DORA
Compliance
Work through your DORA requirements with a clear plan. Get help with ICT risk, supplier reviews, resilience testing, and incident procedures.
Overview
Operational resilience, evidenced.
We build and document your ICT risk-management framework, establish third-party risk and register processes, set up incident classification and reporting, and coordinate TLPT aligned to TIBER-EU where required.
Scope
What we deliver.
The ICT risk, testing, and reporting pillars of DORA.
- ICT risk-management framework
- Governance & accountability
- ICT third-party risk & register
- Incident classification & reporting
- Digital operational resilience testing
- Threat-led penetration testing (TLPT)
- Business continuity & recovery
- Information sharing arrangements
FAQ
DORA FAQ
Scope, cost, and what happens next.
How much does DORA compliance cost?
DORA readiness support is typically €3,000–5,000 per month over 3–6 months, with threat-led penetration testing scoped separately. Use our estimator for a tailored figure.
Who does DORA apply to?
A broad range of EU financial entities — banks, payment and e-money institutions, investment firms, crypto-asset service providers, insurers — and their critical ICT third-party providers.
What is threat-led penetration testing (TLPT) under DORA?
Advanced, intelligence-led red teaming required periodically for significant financial entities, aligned to TIBER-EU. We scope and coordinate TLPT as part of your DORA programme.
How long does DORA readiness take?
Typically 3–6 months for the core framework. TLPT cycles are planned separately.
Can DORA reuse our existing ISO 27001 or NIS2 work?
Yes — we map DORA onto existing frameworks to avoid duplication while adding the ICT-specific and resilience-testing elements DORA requires.
When does DORA apply?
DORA has applied since January 2025 for in-scope EU financial entities and their critical ICT providers. We help you close any remaining gaps.
More questions about this service
Do we need TLPT?
Threat-led penetration testing is required periodically for significant financial entities; we assess whether it applies and coordinate it.
What is the ICT third-party register?
DORA requires a register of all ICT third-party arrangements; we help you build and maintain it.
How do DORA and NIS2 relate?
DORA is the sector-specific regime for financial entities and generally takes precedence over NIS2 for them; we align both where relevant.
Can DORA reuse existing frameworks?
Yes — we map DORA onto ISO 27001 and existing controls, adding the ICT-specific and resilience-testing elements DORA requires.
Related services
Explore more.
Ready to meet DORA?
A 30-minute scoping call costs nothing. A resilience failure costs considerably more.
Book a short call Send an email