DORA · Financial entities · ICT providers
DORA compliance: register of information, incidents and resilience testing
DORA has applied since 17 January 2025, and supervisors now ask less about the policy and more about the register of ICT contracts, test results and how fast an incident was reported. We help financial entities and their ICT providers close the gaps so every answer can be shown in data and logs.
// In short
DORA means digital operational resilience
DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025 to banks, insurers, investment firms, payment institutions and other financial entities. It requires an ICT risk management framework, reporting of major ICT-related incidents, a resilience testing program and a register of contracts with ICT providers. ICT providers feel DORA through contracts and customer questionnaires.
// What we do
Five areas of DORA, each with evidence in a system
We start where your supervisor or your customer asks first. Usually that is the register of information or the incident reporting path.
01ICT risk
ICT risk management framework and the board's role
The management body defines, approves and oversees the ICT risk management framework and is responsible for implementing it (Article 5(2)). Its members follow specific training on a regular basis (Article 5(4)).
- Map of critical or important functions and the systems behind them
- Roles, policies and control reviews with approval dates
- Documented ICT risk training for the board
02Incidents
Classifying and reporting major incidents
Initial notification within 4 hours of classifying an incident as major, and no later than 24 hours after becoming aware of it. Intermediate report within 72 hours of the initial notification, final report no later than one month after the latest intermediate report.
- Classification criteria mapped to monitoring data
- A clear decision on who classifies an incident as major
- One scenario rehearsed, with the clock running
03Testing
Digital operational resilience testing program
Financial entities other than microenterprises test all systems supporting critical or important functions at least yearly, and independent parties run the tests (Article 24). We run penetration tests, source code reviews, scenario-based tests and restore tests.
- A 12-month test plan ordered by criticality
- Report with evidence, fixes retested
- Results linked to the risk register
04ICT continuity
ICT business continuity
An ICT business continuity policy, a business impact analysis (BIA), and continuity and recovery plans tested at least yearly and after substantive changes to ICT systems (Articles 11 and 12).
- BIA for critical or important functions
- Cyberattack scenario and switchover to backup capacity
- Test records kept as evidence for the supervisor
05ICT providers
A register of information built from data
The register covers all contractual arrangements for ICT services from third-party providers (Article 28(3)), using the templates in Implementing Regulation (EU) 2024/2956. In Poland it goes to the KNF, in Germany to BaFin.
- Data from contracts, invoices and the system inventory, not a hand-kept spreadsheet
- An owner for every entry and every function
- Data quality checks before submission
// Deadlines
Dates that set the rhythm of DORA work
DORA
DORA applies from this date
Regulation (EU) 2022/2554 is directly applicable in all Member States (Article 64).
EUR-Lex (opens in a new tab)Register
Reference date for the next register of information
Since 2026, the register shows contracts as of 31 December of the previous year.
BaFin FAQ (opens in a new tab)ESAs
Registers go to the European Supervisory Authorities
National supervisors forward the registers by 31 March each year. Your own submission date is set by your supervisor, such as the KNF in Poland or BaFin in Germany.
KNF (opens in a new tab)
As of . Sources: Regulation (EU) 2022/2554 (DORA), Delegated Regulation (EU) 2025/301, Implementing Regulation (EU) 2024/2956, KNF, BaFin.
// For ICT providers
A financial customer listed you in its register
DORA binds the financial entity, but a large part of its ICT risk is your service. So the questions land on your desk: in questionnaires, in contract negotiations and in every supplier review.
- Questionnaire answers backed by evidence: a configuration, a log, a test result, not a statement
- A continuity plan for your service, proven by an actual restore
- A path for notifying the customer about an incident before the customer has to report it to its supervisor
- Data about your service and subcontractors that the customer will enter in its register
First step: DORA gaps and a register built from data in 5 weeks
Gap analysis in five areas
ICT risk, incidents, testing, ICT continuity and ICT providers for one entity, with priorities and owners.
Register from source data
Current ICT contracts pulled from contracts, invoices and the system inventory, with a list of what is missing.
Incident reporting drill
One scenario from detection to initial notification, timed against the 4-hour and 24-hour limits.
You end up with an owner for every register entry and a 90-day plan to close the gaps
We agree the fixed scope and date in writing before we start. Request the first step
// Scope
What we do and what we don't
We do
- DORA gap analysis for a financial entity or an ICT provider
- A register of information built from data, with an owner for every entry
- Incident classification and a rehearsal of the reporting path
- Penetration tests, source code reviews, scenario-based tests and restore tests
- Evidence-based answers to questionnaires from financial customers
We don't
- TLPT, or a TLPT label on an ordinary penetration test
- A register retyped by hand into a spreadsheet with no data source
- A "you are DORA compliant" statement based on a questionnaire alone
- Resale of GRC tools or licenses
If all you need is a filled-in register template, we will tell you on the first call that we are not the right choice.
// Read more
Related topics and services
More on technology risk and compliance on our blog:
- Technology risk management and business strategy
- Security-driven IT processes: compliance and data protection
- Cloud audit: security, cost control and compliance
DORA is one of the frameworks we cover under compliance and audit.
// FAQ
Questions about DORA compliance
Does DORA apply to us as an ICT provider?
DORA's obligations sit with financial entities. If you provide ICT services to them, you end up in their register of information, and the requirements reach you through the contract, questionnaires and questions about testing, incidents and business continuity. It pays to have evidence-backed answers before the customer asks.
How fast must a major incident be reported?
The initial notification is due within 4 hours of classifying the incident as major and no later than 24 hours after the entity became aware of it. The intermediate report follows within 72 hours of the initial notification, and the final report no later than one month after the latest intermediate report. That is set by Delegated Regulation (EU) 2025/301 (as of 24 September 2026).
What goes into the register of information, and when is it due?
All contractual arrangements for ICT services from third-party providers, in the templates of Implementing Regulation (EU) 2024/2956. Since 2026 the register shows contracts as of 31 December of the previous year, and national supervisors forward it to the European Supervisory Authorities by 31 March. In Poland the KNF collects it (form SPR-PF-18), in Germany BaFin (through its MVP portal), and each sets the submission date for its entities.
Do you run TLPT?
No. Threat-led penetration testing (Article 26) applies only to entities identified by the competent authorities. We run the tests of the resilience testing program (Articles 24 and 25): penetration tests, source code reviews, scenario-based tests and restore tests, with a report and a retest of fixes.
We already submitted a register once. Where do we start now?
With the data sources. We check where every column of the register comes from and who keeps it current. Where data was typed in by hand, we connect it to contracts, invoices and the system inventory, so the next cycle is an update rather than a rewrite.
How long does the first step take, and what does it cost?
5 weeks, with a fixed scope and date agreed in writing before we start. We quote the price after the first call, once we know whether we work with a financial entity or an ICT provider and how many contracts the register covers.
Let's start with the register and your most urgent gap
In 30 minutes we will establish whether you act as a financial entity or an ICT provider, and what goes into the first step.
Book a 30-minute callPrefer to start in writing?
Describe your situation and we will send back the scope and date of the first step. We reply within one business day.
Request the first step