Get DORA ready
For financial-sector firms in scope of the Digital Operational Resilience Act
DORA (EU Regulation 2022/2554) has applied since 17 January 2025. It makes digital operational resilience a direct regulatory obligation for the financial sector: not "do you have security tooling", but "can your important business services survive ICT disruption, and can you prove it". Unlike a certification you choose to pursue, DORA is law - supervisors can ask for your evidence at any time.
Who is in scope
DORA covers most regulated financial entities operating in the EU: banks, payment and e-money institutions, investment firms, fund managers, insurers and intermediaries, crypto-asset service providers, and more - plus the critical ICT third parties that serve them. UK-headquartered firms are commonly caught through EU entities, EU branches, or by serving EU markets; and the UK's own operational resilience regime (FCA/PRA) asks closely related questions, so the work transfers.
The five pillars
- ICT risk management - a documented framework, owned by the management body, covering identification, protection, detection, response and recovery for all ICT assets supporting important business services.
- Incident management and reporting - classify ICT incidents consistently, report major ones to your supervisor on strict timelines, and learn from near misses.
- Digital operational resilience testing - a proportionate testing programme, from vulnerability scanning to scenario exercises (and threat-led penetration testing for the largest firms).
- ICT third-party risk - a register of every ICT provider, risk assessment of the critical ones, and contractual provisions the regulation actually specifies.
- Information sharing - arrangements to exchange threat intelligence within trusted communities.
Where firms struggle in practice: the third-party register (nobody has a complete list of ICT providers on day one), evidencing that the framework runs continuously rather than existing on paper, and giving the management body the visibility the regulation makes them personally accountable for.
The sensible order of work
- 1. Map your important business services and the ICT assets and providers underneath them - scope drives everything else.
- 2. Assess against the five pillars honestly, so you know your distance from compliant before a supervisor asks.
- 3. Build the third-party register early - it takes longer than anyone expects, and contract remediation has lead times.
- 4. Stand up incident classification and reporting - the timelines are too short to design a process mid-incident.
- 5. Test, record, repeat. Resilience testing and board reporting are recurring obligations, not projects.
How Assura helps
Assura includes a guided DORA assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and every requirement is scored with written reasoning - so "are we DORA ready?" gets an honest, defensible answer:
- a scored readiness view across all five pillars, with a prioritised gap list;
- a vendor-risk module that builds your ICT third-party picture with AI-assessed supplier questionnaires;
- an incident register and tabletop exercises that evidence the response and testing pillars;
- board-ready reporting - the management-body visibility DORA demands, generated from live data;
- and cross-framework mapping, so DORA work pre-fills ISO 27001, NIS2 and your UK operational-resilience answers.
Assura measures and evidences your resilience programme; your legal obligations and supervisory relationship stay with your compliance function. Arriving at that conversation with a live, scored picture beats arriving with a binder.
Check your readiness with Assura
Related guides: NIS2 · ISO 27001 · Cyber Essentials