DORA · Financial entities · ICT providers

DORA compliance: register of information, incidents and resilience testing

DORA has applied since 17 January 2025, and supervisors now ask less about the policy and more about the register of ICT contracts, test results and how fast an incident was reported. We help financial entities and their ICT providers close the gaps so every answer can be shown in data and logs.

// In short

DORA means digital operational resilience

DORA, Regulation (EU) 2022/2554, has applied since 17 January 2025 to banks, insurers, investment firms, payment institutions and other financial entities. It requires an ICT risk management framework, reporting of major ICT-related incidents, a resilience testing program and a register of contracts with ICT providers. ICT providers feel DORA through contracts and customer questionnaires.

// What we do

Five areas of DORA, each with evidence in a system

We start where your supervisor or your customer asks first. Usually that is the register of information or the incident reporting path.

  1. 01ICT risk

    ICT risk management framework and the board's role

    The management body defines, approves and oversees the ICT risk management framework and is responsible for implementing it (Article 5(2)). Its members follow specific training on a regular basis (Article 5(4)).

    • Map of critical or important functions and the systems behind them
    • Roles, policies and control reviews with approval dates
    • Documented ICT risk training for the board
  2. 02Incidents

    Classifying and reporting major incidents

    Initial notification within 4 hours of classifying an incident as major, and no later than 24 hours after becoming aware of it. Intermediate report within 72 hours of the initial notification, final report no later than one month after the latest intermediate report.

    • Classification criteria mapped to monitoring data
    • A clear decision on who classifies an incident as major
    • One scenario rehearsed, with the clock running
  3. 03Testing

    Digital operational resilience testing program

    Financial entities other than microenterprises test all systems supporting critical or important functions at least yearly, and independent parties run the tests (Article 24). We run penetration tests, source code reviews, scenario-based tests and restore tests.

    • A 12-month test plan ordered by criticality
    • Report with evidence, fixes retested
    • Results linked to the risk register
    Penetration testing
  4. 04ICT continuity

    ICT business continuity

    An ICT business continuity policy, a business impact analysis (BIA), and continuity and recovery plans tested at least yearly and after substantive changes to ICT systems (Articles 11 and 12).

    • BIA for critical or important functions
    • Cyberattack scenario and switchover to backup capacity
    • Test records kept as evidence for the supervisor
    Business continuity and DR testing
  5. 05ICT providers

    A register of information built from data

    The register covers all contractual arrangements for ICT services from third-party providers (Article 28(3)), using the templates in Implementing Regulation (EU) 2024/2956. In Poland it goes to the KNF, in Germany to BaFin.

    • Data from contracts, invoices and the system inventory, not a hand-kept spreadsheet
    • An owner for every entry and every function
    • Data quality checks before submission
    Data governance

// Deadlines

Dates that set the rhythm of DORA work

  1. DORA

    DORA applies from this date

    Regulation (EU) 2022/2554 is directly applicable in all Member States (Article 64).

    EUR-Lex (opens in a new tab)
  2. Register

    Reference date for the next register of information

    Since 2026, the register shows contracts as of 31 December of the previous year.

    BaFin FAQ (opens in a new tab)
  3. ESAs

    Registers go to the European Supervisory Authorities

    National supervisors forward the registers by 31 March each year. Your own submission date is set by your supervisor, such as the KNF in Poland or BaFin in Germany.

    KNF (opens in a new tab)

As of . Sources: Regulation (EU) 2022/2554 (DORA), Delegated Regulation (EU) 2025/301, Implementing Regulation (EU) 2024/2956, KNF, BaFin.

// For ICT providers

A financial customer listed you in its register

DORA binds the financial entity, but a large part of its ICT risk is your service. So the questions land on your desk: in questionnaires, in contract negotiations and in every supplier review.

  • Questionnaire answers backed by evidence: a configuration, a log, a test result, not a statement
  • A continuity plan for your service, proven by an actual restore
  • A path for notifying the customer about an incident before the customer has to report it to its supervisor
  • Data about your service and subcontractors that the customer will enter in its register

First step: DORA gaps and a register built from data in 5 weeks

  1. Gap analysis in five areas

    ICT risk, incidents, testing, ICT continuity and ICT providers for one entity, with priorities and owners.

  2. Register from source data

    Current ICT contracts pulled from contracts, invoices and the system inventory, with a list of what is missing.

  3. Incident reporting drill

    One scenario from detection to initial notification, timed against the 4-hour and 24-hour limits.

You end up with an owner for every register entry and a 90-day plan to close the gaps

We agree the fixed scope and date in writing before we start. Request the first step

// Scope

What we do and what we don't

We do

  • DORA gap analysis for a financial entity or an ICT provider
  • A register of information built from data, with an owner for every entry
  • Incident classification and a rehearsal of the reporting path
  • Penetration tests, source code reviews, scenario-based tests and restore tests
  • Evidence-based answers to questionnaires from financial customers

We don't

  • TLPT, or a TLPT label on an ordinary penetration test
  • A register retyped by hand into a spreadsheet with no data source
  • A "you are DORA compliant" statement based on a questionnaire alone
  • Resale of GRC tools or licenses

If all you need is a filled-in register template, we will tell you on the first call that we are not the right choice.

// FAQ

Questions about DORA compliance

Does DORA apply to us as an ICT provider?

DORA's obligations sit with financial entities. If you provide ICT services to them, you end up in their register of information, and the requirements reach you through the contract, questionnaires and questions about testing, incidents and business continuity. It pays to have evidence-backed answers before the customer asks.

How fast must a major incident be reported?

The initial notification is due within 4 hours of classifying the incident as major and no later than 24 hours after the entity became aware of it. The intermediate report follows within 72 hours of the initial notification, and the final report no later than one month after the latest intermediate report. That is set by Delegated Regulation (EU) 2025/301 (as of 24 September 2026).

What goes into the register of information, and when is it due?

All contractual arrangements for ICT services from third-party providers, in the templates of Implementing Regulation (EU) 2024/2956. Since 2026 the register shows contracts as of 31 December of the previous year, and national supervisors forward it to the European Supervisory Authorities by 31 March. In Poland the KNF collects it (form SPR-PF-18), in Germany BaFin (through its MVP portal), and each sets the submission date for its entities.

Do you run TLPT?

No. Threat-led penetration testing (Article 26) applies only to entities identified by the competent authorities. We run the tests of the resilience testing program (Articles 24 and 25): penetration tests, source code reviews, scenario-based tests and restore tests, with a report and a retest of fixes.

We already submitted a register once. Where do we start now?

With the data sources. We check where every column of the register comes from and who keeps it current. Where data was typed in by hand, we connect it to contracts, invoices and the system inventory, so the next cycle is an update rather than a rewrite.

How long does the first step take, and what does it cost?

5 weeks, with a fixed scope and date agreed in writing before we start. We quote the price after the first call, once we know whether we work with a financial entity or an ICT provider and how many contracts the register covers.

Let's start with the register and your most urgent gap

In 30 minutes we will establish whether you act as a financial entity or an ICT provider, and what goes into the first step.

Book a 30-minute call

Prefer to start in writing?

Describe your situation and we will send back the scope and date of the first step. We reply within one business day.

Request the first step