Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554 compliance software
Assess and evidence the Digital Operational Resilience Act per group or per financial entity: the five pillars and the technical standards that detail them, the register of information and the Article 30 contract clauses, with the incident clock and the TLPT cycle tracked.
- Legal instrumentRegulation (EU) 2022/2554, applicable since 17 January 2025
- Level 2RTS 2024/1774 (ICT risk), RTS 2025/301 (incident reports), RTS 2025/1190 (TLPT), ITS 2024/2956 (register of information)
- Assessable items230 requirements in 11 domains, 97 of them critical
- Reporting clockInitial notification within 4 h of classification and 24 h of awareness; intermediate within 72 h; final within one month
- TestingYearly tests of systems supporting critical or important functions; TLPT at least every 3 years for identified entities
- ScopeGroup or financial entity across 21 entity types; full or simplified (Article 16) framework
What DORA requires
Who it applies to
- Credit institutions, payment and e-money institutions and account information service providers
- Investment firms, trading venues, CCPs, CSDs, trade repositories, fund managers and crypto-asset service providers
- Insurers and reinsurers, insurance intermediaries and institutions for occupational retirement provision
- ICT third-party service providers to the financial sector, including the 19 designated critical providers
Regulation (EU) 2022/2554, the Digital Operational Resilience Act, has applied since 17 January 2025. As a regulation it binds directly, with no national transposition, and it harmonises ICT risk rules for 21 types of entity: the 20 financial-entity types of Article 2(1), from credit, payment and e-money institutions to investment firms, crypto-asset service providers, insurers, occupational pension funds and trading venues, plus ICT third-party service providers.
DORA rests on five pillars: ICT risk management (Articles 5 to 16), ICT-related incident management, classification and reporting (17 to 23), digital operational resilience testing (24 to 27), ICT third-party risk (28 to 44) and information sharing (45). Level 2 acts supply the detail, among them RTS 2024/1774 on the ICT risk-management framework, RTS 2025/301 on incident report content and timing, RTS 2025/1190 on threat-led penetration testing and ITS 2024/2956 on the register of information. Small and non-interconnected investment firms, exempted payment and e-money institutions and some smaller institutions apply the simplified framework of Article 16 in place of Articles 5 to 15.
Supervision runs on two tracks. Financial entities answer to their national competent authority, and significant banks to the ECB; penalties for financial entities are set by the Member States. Critical ICT third-party providers are overseen at EU level by a Lead Overseer (the EBA, EIOPA or ESMA), which can impose periodic penalty payments of up to 1% of average daily worldwide turnover. The ESAs designated the first 19 critical providers on 18 November 2025.
How GRCLens supports DORA
DORA runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Group and financial-entity assessment
The group is assessed at consolidated level and each financial entity as its own type (credit institution, payment institution, investment firm, insurer and the rest of the 21), with the full or simplified framework, TLPT identification and ICT-provider status as profiles. Entities roll up into a group view with a heat map across 15 risk areas.
Register of information and Article 30 clauses
ICT third-party risk is the largest domain: the register of information under ITS 2024/2956, the baseline contractual provisions of Article 30(2) and the additional ones for critical or important functions in Article 30(3), concentration risk and exit strategies, each assessed as its own requirement.
Four stakeholder dashboards
The management body sees conformity, critical gaps, entity type, competent authority and the reporting clock; the CRO and head of ICT risk the heat map, domain scores and gaps; operations the control validation and open remediation; third-party and procurement teams the register, contract-clause, concentration and exit-strategy findings.
Continuous assurance from eight EU cyber-resilience connectors
Incident records, backup and restore, vulnerability and patch, identity and MFA, the ICT third-party register, resilience testing, training (LMS) and log monitoring are read against the questionnaire, alongside the existing Entra, Tenable, Qualys, Splunk and ITSM connectors. A failing check whose requirement was answered Implemented is flagged as a contradiction.
Assurance register, remediation and KRIs
Each requirement can carry several owners in the assurance register. Gaps become owned, dated actions in the remediation and risk treatment plan, and key risk indicators name the requirements they measure, so an indicator outside appetite beside an answer of Implemented is a finding.
Baseerah summary, Word and PDF reports
Baseerah, the platform's AI assistant running on a self-hosted language model, writes a one-paragraph executive summary for the management body, the CRO and the head of ICT risk. Entity and group reports export as Word and PDF.
DORA frequently asked questions
When did DORA start to apply?
On 17 January 2025. DORA is a regulation, so it applies directly in every Member State without national transposition; the main regulatory and implementing technical standards that detail it entered into force between July 2024 and July 2025.
What are DORA's incident reporting deadlines?
For a major ICT-related incident, RTS 2025/301 requires an initial notification within 4 hours of classifying it as major and no later than 24 hours after becoming aware of it, an intermediate report within 72 hours of the initial notification, and a final report no later than one month after the latest intermediate report. Whether an incident is major is decided by the criteria and thresholds of RTS 2024/1772.
How often is threat-led penetration testing required?
At least every three years, on live production systems supporting critical or important functions, for financial entities identified for TLPT, either by the thresholds in RTS 2025/1190 or at their authority's discretion. Separately, ICT systems and applications supporting critical or important functions must be tested at least yearly.
What does DORA require in contracts with ICT providers?
Article 30(2) lists baseline provisions for every contract for ICT services, and Article 30(3) adds provisions for services supporting critical or important functions. Each arrangement is also recorded in the register of information under ITS 2024/2956. GRCLens assesses each clause as its own requirement and can read the register through its ICT third-party register connector.
What are the penalties under DORA?
DORA sets no EU-wide fine cap for financial entities: Member States lay down the administrative penalties and remedial measures, may apply them to members of the management body, and may opt for criminal penalties. The only EU-level figure applies to critical ICT third-party providers, whose Lead Overseer can impose periodic penalty payments of up to 1% of average daily worldwide turnover, daily for up to six months.
One platform, many obligations
See all supported frameworks → Every framework that applies in European Union →

Talk to us about DORA
Security Solution Consultants provides DORA readiness and advisory alongside the platform, so you can combine tooling with hands-on expertise.