DORA
Compliance

Support to meet the EU Digital Operational Resilience Act — ICT risk-management framework, threat-led penetration testing, third-party risk management, and incident classification and reporting for financial entities.

Overview

Operational resilience, evidenced.

DORA sets binding ICT risk and resilience requirements for financial entities and their critical technology providers across the EU — a formal ICT risk-management framework, rigorous third-party oversight, incident reporting, and resilience testing including threat-led penetration testing for significant entities.

We build and document your ICT risk-management framework, establish third-party risk and register processes, set up incident classification and reporting, and coordinate TLPT aligned to TIBER-EU where required.


Scope

What we deliver.

The ICT risk, testing, and reporting pillars of DORA.

Framework: EU DORA TLPT / TIBER-EU ICT third-party risk Incident reporting

FAQ

DORA FAQ

The questions we're asked most about scope, cost, and timing.

How much does DORA compliance cost?
DORA readiness support is typically €3,000–5,000 per month over 3–6 months, with threat-led penetration testing scoped separately. Use our estimator for a tailored figure.
Who does DORA apply to?
A broad range of EU financial entities — banks, payment and e-money institutions, investment firms, crypto-asset service providers, insurers — and their critical ICT third-party providers.
What is threat-led penetration testing (TLPT) under DORA?
Advanced, intelligence-led red teaming required periodically for significant financial entities, aligned to TIBER-EU. We scope and coordinate TLPT as part of your DORA programme.
How long does DORA readiness take?
Typically 3–6 months for the core framework. TLPT cycles are planned separately.
Can DORA reuse our existing ISO 27001 or NIS2 work?
Yes — we map DORA onto existing frameworks to avoid duplication while adding the ICT-specific and resilience-testing elements DORA requires.
When does DORA apply?
DORA has applied since January 2025 for in-scope EU financial entities and their critical ICT providers. We help you close any remaining gaps.
Do we need TLPT?
Threat-led penetration testing is required periodically for significant financial entities; we assess whether it applies and coordinate it.
What is the ICT third-party register?
DORA requires a register of all ICT third-party arrangements; we help you build and maintain it.
How do DORA and NIS2 relate?
DORA is the sector-specific regime for financial entities and generally takes precedence over NIS2 for them; we align both where relevant.
Can DORA reuse existing frameworks?
Yes — we map DORA onto ISO 27001 and existing controls, adding the ICT-specific and resilience-testing elements DORA requires.

Related services

Explore more.

Ready to meet DORA?

A 30-minute scoping call costs nothing. A resilience failure costs considerably more.

Book a meeting Send an email