DIGITAL OPERATIONAL RESILIENCE ACT (DORA)

ICT risk management frameworks, third-party vendor controls, incident classification, and digital operational resilience testing.

Last reviewed: August 2026 (ENISA & National Cyber Security Guidelines)

Best suited forBanks, insurers, investment and payment firms and other DORA financial entities
Primary outcomeDORA requirement, control and evidence matrix
Scope1. ICT Risk Management: Building robust ICT governance and risk management frameworks
Typical timingTiming depends on the number of systems, roles, environments, available documentation and agreed constraints.

Is this right for you?

When to choose this service

Banks, insurers, investment and payment firms and other DORA financial entitiesICT providers whose financial customers require DORA evidence and contract changesInternal audit, risk, IT and security teams needing one implementation programmeOrganisations preparing for supervisory review, incident reporting or a resilience test

Five Pillars of DORA Readiness

  • 1. ICT Risk Management: Building robust ICT governance and risk management frameworks
  • 2. ICT Incident Reporting: Incident classification and statutory notification protocols to central banks/regulators
  • 3. Digital Operational Resilience Testing: Annual vulnerability reviews and Threat-Led Penetration Testing (TLPT) preparation
  • 4. ICT Third-Party Risk: Auditing vendor contracts, SLA boundaries, and maintaining the Information Register
  • 5. Information Sharing: Threat intelligence sharing protocols

What you receive

  • DORA requirement, control and evidence matrix
  • Map of critical or important functions and ICT dependencies
  • Incident-classification and notification playbook with decision points
  • Resilience-testing programme, annual plan and result register
  • Third-party risk, contract-gap and concentration register
  • Register-of-information governance and quality controls
  • Leadership report with residual risks, resources and deadlines

Delivery flow

From scope to a verified result

  1. Scope and safety boundaries. Confirm the objective, systems, roles, environment, exclusions, authorised actions and emergency stop contact.

  2. Information and access. Receive only the documentation, accounts, configuration or evidence needed for the work through a secure channel.

  3. DORA Regulatory Gap Analysis. We evaluate digital operational resilience, ICT third-party risk management, and threat-led testing requirements.

  4. Validation and reporting. Confirm findings, remove false positives and connect each risk to business impact and an accountable owner.

  5. Workshop and follow-through. Explain priorities, answer delivery teams, agree remediation timing and perform a retest where included.

Before we start

Frequently asked questions

How long does an engagement usually take?

Timing depends on the number of systems, roles, environments, available documentation and agreed constraints. After initial information is received, the scope states the stages, customer involvement and a specific schedule.

What should we prepare before work starts?

Usually we need a system or process owner, current scope, access and test accounts, architecture or process information, critical business scenarios and an emergency contact. Never send passwords through a normal website form.

Will we receive only a technical report?

No. The standard output includes an executive summary, prioritised detail, evidence, remediation guidance and a results workshop. Where relevant, the engagement includes a retest or implementation roadmap.

Does DORA also apply to ICT service providers?

Direct and indirect applicability differ. Financial entities have specific duties for ICT third-party risk, registers and contracts, so providers receive requirements and evidence requests. Critical third-party oversight status must be assessed separately.

Is a DORA penetration test the same as TLPT?

No. A normal penetration test is one element of a resilience-testing programme. TLPT is a regulated, threat-led and controlled full-scope test for designated entities with specific independence, scope and oversight requirements.

Related next steps