DORA compliance
The practical shift is this: operational resilience stopped being an internal quality goal and became a supervised obligation with evidence requirements.
DORA — EU 2022/2554
ISO 27001
NIS 2
TLPT — Article 26
What the regulation requires
What does DORA actually require?
DORA is built on five pillars. Most readiness programmes fail because they treat it as a documentation exercise and address only the first.
1. ICT risk management
A governance framework with the management body accountable, not delegated to IT. Identification of ICT-supported business functions, protection and prevention measures, detection, response and recovery, and learning from incidents.
2. ICT-related incident management
Classification of incidents against defined criteria, and reporting of major incidents to the competent authority within the required timelines.
3. Digital operational resilience testing
A testing programme proportionate to your size and risk profile, and, for entities identified by the authorities, advanced testing in the form of threat-led penetration testing under Article 26.
4. ICT third-party risk
A register of information on all contractual arrangements with ICT providers, mandatory contractual clauses, exit strategies, and concentration risk analysis. This is where most institutions discover how little they know about their fourth parties.
5. Information sharing
Voluntary arrangements for exchanging cyber threat intelligence among financial entities.
Where readiness programmes fail
How do you know whether you are compliant?
You cannot answer that from a policy folder. The supervisory question is not whether you have a framework but whether you can show the evidence that it operated.
A DORA readiness assessment maps your current state against each pillar and produces three things: where you already comply and can prove it, where the control exists but the evidence does not, and where there is a genuine gap. The second category is usually the largest and the most dangerous, because internally it feels like compliance. A control that works but leaves no trace is indistinguishable, to a supervisor, from a control that was never there.
How we work with you
What we do
01
Readiness assessment. Gap analysis across all five pillars, mapped to your existing ISO 27001 or NIST controls so you are not rebuilding what you already have.
02
ICT third-party register. Building the register of information, reviewing contracts against the mandatory clauses, and identifying concentration risk and exit-strategy gaps.
03
Testing programme. Designing a programme proportionate to your profile, and delivering the testing itself, from vulnerability assessment and penetration testing through to threat-led penetration testing for entities in scope of Article 26.
04
Incident classification and reporting. Defining criteria, thresholds and the reporting workflow, so the clock is not started by an argument about whether an incident is major.
05
Evidence pack. Everything structured so it can be handed to a supervisor or an auditor without a translation layer.
Questions we get most often
Common questions about DORA
Does DORA apply to us if we are not in the EU?
Often yes, indirectly and decisively. If you provide ICT services to an EU financial entity, DORA reaches you through the contractual obligations of your client. Ukrainian and other non-EU technology providers increasingly find that their EU financial clients now require register entries, contractual clauses, exit strategies and evidence of testing as a condition of the contract.
We work with both sides of that relationship: financial entities meeting their own obligations, and providers who must satisfy them.
When did DORA start applying?
It applies from 17 January 2025. There is no transition period remaining, which is why supervisory attention has moved from readiness to evidence.
Is ISO 27001 enough for DORA?
No, but it is a substantial head start. An ISO 27001 ISMS covers a large part of pillar one and parts of pillars two and three. It does not cover the ICT third-party register, the mandatory contractual clauses, the incident classification and reporting regime, or Article 26 testing. We map what you already have before proposing anything new.
Who has to do threat-led penetration testing?
Not everyone. Advanced testing under Article 26 applies to entities identified by the competent authorities based on their risk profile and systemic importance. Other entities still need a proportionate testing programme, just not TLPT.
A readiness assessment across all five pillars, mapped to the controls you already run.