DORA Readiness (Digital Operational Resilience)
DORA has applied to EU financial entities since 17 January 2025, and it reaches the ICT providers that serve them through contract. Supervisors expect an ICT risk framework, incident classification and reporting, resilience testing, a register of ICT third-party arrangements and board accountability, all evidenced.
This assessment provides a readiness indicator based on the information provided. It does not constitute legal advice, a regulatory determination, or a guarantee of compliance. Regulatory applicability depends on facts, jurisdiction, and legal interpretation that should be confirmed with qualified counsel.
The companies this problem finds first.
EU-regulated financial entities: banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers
ICT service providers whose financial-entity customers are flowing DORA obligations into contracts
Groups with an EU financial subsidiary
The moments that turn this from a someday into a now.
- Supervisor questionnaire or inspection
- Customer contract with DORA clauses
- Register of information submission
- Major ICT incident
- New EU licence or subsidiary
8 areas, one control library.
Every area maps to controls already in the platform's single control library, so evidence collected here counts toward every other framework the business has adopted.
ICT risk management framework and governance
ICT asset and dependency mapping
ICT incident management, classification and reporting
Digital operational resilience testing
ICT third-party risk and the register of information
Contractual arrangements with ICT providers
Information sharing
Board oversight and training
Deliverables you can hand to a buyer, a board or a regulator.
- DORA applicability position (entity type, proportionality, third-party role) for counsel review
- Article-level readiness assessment with evidence
- Register-of-information readiness check
- Incident-reporting readiness test against the classification thresholds
- Testing programme gap analysis
- Remediation roadmap and board pack
The sources every control cites.
Requirement statements are plain-English summaries for planning; the source instrument controls. Which of these reach your business is a question the assessment records with its reasoning, not one this page answers.
- Digital Operational Resilience Act (Regulation (EU) 2022/2554)
- ISO 22301 (Business Continuity)
- ISO/IEC 27031 (ICT Readiness for Business Continuity)
- NIST Cybersecurity Framework 2.0
- Network and Information Security Directive 2 (Directive (EU) 2022/2555)
What each executive gets out of it.
CEO
Know where you stand against the regulation before the supervisor asks.
CFO
A scoped programme rather than a reactive response to an inspection finding.
CTO / engineering
ICT risk, incident and third-party obligations translated into concrete controls and evidence.
General counsel
Applicability and proportionality reasoning documented for counsel and the board.
CISO / security lead
DORA obligations mapped to the controls already in the library so evidence is collected once.
Integrated capabilities, not a separate programme.
Engagement tiers
Regulated Industry · Resilience · Continuous Assurance. Tiers describe depth and cadence; there is no per-regulation price.
Usually bought by
Chief risk officer, Cco, CISO / security lead, COO, Board
Part of these packages
Fintech Security · Crypto / Digital Asset · EU Expansion
The objections, answered directly.
ISO 27001 covers a share of the ICT risk framework. Incident reporting thresholds, the register of information, resilience testing and contract provisions are DORA-specific and are where findings cluster.
Proportionality changes the depth, not the existence, of the obligations, and the simplified framework still has to be documented and evidenced.
Start with a conversation.
Thirty minutes to scope the engagement. No obligation.