Copp Clark Passes Its DORA Third-Party Assessment Without Overbuilding Compliance
A Canadian company outside the EU still had to prove DORA compliance to its European finance clients, so the challenge was scoping just enough security work without draining its resources.
Copp Clark, a Canadian company supplying financial institutions with global public holiday, trading hour and close-day data, found itself classified as an ICT third-party service provider under the EU’s DORA regulation because of the European financial businesses it serves. The tricky part wasn’t the regulation itself, it was scoping Copp Clark’s proportional responsibility accurately, so the company didn’t drain its resources on compliance activities that went beyond what its actual role required.
Sigma Software ran stakeholder interviews to map Copp Clark’s existing security processes, then performed a gap assessment benchmarked directly against DORA’s requirements for ICT third-party providers, producing a Risk Management Policy, Third-party Management Policy, Business Continuity & Disaster Recovery Plan, and Incident Response Plan. The team followed that with Digital Operational Resilience Testing, scoping a penetration test specifically to Copp Clark’s distributed infrastructure rather than running a blanket, resource-heavy assessment across everything.
“It was our pleasure working with the Sigma Software. They provided friendly, professional, and informative support at all times,” said Carol Champ, VP – Operations at Copp Clark Limited.
The engagement helped Copp Clark establish a security process aligned with both DORA and ISO 27001, and the company went on to pass third-party regulatory checks requested by its European financial customers, closing the compliance gap without derailing day-to-day operations to get there.

