PCI DSS 4.0 · EU DORA · EU CRA · FAPI 2.0 · MiCA · SOC 2
Six frameworks.
One evidence system.
FinTech companies don't get to choose which regulations apply to what they ship.
PCI DSS 4.0 covers your payment software. DORA covers your ICT resilience. EU CRA covers your product security. FAPI 2.0 covers your open banking APIs. MiCA covers your crypto services. SOC 2 covers your enterprise customer's annual vendor review. X-DLM™ integrates Siemens Polarion and Black Duck to produce the evidence each framework requires — as a byproduct of how you already build.
EU Market Exclusion
CRA non-conformity is not a fine with a payment plan. It is EU market exclusion.
Payment platforms that cannot demonstrate CRA conformity lose CE marking and EU market access — revenue eliminated, not reduced. Full product conformity applies December 11, 2027. For FinTechs with material EU ARR, this is an existential product risk.
Payment Card Liability
Serious or unresolved PCI DSS noncompliance can lead to loss of card-processing privileges.
PCI DSS 6.3.2 requires an inventory of bespoke and custom software and its third-party components. Missing evidence can escalate to contractual penalties or acquirer action.
107% more vulnerabilities. 6 active frameworks. And CRA reporting begins September 11, 2026.
Increase in mean vulnerabilities per codebase in 2026 — every actively exploited one triggers CRA's 24-hour early warning clock. Source: 2026 OSSRA Report.
Mean open-source vulnerabilities per codebase. In payment software, each one is a potential PCI DSS 4.0 Req. 6.3.2 finding.
CRA reporting begins September 11, 2026: early warning within 24 hours, vulnerability notification within 72 hours, and a 14-day final report.
Active FinTech frameworks requiring evidence simultaneously: PCI DSS 4.0, EU DORA, EU CRA, FAPI 2.0, MiCA, SOC 2 Type II.
FinTech companies answer to six frameworks — and open-source components are in scope for all of them.
| Regulation | Who it affects | Timing | What you must answer | How X-DLM™ helps |
|---|---|---|---|---|
| PCI DSS 4.0 | Any organization that stores, processes, or transmits payment card data — payment processors, acquirers, gateways, PSPs, wallets, and merchant platforms. | Enforced — March 2024. Continuous QSA assessment. | Req. 6.3.2 inventory of bespoke and custom software and its third-party components. Annual review, update on change. Vulnerability management, change control, secure development evidence. | Black Duck generates a continuous machine-readable SBOM for payment software. X-DLM™ links every component to Polarion release records and routes changes through governed approval workflows. |
| EU DORA | Financial entities within DORA's defined scope — banks, payment institutions, e-money institutions, investment firms, and crypto asset service providers. DORA also oversees designated critical ICT providers. | In force — January 17, 2025. Ongoing supervisory oversight by EBA, ESMA, EIOPA. | Article 9 requires financial entities to protect and manage ICT systems, protocols and tools — including management of ICT third-party dependencies such as open-source software in production financial systems. | X-DLM™ routes every Black Duck third-party dependency finding into Polarion with DORA risk classification and response timelines — producing continuous Article 9 ICT supply chain evidence. |
| EU CRA | Any company placing FinTech software products on the EU market as Products with Digital Elements — payment platforms, lending software, crypto wallets, RegTech systems. | CRA reporting begins September 11, 2026. Full product conformity applies December 11, 2027. | Early warning within 24 hours, vulnerability notification within 72 hours, and a 14-day final report. Machine-readable SBOM (SPDX or CycloneDX), coordinated vulnerability disclosure, secure-by-design evidence, and CE marking apply from December 11, 2027. 10-year documentation retention. | Black Duck generates CRA-conformant SBOMs. X-DLM™ routes findings into Polarion with CRA-timed workflows and produces the conformity evidence package on demand. |
| FAPI 2.0 | Open banking platforms across the UK, EU, Canada, and Australia — banks, PSD2/PSD3 TPPs, account aggregators, and API gateway operators. | Ongoing — Open Banking Canada, UK FCA, EU PSD2/PSD3. | Financial-grade API security profile conformance — correct implementation of OAuth libraries, JWT handling, and gateway dependencies. Known vulnerabilities in these libraries are direct API security risks. | Black Duck identifies open-source dependencies with FAPI 2.0-relevant vulnerabilities. X-DLM™ governs remediation in Polarion with traceability to FAPI 2.0 specification requirements. |
| MiCA | Crypto asset service providers, crypto asset issuers, and electronic money token issuers operating in the EU. | In force — December 30, 2024. CASP authorization ongoing. | Article 30 operational resilience — documented ICT security policies, incident response, business continuity, and technical documentation of software security controls for CASP authorization. | Black Duck governance of open-source dependencies in crypto infrastructure, wallet software, and DeFi integrations produces the technical security evidence. X-DLM™ routes findings into Polarion with MiCA classification. |
| SOC 2 Type II | FinTech SaaS vendors selling to enterprise buyers — particularly banks, insurers, and regulated financial services customers. | Enterprise procurement-driven — annual audits and recurring vendor assessments. | Security controls, vulnerability management, change management, risk management, evidence of operating effectiveness, SBOM on request, vendor security posture documentation. | X-DLM™ keeps vulnerability response evidence, SBOM records, and security decision trails continuously available — eliminating the pre-audit evidence assembly sprint. |
PCI DSS 4.0
- Who it affects
- Any organization that stores, processes, or transmits payment card data — payment processors, acquirers, gateways, PSPs, wallets, and merchant platforms.
- Timing
- Enforced — March 2024. Continuous QSA assessment.
- What you must answer
- Req. 6.3.2 inventory of bespoke and custom software and its third-party components. Annual review, update on change. Vulnerability management, change control, secure development evidence.
- How X-DLM™ helps
- Black Duck generates a continuous machine-readable SBOM for payment software. X-DLM™ links every component to Polarion release records and routes changes through governed approval workflows.
EU DORA
- Who it affects
- Financial entities within DORA's defined scope — banks, payment institutions, e-money institutions, investment firms, and crypto asset service providers. DORA also oversees designated critical ICT providers.
- Timing
- In force — January 17, 2025. Ongoing supervisory oversight by EBA, ESMA, EIOPA.
- What you must answer
- Article 9 requires financial entities to protect and manage ICT systems, protocols and tools — including management of ICT third-party dependencies such as open-source software in production financial systems.
- How X-DLM™ helps
- X-DLM™ routes every Black Duck third-party dependency finding into Polarion with DORA risk classification and response timelines — producing continuous Article 9 ICT supply chain evidence.
EU CRA
- Who it affects
- Any company placing FinTech software products on the EU market as Products with Digital Elements — payment platforms, lending software, crypto wallets, RegTech systems.
- Timing
- CRA reporting begins September 11, 2026. Full product conformity applies December 11, 2027.
- What you must answer
- Early warning within 24 hours, vulnerability notification within 72 hours, and a 14-day final report. Machine-readable SBOM (SPDX or CycloneDX), coordinated vulnerability disclosure, secure-by-design evidence, and CE marking apply from December 11, 2027. 10-year documentation retention.
- How X-DLM™ helps
- Black Duck generates CRA-conformant SBOMs. X-DLM™ routes findings into Polarion with CRA-timed workflows and produces the conformity evidence package on demand.
FAPI 2.0
- Who it affects
- Open banking platforms across the UK, EU, Canada, and Australia — banks, PSD2/PSD3 TPPs, account aggregators, and API gateway operators.
- Timing
- Ongoing — Open Banking Canada, UK FCA, EU PSD2/PSD3.
- What you must answer
- Financial-grade API security profile conformance — correct implementation of OAuth libraries, JWT handling, and gateway dependencies. Known vulnerabilities in these libraries are direct API security risks.
- How X-DLM™ helps
- Black Duck identifies open-source dependencies with FAPI 2.0-relevant vulnerabilities. X-DLM™ governs remediation in Polarion with traceability to FAPI 2.0 specification requirements.
MiCA
- Who it affects
- Crypto asset service providers, crypto asset issuers, and electronic money token issuers operating in the EU.
- Timing
- In force — December 30, 2024. CASP authorization ongoing.
- What you must answer
- Article 30 operational resilience — documented ICT security policies, incident response, business continuity, and technical documentation of software security controls for CASP authorization.
- How X-DLM™ helps
- Black Duck governance of open-source dependencies in crypto infrastructure, wallet software, and DeFi integrations produces the technical security evidence. X-DLM™ routes findings into Polarion with MiCA classification.
SOC 2 Type II
- Who it affects
- FinTech SaaS vendors selling to enterprise buyers — particularly banks, insurers, and regulated financial services customers.
- Timing
- Enterprise procurement-driven — annual audits and recurring vendor assessments.
- What you must answer
- Security controls, vulnerability management, change management, risk management, evidence of operating effectiveness, SBOM on request, vendor security posture documentation.
- How X-DLM™ helps
- X-DLM™ keeps vulnerability response evidence, SBOM records, and security decision trails continuously available — eliminating the pre-audit evidence assembly sprint.
From open-source dependency to governed PCI DSS & CRA evidence trail.
Detect
Black Duck scans source, binaries, containers, and third-party dependencies — identifying vulnerabilities, malware, license conflicts, and provenance risk across payment software, open banking APIs, and crypto infrastructure.
Route
X-DLM™ synchronizes findings into Polarion as governed work items — with PCI DSS, DORA, CRA, FAPI 2.0, and MiCA practice mapping, assigned owners, escalation timelines, and approval chains.
Govern
Findings are linked to requirements, code, test results, risk acceptance records, and release evidence — the CRA secure-by-design and PCI DSS 6.3.2 evidence chain, built continuously.
Prove
Polarion workflow history produces the PCI DSS QSA package, DORA Article 9 documentation, CRA conformity evidence, MiCA CASP submission, and SOC 2 audit trail on demand.
One evidence system for every FinTech framework.
Book a walkthrough of how X-DLM™ operationalizes PCI DSS 4.0, EU DORA, EU CRA, FAPI 2.0, MiCA, and SOC 2 evidence for FinTech and regulated payment software companies — on Siemens Polarion and Black Duck.