Regulation · EU

DORA, without the spreadsheets.

Prove operational resilience to EU financial regulators — and to the banks you supply.

What is DORA?

DORA harmonises ICT risk management rules for the EU financial sector and has applied since 17 January 2025. Financial entities must manage ICT risk, report major incidents, test their resilience and control their ICT third-party providers — which pulls those providers into scope through contracts.

Who needs it

  • Banks, payment and e-money institutions, investment firms and insurers in the EU
  • ICT service providers supplying EU financial entities
  • Fintechs whose customers must register their ICT contracts

What DORA looks at

ICT risk management

A documented framework for identifying, protecting, detecting, responding to and recovering from ICT risks.

Incident reporting

Classifying ICT-related incidents and reporting major ones to the competent authority.

Resilience testing

Regular testing, with threat-led penetration testing for significant entities.

ICT third-party risk

Contractual requirements, exit strategies and a register of information for ICT providers.

How Beviso gets you there

  • DORA requirements pre-loaded alongside ISO 27001 and NIS 2, with shared evidence
  • Vendor register for ICT third-party providers and their contracts
  • Incident log and business continuity evidence

10 DORA controls, ready on day one

These controls are loaded when you enable DORA, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.

Art.9

ICT Risk Management Framework

Financial entities shall have a sound, comprehensive, and well-documented ICT risk management framework to identify, classify, and manage ICT risks.

Evidence from

  • Snyk
  • Wiz
  • Qualys
  • Rapid7
  • CrowdStrike
  • Lacework

Art.9.4.a

ICT Asset Management

ICT assets that support business functions shall be inventoried and classified.

Evidence from

  • AWS
  • DigitalOcean
  • Hetzner
  • Jamf
  • Kandji
  • SentinelOne

Art.9.4.b

Protection and Prevention Measures

Appropriate protection measures shall be in place to prevent ICT-related incidents.

Evidence from

  • CrowdStrike
  • SentinelOne
  • Cloudflare
  • AWS
  • DigitalOcean

Art.9.4.c

Detection Mechanisms

Detection mechanisms enabling prompt identification of anomalous activities shall be established.

Evidence from

  • Datadog
  • Grafana
  • Splunk
  • New Relic
  • AWS
  • Dynatrace

Art.10

ICT-Related Incident Management

Financial entities shall define, establish, and implement an ICT-related incident management process.

Evidence from

  • PagerDuty
  • ServiceNow
  • Jira
  • CrowdStrike

Art.11

Business Continuity — ICT

Financial entities shall put in place a comprehensive ICT business continuity policy.

Evidence from

  • PagerDuty
  • Datadog
  • Grafana
  • AWS

Art.13

Learning from ICT Incidents

Financial entities shall have capabilities in place to gather indicators of compromise and post-incident reviews.

Evidence from

  • PagerDuty
  • ServiceNow
  • Datadog
  • Splunk

Art.24

Third-Party ICT Service Provider Risk

Financial entities shall manage third-party ICT service provider risk as an integral component of ICT risk.

Evidence from

  • Ironclad
  • DocuSign

Art.25

Contractual Arrangements with ICT Providers

Key contractual provisions with ICT service providers shall be established and maintained.

Evidence from

  • Ironclad
  • DocuSign

Art.28

Digital Operational Resilience Testing

Financial entities shall establish, maintain, and review a sound and comprehensive digital operational resilience testing programme.

Evidence from

  • Snyk
  • Detectify
  • HackerOne
  • Qualys
  • Rapid7

DORA questions

We are a SaaS vendor, not a bank. Does DORA affect us?
Indirectly, yes, if you supply EU financial entities. They must include specific terms in ICT contracts and monitor their providers, so expect detailed security and resilience questions.

Start your DORA programme today.

Free while Beviso is in beta. No credit card required.

Get started free