DORA
Who needs it
EU-regulated financial entities including banks, insurers, investment firms, payment institutions, and crypto-asset service providers, plus their critical ICT third-party providers who are brought into scope through contractual and oversight requirements.
Key requirements
A documented ICT risk management framework, major-incident classification and reporting to regulators on defined timelines, regular digital operational resilience testing (including threat-led penetration testing for significant entities), and a register of information on all ICT third-party arrangements.
Cyber/privacy implications
Incident reporting timelines are tight and specific (initial notification, intermediate report, and final report each on defined windows), which means detection and escalation processes have to be fast enough to meet a regulatory clock, not just an internal SLA.
Assessment methodology
ICT risk management framework gap assessment, third-party ICT provider register build-out, incident classification and reporting process design, and resilience testing program scoping including threat-led penetration testing where applicable.
Implementation phases
Assess
Gap analysis against the ICT risk management framework and third-party register requirements.
Build
Implement incident classification/reporting processes and resilience testing program.
Test
Execute resilience testing, including threat-led penetration testing for significant entities.
Evidence & documentation requirements
ICT risk management framework documentation, the register of information on ICT third-party providers, incident classification and reporting records, and resilience testing results including any threat-led penetration testing reports.
Common mistakes
Treating DORA as purely an IT-department concern when it explicitly requires management-body accountability; under-documenting the ICT third-party register, which regulators specifically examine given DORA's focus on concentration risk from critical vendors.
Related standards
Expert review
FAQ
Request a Gap Assessment
See where your ICT risk management framework stands against DORA's requirements.
Request a Gap Assessment →