Financial Services · P1

DORA Readiness (Digital Operational Resilience)

DORA has applied to EU financial entities since 17 January 2025, and it reaches the ICT providers that serve them through contract. Supervisors expect an ICT risk framework, incident classification and reporting, resilience testing, a register of ICT third-party arrangements and board accountability, all evidenced.

This assessment provides a readiness indicator based on the information provided. It does not constitute legal advice, a regulatory determination, or a guarantee of compliance. Regulatory applicability depends on facts, jurisdiction, and legal interpretation that should be confirmed with qualified counsel.

Who it is for

The companies this problem finds first.

EU-regulated financial entities: banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers

ICT service providers whose financial-entity customers are flowing DORA obligations into contracts

Groups with an EU financial subsidiary

When it comes up

The moments that turn this from a someday into a now.

  • Supervisor questionnaire or inspection
  • Customer contract with DORA clauses
  • Register of information submission
  • Major ICT incident
  • New EU licence or subsidiary
What we assess

8 areas, one control library.

Every area maps to controls already in the platform's single control library, so evidence collected here counts toward every other framework the business has adopted.

ICT risk management framework and governance

ICT asset and dependency mapping

ICT incident management, classification and reporting

Digital operational resilience testing

ICT third-party risk and the register of information

Contractual arrangements with ICT providers

Information sharing

Board oversight and training

What you get

Deliverables you can hand to a buyer, a board or a regulator.

  • DORA applicability position (entity type, proportionality, third-party role) for counsel review
  • Article-level readiness assessment with evidence
  • Register-of-information readiness check
  • Incident-reporting readiness test against the classification thresholds
  • Testing programme gap analysis
  • Remediation roadmap and board pack
Frameworks behind it

The sources every control cites.

Requirement statements are plain-English summaries for planning; the source instrument controls. Which of these reach your business is a question the assessment records with its reasoning, not one this page answers.

  • Digital Operational Resilience Act (Regulation (EU) 2022/2554)
  • ISO 22301 (Business Continuity)
  • ISO/IEC 27031 (ICT Readiness for Business Continuity)
  • NIST Cybersecurity Framework 2.0
  • Network and Information Security Directive 2 (Directive (EU) 2022/2555)
Value by role

What each executive gets out of it.

CEO

Know where you stand against the regulation before the supervisor asks.

CFO

A scoped programme rather than a reactive response to an inspection finding.

CTO / engineering

ICT risk, incident and third-party obligations translated into concrete controls and evidence.

General counsel

Applicability and proportionality reasoning documented for counsel and the board.

CISO / security lead

DORA obligations mapped to the controls already in the library so evidence is collected once.

How it fits

Integrated capabilities, not a separate programme.

Engagement tiers

Regulated Industry · Resilience · Continuous Assurance. Tiers describe depth and cadence; there is no per-regulation price.

Usually bought by

Chief risk officer, Cco, CISO / security lead, COO, Board

Part of these packages

Fintech Security · Crypto / Digital Asset · EU Expansion

FAQ

The objections, answered directly.

ISO 27001 covers a share of the ICT risk framework. Incident reporting thresholds, the register of information, resilience testing and contract provisions are DORA-specific and are where findings cluster.

Proportionality changes the depth, not the existence, of the obligations, and the simplified framework still has to be documented and evidenced.

Start with a conversation.

Thirty minutes to scope the engagement. No obligation.

Speak with an advisor