DORA: digital operational resilience with evidence behind it
Map the five DORA pillars to controls with automated checks, keep the register of information for your ICT third parties current, record incidents and tests as dated evidence, and show your competent authority that resilience is managed, not asserted.
What is DORA?
DORA is the European Union's Digital Operational Resilience Act, Regulation (EU) 2022/2554, which applies from 17 January 2025. It requires financial entities, including banks, insurers, investment firms, payment and e-money institutions and crypto-asset service providers, to manage the risks of their information and communication technology under one binding regime, and it brings the ICT third-party providers that serve them into scope. The regulation has five pillars: an ICT risk management framework owned by the management body; ICT-related incident management, classification and reporting to the competent authority; digital operational resilience testing, up to threat-led penetration testing for the most significant entities; ICT third-party risk management, including a register of information on every contractual arrangement and mandatory contract terms; and arrangements for sharing threat intelligence. The European Supervisory Authorities oversee critical third-party providers directly. There is no DORA certificate: supervisors assess the framework, the register, the incident records and the test results, which is why the evidence has to exist before they ask.
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, applies from 17 January 2025 to financial entities in the European Union, from banks, insurers and investment firms to payment institutions and crypto-asset service providers, and to the ICT third-party providers that serve them. It sets binding requirements for ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. There is no DORA certificate; compliance is supervised by national competent authorities.
EU financial entities of every size, and the SaaS and ICT providers that serve them and are asked for DORA-aligned contracts, registers and evidence.
How Viglyn runs DORA
- The ICT risk management framework mapped control by control, with automated checks on identity, access, logging, backups, vulnerability management and change across your cloud and code systems
- The register of information on ICT third-party arrangements kept in the vendor module: provider, service, criticality, contract terms, sub-contracting and exit plans, exportable in the structure supervisors expect
- Incident classification, the reporting clock and the post-incident review held as dated evidence, so major incident reports are built from records, not memory
- Resilience testing evidence: vulnerability scans in one inventory with prioritization shown, scenario tests and penetration test reports as controlled documents
- Shared evidence with ISO 27001, ISO 22301 and NIST CSF, so the resilience work is done once
The DORA questions that decide it
Does DORA apply to a SaaS company?
If you provide ICT services to a financial entity in the EU, yes, indirectly: your customer must put you in its register of information, include DORA's mandatory terms in your contract, and assess you. Expect those customers to ask for your incident, testing and third-party evidence.
How long does DORA readiness take?
Three to six months is typical for a financial entity with an ISO 27001 management system in place, because most of the ICT risk framework carries over. The register of information and the incident reporting process are the parts that need building; Viglyn's vendor module and practitioners do them with you.
How much does DORA cost with Viglyn?
DORA counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. There is no certificate and so no auditor fee; what you need is a framework, a register and evidence your supervisor can inspect.
More DORA questions
What is the register of information?
How are incidents classified and reported?
What is threat-led penetration testing?
See DORA run on your stack
A 30-minute walkthrough with your systems and your framework. No commitment.
