DORA compliance: digital operational resilience for the financial sector

DORA has been mandatory since January 2025 for banks, insurers, fund managers and a long list of financial entities in the EU. We assess your current situation, identify the gaps and support you through the compliance process.

DORA is not optional for the financial sector

The DORA Regulation (Digital Operational Resilience Act) entered into application in January 2025. It affects more than 22,000 financial entities in the EU: banks, insurers, investment firms, fund managers, payment service providers and their critical technology providers. Non-compliance can lead to significant penalties and, above all, can expose the entity's inability to manage a digital crisis.

What DORA covers and how we help

  • Governance and management body accountability for ICT risk
  • ICT risk management framework: identification, protection, detection and recovery
  • Management and notification of major ICT incidents
  • Digital operational resilience testing (TLPT - Threat-Led Penetration Testing)
  • Third-party ICT risk management (technology supply chain)
  • Contractual arrangements with ICT providers: mandatory DORA clauses

DORA compliance process

  1. Initial assessment: We analyze the type of entity, the scope of application and the current state of DORA's five pillars.
  2. Gap analysis: We compare the current situation with the Regulation's requirements, including the RTS and the EIOPA/EBA/ESMA guidelines.
  3. Compliance plan: We design an action plan with priorities, deadlines and owners for each identified gap.
  4. Technical implementation: We support the implementation of resilience testing, the ICT risk management framework and incident response protocols.
  5. Regulatory documentation: We draft the documentation required by DORA: registers, policies, procedures and provider contracts.

Deliverables

  • Applicability analysis and entity classification report
  • Gap analysis against DORA's five pillars (risk management, incidents, testing, third parties, information sharing)
  • Compliance plan with timeline and resource estimate
  • Documented ICT risk management framework
  • Support in the design and execution of TLPT testing if required

Which entities does DORA affect?

  • Credit institutions (banks)
  • Investment firms and fund managers
  • Payment and electronic money institutions
  • Insurers and reinsurers
  • Crypto-asset service providers
  • Critical ICT providers of financial entities

Frequently asked questions about DORA

How does DORA differ from NIS2?

NIS2 is a horizontal directive affecting multiple sectors. DORA is a sector-specific regulation for the financial sector, with more detailed and technical requirements, especially regarding resilience testing (TLPT) and ICT provider management.

What is TLPT testing and who must perform it?

TLPT (Threat-Led Penetration Testing) is advanced intrusion testing based on real threat intelligence, targeting the entity's most critical systems. It's only mandatory for significant entities designated by the competent authorities. We can run it with the TIBER-EU methodology.

Does DORA also affect technology providers of financial entities?

Yes. DORA establishes a direct oversight regime for critical ICT providers. And even if you're not a critical ICT provider, if you're a technology provider to a financial entity, they will require you to include DORA contractual clauses in the service agreement.