What is DORA?
EU Digital Operational Resilience Act (Regulation (EU) 2022/2554). Banks, investment firms, payment institutions, insurance and reinsurance undertakings, crypto-asset service providers, central counterparties, trade repositories, and the ICT third-party providers serving them.
Selling software to financial entities rather than being one? Read DORA for SaaS vendors.
Who needs to comply
- Banks and credit institutions
- Investment firms, payment and e-money institutions
- Insurance and reinsurance undertakings
- Crypto-asset service providers under MiCA
- Critical ICT third-party providers serving any of the above
Key DORA controls covered by Dazr
What auditors look for
DORA supervisors look for an ICT-risk framework approved by the management body, a third-party register with concentration analysis, recent TLPT evidence, and a major-incident classification trail. Dazr holds the controls and evidence for each of these four areas.
How Dazr helps with DORA
Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. DORA is one of its eleven frameworks, included in Enterprise, €499 a month. In practice that means:
- Maintain the ICT-risk framework as recurring controls reviewed by the management body
- Keep ICT third-party providers in the vendor register and run the concentration-risk assessment (Article 29) as a control
- Track TLPT planning, execution and remediation as cyclical controls (at least every 3 years for significant entities)
- Log ICT-related incidents with severity, timestamps and authority references, with Article 18 classification and Article 19 reporting as controls
- Hand the supervisor a single PDF audit trail or a read-only audit view
Back to the full Dazr Compliance overview › | Sign up free ›