DORA applies to financial entities — and, just as importantly, to the ICT providers that serve them. It demands demonstrable resilience: documented testing, incident classification against fixed thresholds, and a third-party risk register that holds up when an examiner asks to see it.
Free readiness call
Thirty minutes, with a specialist who holds a credential in DORA — not a generalist account manager.
ICT risk management framework gap assessment
Third-party risk register and concentration-risk review
Resilience testing programme design, including scoping for threat-led penetration testing (TLPT)
Incident classification and regulatory reporting alignment
Contractual gap review for critical ICT third-party providers
Very likely. DORA's scope covers most regulated financial entities — investment firms, payment institutions, e-money institutions, crypto-asset providers — and their critical ICT suppliers.
ISO 27001 covers information security generally. DORA is more prescriptive on testing cadence, incident reporting timelines and third-party concentration risk.
Thirty minutes, free, with someone who holds a credential in the framework you're asking about.
Book a free 30-minute call