Home/Frameworks/DORA
EU Finance
EU Finance

DORA

The EU's operational resilience regulation for finance. DORA sets binding requirements for how financial entities and their critical technology providers manage ICT risk, withstand disruption, and recover from it.

The standard

What DORA is.

The Digital Operational Resilience Act is an EU regulation, in force since January 2025, that harmonises ICT risk management across the financial sector. It applies to banks, insurers, investment firms, and a wide range of other financial entities — and, critically, to the ICT third parties that serve them.

Its requirements span ICT risk management, incident classification and reporting, digital operational resilience testing, and the management of third-party ICT risk, including oversight of critical providers.

DORA is regulatory compliance, not a certification — but a structured ISMS gives you most of the control foundation it requires.

Who it's for

Is this you?

Banks & insurers

All EU financial entities fall directly within DORA's scope.

Investment & payment firms

From investment firms to crypto-asset service providers.

Critical ICT providers

Technology vendors serving the financial sector face direct obligations.

How we deliver

From kickoff to done,
in five stages.

Delivered through our specialist network. We assess you against each DORA pillar, build the ICT risk-management and incident-reporting capability it demands, and align it with your existing security work — so resilience is operational, not just documented.

01

Scope & kickoff

We define the boundary of your programme — systems, locations, and teams in scope — and agree the timeline and responsibilities up front, so there are no surprises later.

02

Gap diagnostic

A structured assessment of your current posture against every requirement, producing a prioritised remediation plan with realistic effort estimates.

03

Build

We write the policies, procedures, and controls, and work alongside your engineering team on a weekly cadence to implement them — not a stack of templates left for you to figure out.

04

Operate

The management system runs and generates evidence. We drive the internal audit and management review so the programme is demonstrably working before any external scrutiny.

05

Audit support

We prepare the evidence package and sit alongside you through assessment, answering the assessor's questions directly rather than leaving you to defend the work alone.

Questions

Frequently asked.

It can. If you provide ICT services to EU financial entities, you may face obligations as a third-party provider, and critical providers come under direct EU oversight. We help you determine your exposure.

ISO 27001 gives you a large part of the ICT risk-management and control foundation DORA requires, so the two are complementary. We build DORA on top of an ISMS where one exists, and stand one up where it doesn't.

Explore more

Other frameworks.

Ready when you are

Let's get you
DORA ready.

Book a free advisory session and we'll map your fastest credible route to compliance.

Book a free advisory session