Regulatory Programme

DORA, Run As A Programme

The Digital Operational Resilience Act applies directly to financial entities across the EU. There is no certificate to earn. What a competent authority looks for is an ICT risk management framework the board owns, a register of information it can request, and evidence that you test your resilience rather than assume it. Auditara turns that into a programme you can actually run.

What This Is, And What It Is Not

Not Legal Advice

Auditara is a compliance programme platform delivered with a PECB certified Lead Auditor and Lead Implementer. It is not a law firm and does not provide legal advice. Where a question turns on legal interpretation or on guidance from your competent authority, we will tell you to take advice.

Not A Certificate

DORA is a regulation with direct effect. Nobody issues a DORA certificate. What you get here is a defensible framework and the evidence behind it.

Proportionate By Design

Smaller entities may apply a simplified ICT risk management framework. The intake captures which applies to you so the programme fits the entity rather than the largest bank in the market.

Works Alongside ISO 27001

The protection and detection obligations map closely onto an ISO 27001 control set. Run both in the same workspace and the security evidence serves both programmes.

What The Programme Covers

Thirty seven obligations across the five pillars of the regulation, each assessed with your context and evidence guidance in plain English.

ICT Risk Management Framework

The governance document everything else hangs from: strategy, risk tolerance, defined roles, an independent control function, and management body approval with recorded oversight.

Critical Functions And Assets

Identifying which functions are critical or important, the ICT assets supporting them, and the dependencies that could take them down.

Protection, Detection And Recovery

Preventive controls, anomaly detection with defined alert thresholds, ICT business continuity, backups held apart from production, and recovery objectives set per critical function rather than as one global number.

Incident Classification And Reporting

Applying the criteria that make an incident major, then the initial, intermediate and final reports to your competent authority, plus client communication where their interests are affected.

Resilience Testing

A testing programme rather than ad hoc tests: vulnerability assessments, scenario based testing and performance testing at least annually on critical systems, and an assessment of whether threat led penetration testing applies to you.

Third Party Risk And The Register

The register of information covering every ICT contractual arrangement, flagged where it supports a critical function, plus the mandatory contract provisions and exit strategies the regulation names.

Learning And Improvement

Post incident reviews, threat and vulnerability intake, and reviews that feed back into the framework, reported to the management body.

Training At Every Level

ICT security awareness for staff and digital operational resilience training for the management body, because under DORA the board cannot delegate the responsibility away.

How The Programme Runs

The same guided journey as every framework in Auditara. The content changes; the method does not.

Step 1

Book The Call

Fifteen minutes with a PECB certified Lead Auditor and Lead Implementer. Your entity type, whether the simplified framework applies, your critical functions, and what is driving the deadline. Your workspace opens after the call.

Step 2

Answer The Intake

Plain English questions about your organisation. Your answers shape the programme, the framework document and the register.

Step 3

Assess Every Obligation

Work through the obligations one at a time in guided mode, with guidance on each explaining what evidence looks like in practice.

Step 4

Build The Register And The Contracts View

Every ICT provider recorded, the critical ones flagged, contract provisions checked against the requirements, and exit strategies where a critical function depends on someone else.

Step 5

Prove Resilience By Testing It

The testing programme, the annual execution on critical systems, and the findings tracked to closure rather than filed.

Step 6

Stay Authority Ready

Reviews come round on a schedule, the register stays current, and what a supervisor would request is a download rather than a scramble.

Every route starts with a call with a certified ISO 27001 and ISO 42001 Lead Implementer.

Book A Call

Questions

Does DORA apply to us?

It applies to a wide range of financial entities, including credit institutions, payment and e money institutions, investment firms, insurers, crypto asset service providers and more, as well as to ICT providers designated as critical. The intake captures your entity type and we confirm it on the call.

What is the register of information?

A structured record of every contractual arrangement with an ICT third party provider, flagging those supporting critical or important functions. Authorities request it in a defined format, so it needs to be maintained rather than assembled on demand.

Do we have to do threat led penetration testing?

Only entities identified by their competent authority do. Most do not. The programme includes the applicability assessment so you have a documented answer either way.

How is this different from what we already do for operational resilience?

Much of the substance will be familiar. What DORA adds is the specific framework structure, the register, the classification and reporting criteria for major incidents, the testing programme, and the contract provisions that must be in place with providers.

Can we use the simplified framework?

Some smaller entities can. It reduces the depth of what is required rather than removing the obligation. The intake asks, and we confirm the position with you.

Who is accountable?

The management body defines, approves and oversees the framework and bears final responsibility. That is why board approval, board oversight and board training appear as obligations in their own right.

Ready To Get Started?

Book the call. Fifteen minutes, no obligation, and you leave with a route.

See all frameworks