DORA
DORA — the Digital Operational Resilience Act — sets EU-wide rules for how financial entities manage ICT and cyber risk, so the sector can withstand and recover from digital disruptions.
DORA — the Digital Operational Resilience Act — sets EU-wide rules for how financial entities manage ICT and cyber risk, so the sector can withstand and recover from digital disruptions.
DORA brings ICT risk, incident reporting, resilience testing and third-party oversight under one harmonised framework for banks, insurers, investment firms and many of their providers.
A governance framework for identifying, protecting against and recovering from ICT risk.
Classify and report major ICT-related incidents within the required timelines.
Map and manage critical ICT providers, with the right contractual safeguards.
We help financial entities and their providers meet DORA without duplicating what they already do well.
We benchmark your ICT risk and contracts against DORA.
Policies, registers and contract updates to close the gaps.
Resilience testing and incident-reporting processes that hold up.
It applies to most regulated financial entities and many of their ICT providers. We help you confirm scope.
They overlap on cyber resilience; DORA is the sector-specific regime for finance and generally takes precedence there.
Critical ICT third parties are squarely in scope, including contractual and oversight requirements.
Answer a few questions and our specialists will send you a free, no-obligation needs analysis for this area — what applies to you, your main risks, and the right next steps.
One free analysis per company.
Tell us about your ICT setup and we will map your DORA obligations. Your first hour is free.
Book a meeting