02 · Audit
Digital operational resilience for banks, payment institutions, insurers, crypto-asset service providers and their ICT providers — gap analysis, policies, third-party risk, resilience testing and incident reporting.
Service details
DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) is the EU regulation that requires financial entities to withstand, respond to and recover from ICT disruptions and cyberattacks. It has applied since 17 January 2025 to banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and many other financial entities — and indirectly to the ICT providers that serve them.
Remote Admin audits your organization against DORA, prepares the missing policies and procedures, tests your resilience in practice and helps you manage ICT third-party risk. We also support ICT providers in answering banks' due diligence questionnaires and contract requirements.
Material scope
A documented ICT risk management framework approved and overseen by the management body: identification, protection, detection, response, recovery, backup and learning.
Classification of ICT incidents and reporting of major incidents to the supervisor: an initial notification within hours, an intermediate report within 72 hours and a final report within one month.
A testing program with at least yearly tests of systems supporting critical or important functions, and threat-led penetration testing (TLPT) at least every three years for entities selected by the supervisor.
A register of information on all ICT contracts, due diligence of providers, mandatory contract clauses, exit strategies and oversight of critical ICT providers.
Voluntary exchange of cyber threat information and intelligence between financial entities within trusted communities.
Our gap analysis shows your maturity in each pillar, with priorities and effort estimates.
Request a DORA gap analysisOur services
A detailed review of your ICT infrastructure, security policies and operating procedures, with an action plan that closes every gap.
The ICT risk management framework, incident response, business continuity and recovery procedures that DORA requires.
Risk assessment of ICT providers, the register of information, DORA contract clauses and exit strategies — including for cloud services.
Vulnerability assessments, penetration tests, scenario-based tests and incident simulations — and TLPT for significant entities.
Tailored training for staff and the management body on ICT risk, data security, testing and incident response.
Ongoing tracking of your compliance level and support with reporting major ICT incidents to the supervisory authority.
How we work
A 30-minute call with an engineer — we'll outline the scope and ballpark budget, with no sales pitch.
Questions and answers
DORA applies to around twenty types of financial entities, including credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers and reinsurers, pension funds, trading venues and fund managers. Critical ICT third-party providers are directly overseen by the European supervisory authorities, and all ICT providers are affected through contracts with their financial clients.
DORA has applied since 17 January 2025. Since then, financial entities must have the required framework, register of information, incident reporting and testing program in place and be able to show them to the supervisor.
Financial entities must test all ICT systems and applications supporting critical or important functions at least once a year. Entities identified by the supervisor as significant must also perform threat-led penetration testing (TLPT) at least every three years — see our TLPT service.
Under the technical standards, the initial notification is due within 4 hours of classifying an incident as major (and no later than 24 hours after becoming aware of it), the intermediate report within 72 hours of the initial notification, and the final report within one month.
It is a structured register of all contractual arrangements with ICT third-party service providers, maintained at entity and group level and submitted to the supervisor. It shows which providers support which functions and how critical they are.
Yes. Banks must include specific clauses in ICT contracts and assess their providers, so you will receive security questionnaires, audit rights and requirements for incident reporting, testing and exit plans. We help ICT providers prepare policies, evidence and answers to these questionnaires.
For financial entities DORA is the more specific law, so its ICT risk management and incident reporting requirements apply instead of the corresponding NIS2 rules. Entities outside the financial sector follow NIS2 / KSC 2.0.
A typical engagement takes about 12 weeks, depending on the size of the organization and the number of critical functions and ICT providers. Our largest DORA audit took more than 460 hours. We confirm the schedule in the proposal.
Penalties are set by member states and enforced by national supervisors — in Poland, the KNF. They can include administrative fines, orders to remedy breaches and measures against members of the management body, who are ultimately responsible for ICT risk management.
Related services
First step
30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.
A proposal with scope and pricing within 48 hours of the call.
Go to contact