DORA, without the spreadsheets.
Prove operational resilience to EU financial regulators — and to the banks you supply.
What is DORA?
DORA harmonises ICT risk management rules for the EU financial sector and has applied since 17 January 2025. Financial entities must manage ICT risk, report major incidents, test their resilience and control their ICT third-party providers — which pulls those providers into scope through contracts.
Who needs it
- Banks, payment and e-money institutions, investment firms and insurers in the EU
- ICT service providers supplying EU financial entities
- Fintechs whose customers must register their ICT contracts
What DORA looks at
ICT risk management
A documented framework for identifying, protecting, detecting, responding to and recovering from ICT risks.
Incident reporting
Classifying ICT-related incidents and reporting major ones to the competent authority.
Resilience testing
Regular testing, with threat-led penetration testing for significant entities.
ICT third-party risk
Contractual requirements, exit strategies and a register of information for ICT providers.
How Beviso gets you there
- DORA requirements pre-loaded alongside ISO 27001 and NIS 2, with shared evidence
- Vendor register for ICT third-party providers and their contracts
- Incident log and business continuity evidence
10 DORA controls, ready on day one
These controls are loaded when you enable DORA, each with the tools that can supply its evidence automatically. You can add your own controls alongside them.
Art.9
ICT Risk Management Framework
Financial entities shall have a sound, comprehensive, and well-documented ICT risk management framework to identify, classify, and manage ICT risks.
Evidence from
- Snyk
- Wiz
- Qualys
- Rapid7
- CrowdStrike
- Lacework
Art.9.4.a
ICT Asset Management
ICT assets that support business functions shall be inventoried and classified.
Evidence from
- AWS
- DigitalOcean
- Hetzner
- Jamf
- Kandji
- SentinelOne
Art.9.4.b
Protection and Prevention Measures
Appropriate protection measures shall be in place to prevent ICT-related incidents.
Evidence from
- CrowdStrike
- SentinelOne
- Cloudflare
- AWS
- DigitalOcean
Art.9.4.c
Detection Mechanisms
Detection mechanisms enabling prompt identification of anomalous activities shall be established.
Evidence from
- Datadog
- Grafana
- Splunk
- New Relic
- AWS
- Dynatrace
Art.10
ICT-Related Incident Management
Financial entities shall define, establish, and implement an ICT-related incident management process.
Evidence from
- PagerDuty
- ServiceNow
- Jira
- CrowdStrike
Art.11
Business Continuity — ICT
Financial entities shall put in place a comprehensive ICT business continuity policy.
Evidence from
- PagerDuty
- Datadog
- Grafana
- AWS
Art.13
Learning from ICT Incidents
Financial entities shall have capabilities in place to gather indicators of compromise and post-incident reviews.
Evidence from
- PagerDuty
- ServiceNow
- Datadog
- Splunk
Art.24
Third-Party ICT Service Provider Risk
Financial entities shall manage third-party ICT service provider risk as an integral component of ICT risk.
Evidence from
- Ironclad
- DocuSign
Art.25
Contractual Arrangements with ICT Providers
Key contractual provisions with ICT service providers shall be established and maintained.
Evidence from
- Ironclad
- DocuSign
Art.28
Digital Operational Resilience Testing
Financial entities shall establish, maintain, and review a sound and comprehensive digital operational resilience testing programme.
Evidence from
- Snyk
- Detectify
- HackerOne
- Qualys
- Rapid7
DORA questions
- We are a SaaS vendor, not a bank. Does DORA affect us?
- Indirectly, yes, if you supply EU financial entities. They must include specific terms in ICT contracts and monitor their providers, so expect detailed security and resilience questions.
Often run alongside DORA
Start your DORA programme today.
Free while Beviso is in beta. No credit card required.
Get started free