Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable when DORA cryptography evidence is…
Governance, Ownership & Risk

Who is accountable when DORA cryptography evidence is missing or incomplete?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Governance, Ownership & Risk

Accountability sits with the management body and senior leaders, not only with operations teams. DORA makes ICT risk management a governance duty, so boards must approve the framework and ensure it can be evidenced. If cryptographic controls, registers, or third-party assurance are incomplete, the organisation remains responsible for the shortfall.

Why This Matters for Security Teams

When cryptography evidence is missing or incomplete under DORA, the issue is not limited to a paperwork gap. It becomes a governance failure because the management body is expected to approve, oversee, and evidence ICT risk controls. That includes the cryptographic baseline, key management decisions, assurance from third parties, and the records that prove those controls exist and operate as intended.

This matters because evidence gaps often mask deeper control weakness: unclear ownership, fragmented vendor attestations, weak inventory discipline, or undocumented exceptions. NHI-heavy environments are especially exposed, since secrets and service identities are easy to lose track of. NHIMG’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives notes that 68% of organisations do not know how to fully address NHI risks, which is why evidence quality often lags control design.

In practice, many security teams discover missing cryptography evidence only after audit requests, supervisory scrutiny, or a vendor incident has already forced the question.

How It Works in Practice

Accountability under DORA follows the governance chain, not the ticket queue. Operations teams may collect logs, register keys, or maintain evidence packs, but senior leadership remains responsible for ensuring the control framework is complete and defensible. That means the organisation should be able to show what cryptographic assets exist, where they are used, who approves them, how keys are generated and rotated, and what assurance exists for outsourced components.

Practically, this is best handled as an evidence lifecycle. Map each cryptographic control to an owner, a source of truth, and a retention rule. Tie key inventory to asset inventory, and tie third-party attestations to contract and review cycles. Use control language from NIST SP 800-53 Rev 5 Security and Privacy Controls to structure evidence for access control, key management, audit logging, and system integrity, even when DORA is the legal driver.

  • Assign a named accountable executive for cryptography governance and evidence completeness.
  • Maintain an inventory of keys, certificates, algorithms, and systems using them.
  • Document key lifecycle events, including creation, rotation, revocation, and escrow where applicable.
  • Collect third-party assurance, but verify it against internal control objectives.
  • Track exceptions with expiry dates, compensating controls, and board visibility.

For organisations with large NHI estates, evidence discipline must also cover API keys, service account credentials, and automation tokens. NHIMG research on the Ultimate Guide to NHIs shows 79% of organisations have experienced secrets leaks, which is a strong signal that control evidence and actual control hygiene are often misaligned. These controls tend to break down when cryptographic services are spread across cloud, SaaS, and legacy systems because ownership and proof artifacts become inconsistent across platforms.

Common Variations and Edge Cases

Tighter cryptography governance often increases reporting and evidence overhead, so organisations must balance auditability against operational speed. That tradeoff is manageable when evidence collection is automated, but it becomes harder when controls are distributed across business units, managed service providers, and cloud-native platforms.

There is no universal standard for exactly which cryptography artifacts must be packaged for every DORA review, so current guidance suggests building an evidence model that is risk-based, repeatable, and board-readable. The strongest approach is to treat missing evidence as a control deficiency until it is remediated, not as a documentation inconvenience. If a vendor manages part of the stack, the organisation still retains accountability and should insist on contractually defined assurance, not informal reassurance.

This is especially important where secrets are embedded in automation or CI/CD. NHIMG’s research on Hard-Coded Secrets in VSCode Extensions shows how easily credential evidence becomes detached from actual use. In those environments, incomplete records usually signal that the organisation cannot yet prove control effectiveness, even if the tools are present. If evidence depends on manual chasing across teams and suppliers, the model breaks down during incidents, not just during audits.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack surface, NIST CSF 2.0 and NIST AI RMF set the technical controls, and DORA define the regulatory obligations.

FrameworkControl / ReferenceRelevance
DORADORA makes ICT risk governance and evidence a board-level duty.
NIST CSF 2.0GV.RM-01Risk management governance supports accountable oversight of cryptographic controls.
OWASP Non-Human Identity Top 10NHI-03Secrets and service identities are often the missing evidence in cryptography reviews.
CSA MAESTROGOV-02Agentic and cloud control governance requires traceable assurance and ownership.
NIST AI RMFGOV-1Govern function emphasizes accountability, documentation, and oversight.

Assign executive ownership for cryptography evidence and prove control effectiveness to the board.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org