NIS2 — transposed Oct 2024 DORA — enforced Jan 2025 EU AI ACT — Art.50 transparency 2 Aug 2026 CRA — reporting obligations from Sep 2026 ISO 42001 — certification live GDPR — ongoing enforcement NIS2 — transposed Oct 2024 DORA — enforced Jan 2025 EU AI ACT — Art.50 transparency 2 Aug 2026 CRA — reporting obligations from Sep 2026 ISO 42001 — certification live GDPR — ongoing enforcement
Home/Services/DORA Compliance for Financial Entities
DORA

DORA (Digital Operational Resilience Act) Compliance

DORA applies to financial entities — and, just as importantly, to the ICT providers that serve them. It demands demonstrable resilience: documented testing, incident classification against fixed thresholds, and a third-party risk register that holds up when an examiner asks to see it.

  • ICT risk management framework gap assessment
  • Third-party and concentration-risk register
  • Resilience testing programme, incl. TLPT scoping
  • Incident classification and reporting alignment

Free readiness call

Request a DORA scoping call

Thirty minutes, with a specialist who holds a credential in DORA — not a generalist account manager.

No obligation. No spam. One reply, from a specialist.

What's included

1

ICT risk management framework gap assessment

2

Third-party risk register and concentration-risk review

3

Resilience testing programme design, including scoping for threat-led penetration testing (TLPT)

4

Incident classification and regulatory reporting alignment

5

Contractual gap review for critical ICT third-party providers

Our process

01

Scope entities and critical ICT providers

02

Assess against DORA's five pillars

03

Remediate contracts, testing and registers

04

Support first regulatory reporting cycle

Frequently asked

We're a fintech, not a bank — are we in scope?

Very likely. DORA's scope covers most regulated financial entities — investment firms, payment institutions, e-money institutions, crypto-asset providers — and their critical ICT suppliers.

How is this different from our existing ISO 27001 work?

ISO 27001 covers information security generally. DORA is more prescriptive on testing cadence, incident reporting timelines and third-party concentration risk.

Get a straight answer on where you stand

Thirty minutes, free, with someone who holds a credential in the framework you're asking about.

Book a free 30-minute call