reach the text of Article 64 itself, so legal should confirm both dates against it.
  • Removed: production's fines ("2% of annual worldwide turnover or €10 million", "€1 million for senior executives", "€5 million" and, on the pack page, "1% of daily worldwide turnover"). EUR-Lex's own summary of DORA says competent authorities impose "the administrative penalties and remedial measures determined by national law", so a single DORA fine figure would mislead, and we couldn't read the penalty articles themselves. Also removed: the 24 October 2024 delegated-acts date, the "five pillars" (named differently in two places on production) and "at least annually" testing, none of which we could verify.

What DORA asks

Exit plans that are documented, and tested.

For ICT services that support critical or important functions, DORA expects an exit plan that would work. A written plan is the start. Testing it is what Article 28(8) adds.

EUDORA · Article 28(8)
“Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically.”
Regulation (EU) 2022/2554, Article 28(8). Applies to ICT services supporting critical or important functions.
EUDORA · Recital 74
“Such contractual arrangements should also provide for dedicated exit strategies to enable, in particular, mandatory transition periods during which ICT third-party service providers should continue providing the relevant services…”
Regulation (EU) 2022/2554, recital 74

Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.

14 Dec 2022DORA adoptedRegulation (EU) 2022/2554
16 Jan 2023Entered into force20 days after publication in the Official Journal
17 Jan 2025Applies to financial entities in scopeArticle 64
Step 2, the shift: a plan on paper versus a plan with evidence. This keeps the best idea from production's evidence pack page ("The exit plan on file … Not tested") without its liability lines ("you'll be liable for any DORA penalty", "you'll be found non-compliant"). Each item on the right is a confirmed fact: rebuilt with no vendor help, missing items flagged, functions tested without the original developers, dated documents.

The gap

A written exit plan isn't a tested one.

An exit plan describes what would happen if a provider failed. Testing shows whether it would work. Codekeeper gives you the second, from a real rebuild.

An exit plan on file

  • ×Names the provider and describes the recovery
  • ×Signed off at the annual review
  • ×Nobody has rebuilt the software without the vendor
  • ×Missing files come to light when you need them

An exit plan with evidence

  • The software rebuilt from the deposit, with no help from the vendor
  • Missing items flagged, so the depositor can add them
  • Business functions tested by people who didn't write the software
  • Dated documents for your Article 28 file
Step 3, the model, applied to DORA: four steps, one sentence each. Applications, then a protection, then a level, then the Exit Exercise as the add-on. Production's roadmap promised "ensuring compliance without extra burden" and a certificate "showing regulators that … operational resilience is assured". Both are gone. Daily sync, four rebuilds a year and the Exit Exercise facts are all confirmed.

How it works

From your list of critical services to evidence on file.

1

Name the services

Add the applications that support critical or important functions, from a vendor or built in-house.

2

Attach the protection

Resilience Pro or Continuity for each one. The deposit syncs daily from the vendor's repositories.

3

Rebuild and file

Run up to four rebuilds a year. Each successful run issues a dated Recoverability Certificate.

4

Exercise the exit

Add an Exit Exercise to test the business functions you nominate, with a DORA annex in the report.

Step 4, the proof, mapped to Article 28. Each row takes a phrase from the verified Article 28(8) quote, or the transition-period idea from recital 74, and shows the documents that support it and the level they come with. Wording stays at "supports" and "evidence for". Production's evidence-pack claims are gone: "A certificate the supervisor accepts", "Compliant with Article 28", "Checked against Article 30" and "Maps to your Register of Information entry" (we couldn't verify the register article). The Continuity row is careful: Continuity keeps the live environment paid and switched on for an agreed period; it isn't the provider's transition period.

Evidence for Article 28

What each document adds to your file.

Every document is dated and tied to one application, so your file shows what was tested, how and when.

What your Article 28 file needsCodekeeper evidence
An exit plan that's comprehensive and documentedExit workbookBuild stepsSBOMResilience Pro and Continuity (also Escrow Pro). The recovery process step by step, and the components the application needs.
Proof the software can be rebuilt without the providerRecoverability CertificateRun reportResilience Pro and Continuity (also Escrow Pro). AI agents rebuild the deposit in a sealed sandbox, with no help from the vendor.
Proof the business functions work after an exitTested Exit ReportDORA annexExit Exercise, an add-on to any plan. A clean-room rebuild by our specialists, tested against the functions you nominate.
Tested and reviewed periodicallyDated Recoverability CertificatesFour rebuilds a year included in Resilience Pro and Continuity, run when you choose. Either party can request an Exit Exercise when the plan needs exercising again.
The deposit is held, checked and currentSoftware Resilience CertificateVault reportEvery protection. Deposits sync daily through integrations.
A plan for the live service during an exitLive environment mapContinuity. We map where the application runs at setup, keep the map current, and if the vendor stops we keep the live environment paid and switched on for an agreed period while we recover.

Codekeeper's evidence supports your assessment. Whether it meets a specific requirement is for you and your assessor to decide.

Show the top rung in full, because it's the one DORA buyers ask about. A rebuild proves the deposit builds; the Exit Exercise proves the business could exit and keep working. The report mock repeats the agreed contents (pass or fail, gaps, date, framework annex), as on the Exit Exercise page. No duration is stated: the timeline is agreed at scoping.

Exit Exercise

When the plan needs exercising, not just a rebuild.

Our specialists rebuild the application by hand in a clean room, from the deposit alone, and test the business functions you nominate. The Tested Exit Report records the result, with an annex mapped to DORA.

  • The original developers aren't involved
  • Either party to the agreement can request one
  • Pass or fail per function, the gaps found and the date
  • The timeline is agreed at scoping

Example report. Names and contents are fictional and vary by application.

Recommend a level, as guidance. The brief: Resilience Pro or Continuity for critical or important functions, plus an Exit Exercise when the plan needs exercising. The note under the cards says plainly that this is guidance, not a compliance promise, and repeats the agreed price logic. Prices are the 6 Oct list; setup fees are confirmed. "From $12,000" for the Exit Exercise is confirmed, but no unit is published: confirm how it's quoted before launch. Resilience recovery is best effort under the Resilience Arrangement; the Resilience page carries that detail.

Our guidance

For critical or important functions.

Choose the protection by who runs the recovery and whether the service has to stay on. Add the Exit Exercise when your exit plan needs exercising, not just a rebuild.

Recovered by us · tested in advance

Resilience Pro

From$649per application per month

Proven before we need it.

  • The deposit comes to Codekeeper and we run the recovery
  • Agentic Verification: 4 rebuilds a year, on supported technology stacks
  • Recoverability Certificate, run report, SBOM and Exit workbook
  • A deployable copy
Kept switched on

Continuity

From$1,449per application per month

Full continuity.

  • Everything in Resilience Pro
  • The live environment mapped at setup and kept current
  • Kept paid and switched on for an agreed period while we recover
  • Bills recharged at cost
Add-on to any plan

Exit Exercise

From$12,000

Your exit plan, exercised.

  • Clean-room rebuild by our specialists, from the deposit alone
  • Tests of the business functions you nominate
  • No involvement from the original developers
  • Tested Exit Report with a DORA annex

This is our guidance, not a compliance promise: your assessment of each function decides. Setup is $499 per arrangement for Resilience Pro and $999 for Continuity. Escrow means the deposit is released to you and you run the recovery. Resilience costs more because we do the recovery. Continuity costs more again because we also keep the live environment switched on. Prefer to run the recovery yourself? Escrow Pro produces the same Recoverability Certificate. See full pricing

Three readers of this page. The financial entity is the obvious one (scope paraphrased from Article 2(1), read on EUR-Lex). ICT vendors selling into financial services are the second: their customers must plan an exit from them, so evidence helps the deal. The third is the team that compiles the file. The suggested film is the "regulated buyer" customer story from the video plan; it would do more here than any claim we can write.

Who it's for

Whoever has to show the exit works.

Financial entities in scope

Banks, insurers, investment firms, payment and e-money institutions, and the other entities listed in Article 2(1).

ICT providers to financial entities

Your customers have to plan their exit from you. Show them the deposit builds, with Escrow Pro, before they ask.

Risk, resilience and audit teams

The people who compile the Article 28 file and need dated evidence, not just a policy.

Suggested filmCustomer story: a DORA review, with the evidence on fileAbout 90 s. A named risk lead at a regulated customer: the critical service, the question the reviewer asked, the Recoverability Certificate and Tested Exit Report they showed, and what happened next. Shoot only with a customer who agrees to be named.
The secondary conversion, on every page. Visitors who aren't ready to talk can still leave their email. The sample evidence pack is the same offer on every page, so the site has one lead magnet instead of a different e-book per page. It also carries the launch story: proof, not promises. The button goes to the sample evidence pack page.

Sample evidence pack

See what your auditor would receive.

An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.

  • Recoverability Certificate
  • Run report
  • SBOM and Exit workbook excerpts
Get the sample evidence pack
Production's FAQ, corrected. The dates now match EUR-Lex (16 January 2023 in force, 17 January 2025 applies). Scope follows Article 2(1). The critical-or-important-function definition is quoted from Article 3(22) on EUR-Lex. The testing-frequency answer quotes Article 28(8) instead of production's unverified "at least annually". The penalties question is left out until legal confirms the wording. The "Does software escrow support DORA? Yes. Article 30 …" answer is replaced by the disclaimer answer.

Questions

DORA, answered.

What is DORA?

The Digital Operational Resilience Act, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It covers how financial entities manage ICT risk, including the risk that comes from ICT third-party service providers.

When did DORA come into force?

It entered into force on 16 January 2023, twenty days after publication in the Official Journal, and has applied since 17 January 2025.

Who does DORA apply to?

Article 2(1) lists the entities in scope. They include credit institutions, payment and electronic money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, managers of alternative investment funds, insurance and reinsurance undertakings, and institutions for occupational retirement provision. The list also includes ICT third-party service providers.

What does Article 28(8) ask for?

For ICT services supporting critical or important functions: “Exit plans shall be comprehensive, documented and, in accordance with the criteria set out in Article 4(2), shall be sufficiently tested and reviewed periodically.”

What counts as a critical or important function?

Article 3(22) defines it as “a function, the disruption of which would materially impair the financial performance of a financial entity, or the soundness or continuity of its services and activities…”, and the definition goes on to cover functions whose failure would impair compliance with the entity's authorisation or other obligations.

How often should we test our exit plans?

Article 28(8) says exit plans shall be “sufficiently tested and reviewed periodically”. How often is for you and your assessor to judge. Resilience Pro and Continuity include four rebuilds a year, run when you choose, and an Exit Exercise can be added whenever the plan needs exercising.

Will this make us DORA compliant?

Codekeeper gives you evidence for your Article 28 file: certificates, run reports, SBOMs, Exit workbooks and Tested Exit Reports with a DORA annex. Whether it meets a specific requirement is for you and your assessor to decide.

Our critical provider is a SaaS vendor. Does this still work?

Yes. SaaS applications have their own price row. We hold the code, infrastructure, data exports and the access needed to bring the service back, and rebuilds run on supported technology stacks.

What happened to the DORA Evidence Pack?

It's part of this page now. The sample evidence pack shows the documents an Agentic Verification run produces, and the Exit Exercise adds a Tested Exit Report with a DORA annex.

The same close on every page. The DORA close names the outcome the page sells: a tested exit plan on file, not a compliance promise. Every page ends on the same two actions in the same order: Book a demo, then the sample evidence pack.

Put a tested exit plan on file.

We'll map your critical or important functions to the applications behind them, and the evidence each one needs.