Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
DORA

DORA: digital operational resilience with evidence behind it

Map the five DORA pillars to controls with automated checks, keep the register of information for your ICT third parties current, record incidents and tests as dated evidence, and show your competent authority that resilience is managed, not asserted.

What is DORA?

DORA is the European Union's Digital Operational Resilience Act, Regulation (EU) 2022/2554, which applies from 17 January 2025. It requires financial entities, including banks, insurers, investment firms, payment and e-money institutions and crypto-asset service providers, to manage the risks of their information and communication technology under one binding regime, and it brings the ICT third-party providers that serve them into scope. The regulation has five pillars: an ICT risk management framework owned by the management body; ICT-related incident management, classification and reporting to the competent authority; digital operational resilience testing, up to threat-led penetration testing for the most significant entities; ICT third-party risk management, including a register of information on every contractual arrangement and mandatory contract terms; and arrangements for sharing threat intelligence. The European Supervisory Authorities oversee critical third-party providers directly. There is no DORA certificate: supervisors assess the framework, the register, the incident records and the test results, which is why the evidence has to exist before they ask.

In one paragraph

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, applies from 17 January 2025 to financial entities in the European Union, from banks, insurers and investment firms to payment institutions and crypto-asset service providers, and to the ICT third-party providers that serve them. It sets binding requirements for ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. There is no DORA certificate; compliance is supervised by national competent authorities.

Who it's for

EU financial entities of every size, and the SaaS and ICT providers that serve them and are asked for DORA-aligned contracts, registers and evidence.

With Viglyn

How Viglyn runs DORA

  • The ICT risk management framework mapped control by control, with automated checks on identity, access, logging, backups, vulnerability management and change across your cloud and code systems
  • The register of information on ICT third-party arrangements kept in the vendor module: provider, service, criticality, contract terms, sub-contracting and exit plans, exportable in the structure supervisors expect
  • Incident classification, the reporting clock and the post-incident review held as dated evidence, so major incident reports are built from records, not memory
  • Resilience testing evidence: vulnerability scans in one inventory with prioritization shown, scenario tests and penetration test reports as controlled documents
  • Shared evidence with ISO 27001, ISO 22301 and NIST CSF, so the resilience work is done once
Straight answers

The DORA questions that decide it

Does DORA apply to a SaaS company?

If you provide ICT services to a financial entity in the EU, yes, indirectly: your customer must put you in its register of information, include DORA's mandatory terms in your contract, and assess you. Expect those customers to ask for your incident, testing and third-party evidence.

How long does DORA readiness take?

Three to six months is typical for a financial entity with an ISO 27001 management system in place, because most of the ICT risk framework carries over. The register of information and the incident reporting process are the parts that need building; Viglyn's vendor module and practitioners do them with you.

How much does DORA cost with Viglyn?

DORA counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. There is no certificate and so no auditor fee; what you need is a framework, a register and evidence your supervisor can inspect.

FAQ

More DORA questions

What is the register of information?
A structured record of every contractual arrangement for ICT services, with the provider, the function it supports, its criticality, sub-contractors and exit arrangements, maintained at entity, sub-consolidated and consolidated level and reported to the competent authority on request. Viglyn's vendor module holds the fields and exports the register.
How are incidents classified and reported?
Incidents are classified against criteria such as clients affected, duration, geographic spread, data losses and economic impact. Major ICT-related incidents must be reported to the competent authority in stages, an initial notification, an intermediate report and a final report, on the deadlines set in the technical standards. Viglyn keeps the classification and the clock with the incident record.
What is threat-led penetration testing?
TLPT is an intelligence-led red-team test of live production systems, required at least every three years for the financial entities their authorities designate, following the TIBER-EU style framework. All in-scope entities must also run a broader program of resilience tests on the systems that support critical functions at least yearly; Viglyn holds the scopes, results and remediation as evidence.

See DORA run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.