A critical or important function (CIF) is one whose disruption would materially impair a firm’s financial performance, the soundness or continuity of its services, or its ability to meet regulatory obligations. Identifying CIFs is foundational to DORA — it drives testing scope, the third-party register and incident classification.
Almost everything in DORA depends on knowing your critical functions. It is also the task firms most often underestimate.
What a CIF is
A critical or important function is any function whose failure would materially harm the firm or its clients, the continuity of its services, or its ability to meet its authorisation conditions. The definition is deliberately outcome-focused.
Why mapping matters
Your CIFs determine what you must test at least annually, which third-party arrangements carry the heaviest obligations, and how incidents are classified. Get the mapping wrong and every downstream obligation is mis-scoped.
A step-by-step method
List your business services — the services you provide to clients and the market.
Assess materiality — which services, if disrupted, would materially harm the firm, its clients or its regulatory standing?
Trace the ICT dependencies — for each CIF, identify the systems, applications, data and third parties that support it.
Cross-reference the register — use your Article 28 register as the authoritative source of third-party dependencies.
Document and review — record the mapping and revisit it as the business changes.
Common pitfalls
Treating CIF mapping as an IT-only exercise rather than a business one
Underestimating the time it takes — it is consistently longer than expected
Missing dependencies buried in sub-outsourcing chains
Want help mapping your critical functions? Talk to CyberLabs.