DORA, without an enterprise budget.

ICT risk management, incident reporting, third-party oversight and resilience testing — 260 controls, included.

Operational resilience, now supervised

The Digital Operational Resilience Act applies across the EU financial sector and it is broad by design: ICT risk management, incident classification and reporting, resilience testing, and oversight of third-party ICT providers — with a register of information you are expected to maintain and submit.

Most DORA tooling is priced for tier-one banks. If you are a payment institution, an insurance intermediary, a crypto-asset provider or a smaller investment firm, you carry a comparable obligation on a fraction of the budget.

OpenGRC includes DORA and the regulatory technical standards bundles — ICT risk management, incident reporting, ICT services supporting critical functions, threat-led penetration testing — on every plan.

Built for the regulation

The four pillars, operationalised.

Third-party ICT register

Third-party ICT register

DORA expects a maintained register of ICT third-party arrangements. Vendor management holds the inventory, contract and document tracking with expiry, risk scoring and questionnaires — and the application registry records what each one supports.

Incident classification and reporting

Incident classification and reporting

Incidents follow a six-phase process with playbooks, tasks and a full timeline, and notification deadline tracking runs the clock from the moment an incident is opened.

Resilience testing evidence

Resilience testing evidence

Testing programmes, including threat-led penetration testing, produce findings that flow into remediation projects with owners and milestones rather than sitting in a PDF.

DORA and its technical standards

BundleControls
DORA — the Regulation260
RTS on ICT risk management frameworkIncluded
RTS on ICT-related incident classificationIncluded
RTS on incident reportingIncluded
RTS on ICT services supporting critical functionsIncluded
RTS on threat-led penetration testingIncluded
RTS on joint examination teams and oversight conductIncluded

DORA questions

Does DORA apply to us?

It applies broadly across EU financial entities — banks, insurers and intermediaries, investment firms, payment and e-money institutions, crypto-asset service providers and more — and to critical ICT third-party providers serving them. Scope is a legal question, not a software one, so take advice if you are unsure.

What about the register of information?

We already do ISO 27001. Does that help?

Are the RTS bundles included?