Articles tagged: FinTech
15 articles on FinTech from the Top Floor insights library.
2026-08-25
How Long Does DORA Readiness Take?
There is no grace period to plan against: DORA has applied since January 2025 and provides no transitional period. The honest timeline is set by the regulation's recurring clocks and by the workstreams with external lead times, and it differs for a new entrant, a laggard, a vendor and a group.
2026-08-23
Does DORA Require Threat-Led Penetration Testing?
Only if your competent authority tells you so. No financial entity opts into TLPT, and no vendor can tell you that you are in scope. What the designation actually turns on, and what to do while you wait to hear.
2026-08-23
What the DORA Register of Information Requires
Fourteen linked tables, machine-validated, with the LEI as the only identifier that works. In the ESAs' dry run, 6.5% of registers passed every data quality check and 86.4% of the failures were an empty mandatory field.
2026-08-22
What Does PCI DSS Compliance Actually Cost?
There is no published rate card for PCI, and the site that specialises in the question says so itself. What exists are seller-side ranges that disagree with each other by more than 2x on the same line item. The width is the finding.
2026-08-22
SAQ A Got Stricter by Getting Shorter
The Council removed three requirements from SAQ A and added an eligibility criterion in their place. Iframe merchants now have to confirm something before they may use the questionnaire at all. Redirect merchants do not.
2026-08-22
How to Reduce Your PCI DSS Scope
Four levers, in order of how much they remove: get card data out entirely, tokenize what you must keep, encrypt at the point of capture, and segment the remainder. The one that undoes all four is the back office nobody drew.
2026-08-22
How Long Does PCI DSS Compliance Take?
One published assessor timeline puts a first Report on Compliance at three to six months from scoping to signed report, and annual renewals at six to ten weeks. If you self-assess there is no fieldwork clock at all, only a remediation clock.
2026-08-16
Does DORA Apply to US Companies?
Almost certainly not directly, and almost certainly yes in practice. DORA binds EU financial entities, not their overseas vendors, but Articles 28 to 30 mean it arrives at your door as a contract addendum with a signature deadline attached.
2026-08-16
What a DORA Addendum Actually Asks You to Sign
Nine baseline terms under Article 30(2), six more under Article 30(3) when your service supports a critical or important function. A clause-by-clause read of the addendum European financial customers are sending their technology vendors.
2026-08-16
DORA Incident Reporting: The 4, 24, and 72 Hour Clocks
Three reports on three clocks, set by Commission Delegated Regulation (EU) 2025/301. The four-hour one is the surprise, because it starts at classification rather than at containment.
2026-08-16
Which PCI SAQ Do You Need? A Decision Guide
Your SAQ follows how card data touches your systems, not how big you are. The Council publishes several, each with its own eligibility criteria, and the boundary between the two most common ones is an engineering decision on your checkout page.
2026-08-16
Do You Need PCI Compliance If You Use Stripe or Shopify?
Yes. Stripe's own documentation says PCI compliance is a shared responsibility that applies to both Stripe and your business, and that you must attest annually. Using a processor shrinks the obligation; it does not transfer it.
2026-08-16
Merchant or Service Provider? The PCI AOC Your Customers Want
A merchant accepts cards for its own goods. A service provider handles or can affect the security of card data on someone else's behalf. Many SaaS companies are both, and sending the wrong attestation is how a vendor review stalls.
2026-08-16
Do You Need a QSA, or Can You Self-Assess for PCI DSS?
Most merchants can self-assess, and the entity that decides is your acquirer, not the Council and not a consultant. Get the answer in writing before you buy anything, including from us.
2026-02-21
PCI DSS v4.0: The Complete Guide to Future-Dated Requirements
PCI DSS v4.0 introduced dozens of new requirements, many labeled 'best practice until March 31, 2025,' after which they became mandatory. If your organization processes, stores, or transmits cardholder data, these future-dated requirements are now enforceable. Here is what changed and how to prepare.