Home/Case studies/DORA audit

Case study · Audit

DORA compliance audit for an institution of national importance

More than 460 hours of audit work covering all five pillars of the DORA Regulation — from the plan, through interviews and evidence review, to the final report for the management board and the regulator.

DORACritical infrastructurePublic sectorTPRMTLPT

Client and challenge

An institution of national importance operating in critical infrastructure and providing services to the financial sector. As a service provider to entities subject to DORA, it had to demonstrate the compliance of its own operational resilience — ahead of an external audit and questions from its financial-sector clients.

The challenge was scale: dozens of ICT systems, many third-party providers, scattered documentation and a confidentiality regime that restricted access to the environment. The client needed a partner who would run the audit from plan to report with a single team, without handing knowledge off between firms.

Audit scope

  • ICT risk management (Art. 5–16) — governance framework, management body roles, policies, business continuity and recovery.
  • ICT incident management (Art. 17–23) — classification, notification procedures, reporting deadlines.
  • Digital operational resilience testing (Art. 24–27) — testing program, TLPT readiness.
  • Third-party risk (Art. 28–30) — register of information, contractual clauses, provider concentration assessment.
  • Information sharing (Art. 45) — arrangements for sharing cyber threat information.

Process

Weeks 1–2 · Audit planMapping DORA requirements to the organization, evidence list, interview schedule, agreement on confidentiality and access rules.
Weeks 3–8 · Interviews and evidence reviewInterviews with process owners, review of policies, ICT provider contracts, test results and incident registers.
Weeks 9–10 · Testing and verificationTechnical verification of selected controls, assessment of the resilience testing program, gap analysis against TLPT requirements.
Weeks 11–12 · Report and remediation planA report with a maturity assessment for each pillar, a prioritized list of non-conformities, and an action plan with a schedule and effort estimates — in board-level language.

Outcome

The management board received a single document answering the question “where do we stand and what should we do first,” and the technical teams received a concrete task list. The client can now answer any financial client’s questionnaire with evidence rather than assurances. The register of ICT information and contractual clauses were standardized to the level required by Art. 28–30.

One team from plan to final report. We didn’t have to explain our organization three times to three different firms.

Chief Security Officer, critical infrastructure institution — reference available after signing an NDA

What’s next

After the audit, the client continued working with us in IT Security (resilience testing program) and Cloud Computing (maintaining the environment in line with DORA requirements). This is the typical path: the audit reveals the gaps, and the other two areas close and maintain them.

Other projects

See more case studies

All projects →
AuditFinTech · Kanga Exchange

Kanga Exchange: from intensive pentests to a 3-year strategic partnership

Crypto-asset security with MiCA and DORA compliance: exchange app pentests, Pentest as a Service, Hybrid Vulnerability Scanner and a MiCA RTS audit.

3 monthsof intensive testing in Phase I
3 yearsPtaaS contract + MiCA audit
Read the case study →
AuditBanking · ICT vendor due diligence

Passing a bank’s security questionnaire

A complete set of answers and evidence for the ICT vendor questionnaire: policies, procedures and records required under banking outsourcing rules.

100%of areas covered
0follow-up questions
IT SecurityBanking · ING Bank Śląski S.A.

12-month penetration testing program for ING Bank Śląski

A year-long penetration testing cycle for critical infrastructure and web applications in a sprint model, aligned with DORA and OWASP, with official references.

12 monthscontinuous program
OWASPASVS · black-box
Read the case study →