Home › Frameworks › DORA

DORA compliance software for EU financial entities.

The DORA articles as 27 recurring controls with evidence: ICT risk framework, incident classification and reporting (Articles 17-23), resilience testing and TLPT, ICT third-party risk and the register of contractual arrangements. EU-built, EU-hosted. Included in Enterprise, €499 a month.

When did you become aware?

Indicative. Clocks run from awareness; check your national law and the full calculator for options such as trust service providers or a fix date.

Articles 5-15ICT risk management framework: governance, identification, protection, detection, response & recovery…
Articles 17-23ICT-related incident management, classification (Article 18) and reporting.
Article 26-27Threat-led penetration testing (TLPT) on at least a 3-year cycle for significant entities.
Articles 28-44Third-party ICT risk: register of contractual arrangements (Article 28), concentration analysis, exit…

What is DORA?

EU Digital Operational Resilience Act (Regulation (EU) 2022/2554). Banks, investment firms, payment institutions, insurance and reinsurance undertakings, crypto-asset service providers, central counterparties, trade repositories, and the ICT third-party providers serving them.

Selling software to financial entities rather than being one? Read DORA for SaaS vendors.

Who needs to comply

  • Banks and credit institutions
  • Investment firms, payment and e-money institutions
  • Insurance and reinsurance undertakings
  • Crypto-asset service providers under MiCA
  • Critical ICT third-party providers serving any of the above

Key DORA controls covered by Dazr

Articles 5-15ICT risk management framework: governance, identification, protection, detection, response & recovery, learning & evolution, communication.
Articles 17-23ICT-related incident management, classification (Article 18) and reporting.
Article 26-27Threat-led penetration testing (TLPT) on at least a 3-year cycle for significant entities.
Articles 28-44Third-party ICT risk: register of contractual arrangements (Article 28), concentration analysis, exit strategy, sub-contracting controls.

What auditors look for

DORA supervisors look for an ICT-risk framework approved by the management body, a third-party register with concentration analysis, recent TLPT evidence, and a major-incident classification trail. Dazr holds the controls and evidence for each of these four areas.

How Dazr helps with DORA

Dazr Compliance is an EU-hosted compliance management platform (GRC software) for European organisations of every size, from a five-person team to the enterprise. DORA is one of its eleven frameworks, included in Enterprise, €499 a month. In practice that means:

  • Maintain the ICT-risk framework as recurring controls reviewed by the management body
  • Keep ICT third-party providers in the vendor register and run the concentration-risk assessment (Article 29) as a control
  • Track TLPT planning, execution and remediation as cyclical controls (at least every 3 years for significant entities)
  • Log ICT-related incidents with severity, timestamps and authority references, with Article 18 classification and Article 19 reporting as controls
  • Hand the supervisor a single PDF audit trail or a read-only audit view

Back to the full Dazr Compliance overview › | Sign up free ›

DORA questions, answered.

What is the difference between DORA and NIS2 in this platform?

NIS2 is a directive transposed by member states; DORA is a regulation that applies directly. They overlap on incident reporting and on supply-chain / third-party risk; they differ on TLPT cadence (DORA explicit) and on the register of contractual arrangements (DORA-specific). Dazr lets you enable both; the controls stay distinct.

Do you support TLPT scoping?

We track the TLPT cycle as a recurring set of controls (scoping, red-team execution, blue-team review, remediation). The actual TLPT engagement is delivered by an external red team you contract with; Dazr is the system of record.

Can I use Dazr if I am a Tier-1 critical ICT third-party provider?

Yes. The Custom tier covers the multi-entity setup, dedicated CSM and the procurement-friendly contracting that Tier-1 ICT providers typically need.

Where is data hosted?

European Union only. Workspace records are encrypted at rest with AES-256-GCM at the application layer; uploaded evidence files rely on the storage provider's at-rest encryption. Italian entity, EU jurisdiction.

Ready to start your DORA program?

DORA is included in Enterprise (€499/mo, self-serve via Mollie, excl. VAT, cancel any time). Free and Basic cover ISO 27001, GDPR and NIS2; Pro adds NEN 7510, ISO 27701, ISO 22301 and SOC 2. Custom is the only tier on a contract, priced on request.