DORA, without an enterprise budget.
ICT risk management, incident reporting, third-party oversight and resilience testing — 260 controls, included.
Operational resilience, now supervised
The Digital Operational Resilience Act applies across the EU financial sector and it is broad by design: ICT risk management, incident classification and reporting, resilience testing, and oversight of third-party ICT providers — with a register of information you are expected to maintain and submit.
Most DORA tooling is priced for tier-one banks. If you are a payment institution, an insurance intermediary, a crypto-asset provider or a smaller investment firm, you carry a comparable obligation on a fraction of the budget.
OpenGRC includes DORA and the regulatory technical standards bundles — ICT risk management, incident reporting, ICT services supporting critical functions, threat-led penetration testing — on every plan.
The four pillars, operationalised.
Third-party ICT register
DORA expects a maintained register of ICT third-party arrangements. Vendor management holds the inventory, contract and document tracking with expiry, risk scoring and questionnaires — and the application registry records what each one supports.
Incident classification and reporting
Incidents follow a six-phase process with playbooks, tasks and a full timeline, and notification deadline tracking runs the clock from the moment an incident is opened.
Resilience testing evidence
Testing programmes, including threat-led penetration testing, produce findings that flow into remediation projects with owners and milestones rather than sitting in a PDF.
DORA and its technical standards
| Bundle | Controls |
|---|---|
| DORA — the Regulation | 260 |
| RTS on ICT risk management framework | Included |
| RTS on ICT-related incident classification | Included |
| RTS on incident reporting | Included |
| RTS on ICT services supporting critical functions | Included |
| RTS on threat-led penetration testing | Included |
| RTS on joint examination teams and oversight conduct | Included |
DORA questions
Does DORA apply to us?
It applies broadly across EU financial entities — banks, insurers and intermediaries, investment firms, payment and e-money institutions, crypto-asset service providers and more — and to critical ICT third-party providers serving them. Scope is a legal question, not a software one, so take advice if you are unsure.
™