Home/Case studies/DORA audit

Case study · Audit

DORA compliance audit for an institution of national importance

More than 460 hours of audit work covering all five pillars of the DORA Regulation — from the plan, through interviews and evidence review, to the final report for the management board and the regulator.

DORACritical infrastructurePublic sectorTPRMTLPT

Client and challenge

An institution of national importance operating in critical infrastructure and providing services to the financial sector. As a service provider to entities subject to DORA, it had to demonstrate the compliance of its own operational resilience — ahead of an external audit and questions from its financial-sector clients.

The challenge was scale: dozens of ICT systems, many third-party providers, scattered documentation and a confidentiality regime that restricted access to the environment. The client needed a partner who would run the audit from plan to report with a single team, without handing knowledge off between firms.

Audit scope

  • ICT risk management (Art. 5–16) — governance framework, management body roles, policies, business continuity and recovery.
  • ICT incident management (Art. 17–23) — classification, notification procedures, reporting deadlines.
  • Digital operational resilience testing (Art. 24–27) — testing program, TLPT readiness.
  • Third-party risk (Art. 28–30) — register of information, contractual clauses, provider concentration assessment.
  • Information sharing (Art. 45) — arrangements for sharing cyber threat information.

Process

Weeks 1–2 · Audit planMapping DORA requirements to the organization, evidence list, interview schedule, agreement on confidentiality and access rules.
Weeks 3–8 · Interviews and evidence reviewInterviews with process owners, review of policies, ICT provider contracts, test results and incident registers.
Weeks 9–10 · Testing and verificationTechnical verification of selected controls, assessment of the resilience testing program, gap analysis against TLPT requirements.
Weeks 11–12 · Report and remediation planA report with a maturity assessment for each pillar, a prioritized list of non-conformities, and an action plan with a schedule and effort estimates — in board-level language.

Outcome

The management board received a single document answering the question "where do we stand and what should we do first," and the technical teams received a concrete task list. The client can now answer any financial client's questionnaire with evidence rather than assurances. The register of ICT information and contractual clauses were standardized to the level required by Art. 28–30.

One team from plan to final report. We didn't have to explain our organization three times to three different firms.

Chief Security Officer, critical infrastructure institution — reference available after signing an NDA

What's next

After the audit, the client continued working with us in IT Security (resilience testing program) and Cloud Computing (maintaining the environment in line with DORA requirements). This is the typical path: the audit reveals the gaps, and the other two areas close and maintain them.

Other projects

See more case studies

All projects →
IT SecurityFinance · leasing company

Penetration testing under a regulatory deadline

Scope, pricing and schedule for application and infrastructure testing prepared within 48 hours of first contact. Report in board-level language.

48 hto a ready proposal
2testing areas
Read the case study →
AuditBanking · ICT vendor due diligence

Passing a bank's security questionnaire

A complete set of answers and evidence for the ICT vendor questionnaire: policies, procedures and records required under banking outsourcing rules.

100%of areas covered
0follow-up questions
Read the case study →
Cloud ComputingManufacturing · FMCG

Outsourced IT department for a food manufacturer

Maintenance of the production ERP, B2B platform, KSeF (Polish National e-Invoicing System) e-invoicing, workstations, network and backup. One SLA contract instead of five vendors.

24/7monitoring
3critical systems
Read the case study →