Back to all articles
DORA in practice: evidencing patch compliance across a mobile fleet
Why mobile patching became an audit topic
RTS (EU) 2024/1774 Article 10(4)(d) expects financial entities to demonstrate that security patches are deployed within defined timeframes. For laptops and servers, most institutions already have that evidence. For mobile fleets, it is usually a spreadsheet maintained by hand.
What good evidence looks like
| Question from the auditor | Evidence you need |
|---|---|
| Which OS version is approved? | A documented baseline per device group |
| When was it deployed? | Timestamped campaign records |
| Which devices are outstanding? | A live exception list with owners |
Getting there
- Define the approved version per group.
- Validate business apps against it.
- Enforce the update with a deadline users cannot postpone.
- Export the campaign record as your audit artefact.