Home/Audit/DORA audit

02 · Audit

DORA audit and implementation

Digital operational resilience for banks, payment institutions, insurers, crypto-asset service providers and their ICT providers — gap analysis, policies, third-party risk, resilience testing and incident reporting.

460+hours in our largest audit
5 pillarsall covered in one audit
12 weekstypical delivery time

Service details

What is DORA?

DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) is the EU regulation that requires financial entities to withstand, respond to and recover from ICT disruptions and cyberattacks. It has applied since 17 January 2025 to banks, payment and e-money institutions, investment firms, insurers, crypto-asset service providers and many other financial entities — and indirectly to the ICT providers that serve them.

Remote Admin audits your organization against DORA, prepares the missing policies and procedures, tests your resilience in practice and helps you manage ICT third-party risk. We also support ICT providers in answering banks' due diligence questionnaires and contract requirements.

  • Gap analysis across all five DORA pillars
  • Documentation, testing and evidence for the supervisor
  • Support for ICT providers of financial institutions
Audit

Material scope

The five pillars of DORA

1

ICT risk management

A documented ICT risk management framework approved and overseen by the management body: identification, protection, detection, response, recovery, backup and learning.

2

ICT incident management and reporting

Classification of ICT incidents and reporting of major incidents to the supervisor: an initial notification within hours, an intermediate report within 72 hours and a final report within one month.

3

Digital operational resilience testing

A testing program with at least yearly tests of systems supporting critical or important functions, and threat-led penetration testing (TLPT) at least every three years for entities selected by the supervisor.

4

ICT third-party risk

A register of information on all ICT contracts, due diligence of providers, mandatory contract clauses, exit strategies and oversight of critical ICT providers.

5

Information sharing

Voluntary exchange of cyber threat information and intelligence between financial entities within trusted communities.

Not sure where you stand?

Our gap analysis shows your maturity in each pillar, with priorities and effort estimates.

Request a DORA gap analysis

Our services

How we support financial entities with DORA

DORA compliance audit

A detailed review of your ICT infrastructure, security policies and operating procedures, with an action plan that closes every gap.

Operational resilience policies

The ICT risk management framework, incident response, business continuity and recovery procedures that DORA requires.

Third-party risk and contracts

Risk assessment of ICT providers, the register of information, DORA contract clauses and exit strategies — including for cloud services.

Resilience testing

Vulnerability assessments, penetration tests, scenario-based tests and incident simulations — and TLPT for significant entities.

Training

Tailored training for staff and the management body on ICT risk, data security, testing and incident response.

Monitoring and reporting

Ongoing tracking of your compliance level and support with reporting major ICT incidents to the supervisory authority.

How we work

A DORA audit in four steps

Scope and proportionalityWe identify your entity type, critical or important functions and the systems and ICT providers that support them.
Gap analysisMaturity assessment across the five pillars and the related technical standards — a report with priorities and effort estimates.
RemediationPolicies and procedures, register of information, contract updates, testing program and training.
Evidence and maintenanceDocumentation ready for supervisory inspections, periodic reviews and resilience testing year after year.
Not sure which option to choose?

A 30-minute call with an engineer — we'll outline the scope and ballpark budget, with no sales pitch.

Book a consultation

Questions and answers

DORA FAQ

Who does DORA apply to?

DORA applies to around twenty types of financial entities, including credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers and reinsurers, pension funds, trading venues and fund managers. Critical ICT third-party providers are directly overseen by the European supervisory authorities, and all ICT providers are affected through contracts with their financial clients.

When did DORA start to apply?

DORA has applied since 17 January 2025. Since then, financial entities must have the required framework, register of information, incident reporting and testing program in place and be able to show them to the supervisor.

How often is resilience testing required?

Financial entities must test all ICT systems and applications supporting critical or important functions at least once a year. Entities identified by the supervisor as significant must also perform threat-led penetration testing (TLPT) at least every three years — see our TLPT service.

What are the deadlines for reporting major ICT incidents?

Under the technical standards, the initial notification is due within 4 hours of classifying an incident as major (and no later than 24 hours after becoming aware of it), the intermediate report within 72 hours of the initial notification, and the final report within one month.

What is the register of information?

It is a structured register of all contractual arrangements with ICT third-party service providers, maintained at entity and group level and submitted to the supervisor. It shows which providers support which functions and how critical they are.

We are an ICT provider to a bank. Does DORA affect us?

Yes. Banks must include specific clauses in ICT contracts and assess their providers, so you will receive security questionnaires, audit rights and requirements for incident reporting, testing and exit plans. We help ICT providers prepare policies, evidence and answers to these questionnaires.

How does DORA relate to NIS2?

For financial entities DORA is the more specific law, so its ICT risk management and incident reporting requirements apply instead of the corresponding NIS2 rules. Entities outside the financial sector follow NIS2 / KSC 2.0.

How long does a DORA audit take?

A typical engagement takes about 12 weeks, depending on the size of the organization and the number of critical functions and ICT providers. Our largest DORA audit took more than 460 hours. We confirm the schedule in the proposal.

What are the penalties for non-compliance?

Penalties are set by member states and enforced by national supervisors — in Poland, the KNF. They can include administrative fines, orders to remedy breaches and measures against members of the management body, who are ultimately responsible for ICT risk management.

First step

Let's talk about a DORA audit.

30 minutes, no slide deck. We'll tell you straight whether this service solves your problem, what scope makes sense and how much it costs.

Book a consultation

A proposal with scope and pricing within 48 hours of the call.

Go to contact