DORA compliance readiness

DORA Compliance Services: ICT Risk, Incident Reporting, and Third-Party Readiness

DORA compliance readiness for EU financial entities and the ICT providers that serve them. We assess your ICT risk management, incident reporting, resilience testing, and third-party oversight against the Digital Operational Resilience Act, then give you a risk-ranked roadmap. Most programs take 6–12 weeks.

DORA with Accredify Global
6–12 wksTypical readiness program
5 pillarsAssessed in one engagement
17 Jan 2025DORA has applied since
19Critical ICT providers designated
23+Technical experts
71Countries covered
FIVE PILLARS
Risk, Incidents, Testing, Third Parties
Plus information sharing
EVIDENCE-LED
Tested on Real Events
Incidents, restores, and vendor reviews
MAPPED
ISO 27001, ISO 22301, NIS2
Reuse the controls you already have
TAILORED
One Tailored Proposal
After a free scoping review
DORA, in plain terms

What Is DORA Compliance?

DORA compliance means meeting the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554. It requires EU financial entities to manage ICT risk and report major ICT incidents. They must also test their digital resilience and control the risk from their ICT third-party providers.

DORA applies directly to around 20 types of financial entities, including banks, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers. It also reaches their ICT providers, including US SaaS, cloud, and managed service companies, through contract requirements.

Accredify Global assesses where you stand against each part of DORA and tests controls on real events. You get a risk-ranked roadmap and the evidence your supervisor or customer will ask for.

ICT riskA governed ICT risk management framework
IncidentsClassification and reporting of major incidents
TestingResilience testing, including TLPT for some
Third partiesRegister, contracts, and exit plans
Where the rules stand

DORA in 2026: Applicable, Supervised, and Reaching ICT Providers

DORA has applied since 17 January 2025. Supervisors now expect financial entities to show it working. That means an ICT risk framework in use, major incidents reported on time, and a register of ICT third-party arrangements submitted each year. In 2026 many supervisors repeated the register collection with a narrower scope.

On 18 November 2025, the European Supervisory Authorities designated the first 19 critical ICT third-party providers, including major cloud platforms. They are now directly overseen at EU level. There is no DORA certification: compliance is shown through evidence, supervision, and the contracts financial entities sign with their providers.

17 Jan 2025DORA applicable
18 Nov 2025First 19 critical ICT providers designated
AnnualRegister of information reporting

Sources: Regulation (EU) 2022/2554 (EUR-Lex) · Critical ICT provider designations · FSMA: register of information in 2026

Requirements

DORA Compliance Requirements: The Five Pillars, and What We Assess

Each pillar has detailed technical standards behind it. This is what each one asks, and what our assessment checks.

PillarWhat DORA requiresWhat we assess
ICT risk managementA governed framework, with the management body accountablePolicies, asset inventory, protection, detection, backup, and board oversight
Incident management & reportingClassify ICT incidents and report major ones to the supervisorClassification criteria, escalation, and reporting drills against the deadlines
Resilience testingA testing program; threat-led penetration testing for significant entitiesTest plans, scenario coverage, and remediation of test findings
ICT third-party riskA register of information, required contract terms, and exit strategiesRegister completeness, contract clauses, concentration risk, and exit plans
Information sharingVoluntary sharing of cyber threat informationParticipation arrangements and how intelligence feeds risk decisions
Who this is for

Who Needs DORA Compliance?

DORA is not only for EU banks. It reaches every link in the financial sector's ICT supply chain.

Banks, insurers & investment firms

EU-regulated entities that must meet DORA directly and answer to their supervisor.

Payment & e-money institutions

Smaller regulated firms applying DORA's requirements in proportion to their size and risk.

Crypto-asset service providers

Firms authorized under MiCA, which also fall within DORA's scope.

US SaaS & cloud providers

ICT providers whose EU financial customers must add DORA terms to their contracts.

Managed service providers

IT and security providers that support critical or important functions for financial entities.

Fintech & regtech

Growing firms that need DORA evidence to win and keep regulated customers.

Two areas to get right

DORA Incident Reporting and Third-Party Requirements

Both depend on fast decisions and complete records, so we test them in detail.

Major incident reporting deadlines

Initial notificationWithin 4 hours of classifying as major, and no later than 24 hours after becoming aware
Intermediate reportWithin 72 hours of the initial notification
Final reportWithin one month of the latest intermediate report

We test whether your team can classify an incident and meet these deadlines, using a realistic scenario.

DORA compliance checklist: third-party oversight

  • A complete register of information on all ICT third-party arrangements
  • Which providers support critical or important functions
  • Required contract terms, including audit, access, and termination rights
  • Risk assessment before signing, and ongoing monitoring
  • Concentration risk across providers
  • Tested exit strategies for critical services
How it works

How Our DORA Readiness Assessment Works

Six stages from scoping call to a roadmap your management body can approve.

Scope & entity typeYour role under DORA, critical functions, and proportionality.
Governance reviewICT risk framework, roles, and management body oversight.
Control testingIncidents, backups, and testing checked against real events.
Third-party reviewRegister, contracts, concentration risk, and exit plans.
Risk-ranked roadmapGaps prioritized by supervisory and business risk.
Leadership reportA readiness summary for your board and supervisor.

Not sure whether DORA applies to you, or what your EU customers will ask for? A free scoping review answers that first.

Book a free scoping review
Why Accredify Global

What Our DORA Compliance Services Improve

The outcomes risk, security, and leadership teams care about most.

Stronger ICT governance

Clear ownership of ICT risk, with management body oversight that is documented and real, not just a signed policy.

Incident readiness you can prove

A classification method and escalation path tested against DORA's reporting deadlines on a realistic scenario.

Third-party oversight that holds up

A complete register, contract gaps identified, and exit plans for the providers behind critical functions.

Less duplicated work

Findings mapped to ISO 27001, ISO 22301, NIS2, and SOC 2, so existing evidence is reused.

Cost and timeline

DORA Readiness Cost and Timeline

There is no list price. The cost follows your entity type, the number of critical functions and ICT providers, and how mature your controls are. A free scoping review gives you a tailored proposal.

What moves the cost

  • Your role — financial entity, ICT provider, or both
  • Critical functions — how many, and which systems support them
  • Third parties — the number of ICT providers in your register
  • Entities and countries — group structures and multiple supervisors
  • Reuse — ISO 27001, ISO 22301, or SOC 2 evidence already in place

How long it takes

Assessment and roadmap6–12 weeks, depending on scope
Closing gapsSet by your roadmap and team capacity
Register of informationUpdated and reported every year
How it fits with what you have

DORA vs NIS2, ISO 27001, ISO 22301, and SOC 2

DORA overlaps with the frameworks most financial and ICT firms already hold.

FrameworkWhat it isHow it relates to DORA
NIS2An EU directive on cybersecurity for essential and important entitiesFor financial entities, DORA applies as the sector-specific rule where it covers the same ground.
ISO 27001A certifiable information security standardCovers much of DORA's ICT risk pillar, but not incident reporting deadlines or the register.
ISO 22301A certifiable business continuity standardSupports DORA's continuity, recovery, and testing expectations.
SOC 2A CPA attestation report for service organizationsUseful evidence for ICT providers answering financial customers' DORA questions.
Choosing a partner

How to Choose DORA Compliance Services

The questions worth asking before you sign, and how Accredify Global answers them.

Question to askAccredify Global's answer
Can you certify us for DORA?No one can. There is no DORA certification; we assess readiness and help you build evidence.
Do you test controls or only review policies?We test on real events: incidents, backup restores, and vendor reviews.
Do you cover ICT providers as well as financial entities?Yes. We assess both sides of the contract.
Do you perform threat-led penetration testing?TLPT needs specialist testers under the TIBER-EU approach. Where it applies, we coordinate specialists within the same plan.
Do you give legal advice?No. Where legal interpretation is needed, we coordinate it within the same plan.
How is it priced?A tailored proposal after a free scoping review.
Deliverables

Typical DORA Deliverables

Current-state ICT risk assessment

Where you stand against each DORA pillar.

Risk-ranked roadmap

Remediation actions in priority order, with owners.

Third-party oversight review

Register completeness, contract gaps, and exit plan status.

Incident drill report

How your team performed against the reporting deadlines.

Evidence support

Records organized for your supervisor or financial customers.

Leadership summary

A compliance report your management body can approve.

Common questions

Frequently Asked Questions About DORA Compliance

Straight answers on scope, requirements, incident reporting, third parties, cost, and timeline.

What is DORA compliance?

DORA compliance means meeting the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554. Financial entities must manage ICT risk, report major ICT incidents, test their digital resilience, and control risk from their ICT third-party providers.

When did DORA come into effect?

DORA has applied since 17 January 2025. Supervisors now expect financial entities to show it working, including an annual register of information on ICT third-party arrangements.

Who does DORA apply to?

DORA applies directly to around 20 types of EU financial entities, including banks, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers. It also affects their ICT third-party providers through required contract terms, and critical ICT providers through direct EU oversight.

Is DORA only relevant for EU banks?

No. It covers many types of financial entity. It is also highly relevant for ICT providers, including US SaaS, cloud, and managed service companies, that support regulated financial entities in the EU.

What are the five pillars of DORA?

ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing on cyber threats.

Is there a DORA certification?

No. There is no official DORA certification. Compliance is shown through evidence, supervisory review, and the contracts financial entities sign with their ICT providers. Accredify Global assesses readiness and helps you build that evidence.

What are the DORA incident reporting deadlines?

For a major ICT incident, the initial notification is due within 4 hours of classifying it as major. It must be no later than 24 hours after becoming aware. An intermediate report follows within 72 hours, and a final report within one month of the latest intermediate report.

What is the DORA register of information?

It is a register of all ICT third-party arrangements that a financial entity maintains and reports to its supervisor each year. It shows which providers support critical or important functions.

What are critical ICT third-party providers under DORA?

They are ICT providers designated by the European Supervisory Authorities for direct EU oversight. The first 19 were designated on 18 November 2025, including major cloud platforms. Financial entities still manage their own risk from these providers.

Does DORA compliance include third-party risk?

Yes. ICT third-party risk is one of DORA's five pillars. It covers the register of information, required contract terms, risk assessment, monitoring, concentration risk, and exit strategies.

What is threat-led penetration testing (TLPT) under DORA?

TLPT is advanced, intelligence-led testing of live production systems that significant financial entities must perform at least every three years. It uses specialist testers, and Accredify Global coordinates specialists where it applies.

What is the difference between DORA and NIS2?

Both are EU laws on digital resilience. NIS2 covers essential and important entities across many sectors, while DORA is the sector-specific rule for financial entities. Where they overlap, DORA applies to financial entities.

Can DORA work connect to existing security programs?

Yes. DORA overlaps with ISO 27001, ISO 22301, SOC 2, incident response, continuity planning, and vendor risk programs. We map existing evidence to DORA before planning new work.

How much does DORA compliance cost?

The cost depends on your role under DORA and the number of critical functions and ICT providers. Group structure, countries, and control maturity also matter. Accredify Global reviews your scope for free and sends a tailored proposal.

How long does a DORA readiness assessment take?

Most Accredify Global DORA readiness assessments and roadmaps take 6 to 12 weeks, depending on scope. Closing the gaps then follows your roadmap.

Free DORA scoping review

Find Out Where You Stand on DORA, Before Your Supervisor or Customer Asks

Tell us about your role, critical functions, and ICT providers. We'll confirm how DORA applies, recommend a timeline, and send a tailored proposal.

Book your free scoping review →
Prefer to talk first? +1-214-899-5643 · Request a DORA proposal

Last reviewed by the Accredify Global compliance team.

Request Proposal - ISO, SOC & Compliance Services
Please select at least one option
08P19

Ready to Start Your Certification or Compliance Journey?

Tell us your requirement — we'll help identify the right certification, framework, and timeline. Free 15-minute consultation available.