Governance & policies
Keep agreed policies, responsibilities, review activity and supporting records in a structured programme.
Fit2Trade helps credit unions organise policies, recurring checks, vendor records, incident evidence and reporting activity as they prepare for DORA from January 2028.
✓ Clear ownership ✓ Recurring records ✓ Structured oversight
Fit2Trade supports the organisation and evidence of agreed DORA-related work. It does not provide cyber monitoring, conduct technical resilience testing or make the compliance decision.
Keep agreed policies, responsibilities, review activity and supporting records in a structured programme.
Assign agreed control checks, record completion and retain supporting evidence without implying Fit2Trade performs technical security monitoring.
Collect consistent supplier information, record reviews and keep outstanding follow-up actions visible.
Maintain internal records, assigned actions and supporting evidence around incidents and continuity activity.
Record agreed testing or review outcomes and organise the information needed for internal oversight and reporting.
Recurring activity can be organised monthly, quarterly or annually according to the agreed programme. Each item can have a clear owner, due point, supporting record and visible follow-up.
The credit union retains responsibility for its programme and compliance decisions. Fit2Trade helps the people involved contribute the records, evidence and oversight their role requires.
Use internal reporting to review status, material exceptions, incidents, third-party oversight and planned improvement where these are included in the chosen scope.
Coordinate owners, policies, schedules, supporting documents, records and follow-up actions.
Supply the technical information or evidence requested by the credit union for the services and controls they are responsible for.
Both options are priced per credit union per year. Pro includes everything in Core and adds the wider toolkit shown below.
A focused operating foundation for recurring DORA readiness work.
A broader governance, assessment and oversight toolkit.
Final scope, responsibilities and implementation are confirmed before agreement.
Fit2Trade tools and workflows help organise internal records and readiness activity. They do not provide vulnerability scanning, endpoint monitoring, penetration testing, regulatory submission integrations or a compliance certification. The Pro annual ICT self-assessment is a Fit2Trade workflow and is not presented as a Central Bank regulatory submission.
Fit2Trade helps organise, complete and evidence resilience work. It does not guarantee DORA compliance or replace competent regulatory, legal, cybersecurity or ICT advice.
We’ll show the ownership model, recurring work, evidence structure and the difference between DORA Core and DORA Pro.