DORA Compliance Services: ICT Risk, Incident Reporting, and Third-Party Readiness
DORA compliance readiness for EU financial entities and the ICT providers that serve them. We assess your ICT risk management, incident reporting, resilience testing, and third-party oversight against the Digital Operational Resilience Act, then give you a risk-ranked roadmap. Most programs take 6–12 weeks.
What Is DORA Compliance?
DORA compliance means meeting the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554. It requires EU financial entities to manage ICT risk and report major ICT incidents. They must also test their digital resilience and control the risk from their ICT third-party providers.
DORA applies directly to around 20 types of financial entities, including banks, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers. It also reaches their ICT providers, including US SaaS, cloud, and managed service companies, through contract requirements.
Accredify Global assesses where you stand against each part of DORA and tests controls on real events. You get a risk-ranked roadmap and the evidence your supervisor or customer will ask for.
DORA in 2026: Applicable, Supervised, and Reaching ICT Providers
DORA has applied since 17 January 2025. Supervisors now expect financial entities to show it working. That means an ICT risk framework in use, major incidents reported on time, and a register of ICT third-party arrangements submitted each year. In 2026 many supervisors repeated the register collection with a narrower scope.
On 18 November 2025, the European Supervisory Authorities designated the first 19 critical ICT third-party providers, including major cloud platforms. They are now directly overseen at EU level. There is no DORA certification: compliance is shown through evidence, supervision, and the contracts financial entities sign with their providers.
Sources: Regulation (EU) 2022/2554 (EUR-Lex) · Critical ICT provider designations · FSMA: register of information in 2026
DORA Compliance Requirements: The Five Pillars, and What We Assess
Each pillar has detailed technical standards behind it. This is what each one asks, and what our assessment checks.
| Pillar | What DORA requires | What we assess |
|---|---|---|
| ICT risk management | A governed framework, with the management body accountable | Policies, asset inventory, protection, detection, backup, and board oversight |
| Incident management & reporting | Classify ICT incidents and report major ones to the supervisor | Classification criteria, escalation, and reporting drills against the deadlines |
| Resilience testing | A testing program; threat-led penetration testing for significant entities | Test plans, scenario coverage, and remediation of test findings |
| ICT third-party risk | A register of information, required contract terms, and exit strategies | Register completeness, contract clauses, concentration risk, and exit plans |
| Information sharing | Voluntary sharing of cyber threat information | Participation arrangements and how intelligence feeds risk decisions |
Who Needs DORA Compliance?
DORA is not only for EU banks. It reaches every link in the financial sector's ICT supply chain.
EU-regulated entities that must meet DORA directly and answer to their supervisor.
Smaller regulated firms applying DORA's requirements in proportion to their size and risk.
Firms authorized under MiCA, which also fall within DORA's scope.
ICT providers whose EU financial customers must add DORA terms to their contracts.
IT and security providers that support critical or important functions for financial entities.
Growing firms that need DORA evidence to win and keep regulated customers.
DORA Incident Reporting and Third-Party Requirements
Both depend on fast decisions and complete records, so we test them in detail.
Major incident reporting deadlines
| Initial notification | Within 4 hours of classifying as major, and no later than 24 hours after becoming aware |
|---|---|
| Intermediate report | Within 72 hours of the initial notification |
| Final report | Within one month of the latest intermediate report |
We test whether your team can classify an incident and meet these deadlines, using a realistic scenario.
DORA compliance checklist: third-party oversight
- A complete register of information on all ICT third-party arrangements
- Which providers support critical or important functions
- Required contract terms, including audit, access, and termination rights
- Risk assessment before signing, and ongoing monitoring
- Concentration risk across providers
- Tested exit strategies for critical services
How Our DORA Readiness Assessment Works
Six stages from scoping call to a roadmap your management body can approve.
Not sure whether DORA applies to you, or what your EU customers will ask for? A free scoping review answers that first.
Book a free scoping reviewWhat Our DORA Compliance Services Improve
The outcomes risk, security, and leadership teams care about most.
Clear ownership of ICT risk, with management body oversight that is documented and real, not just a signed policy.
A classification method and escalation path tested against DORA's reporting deadlines on a realistic scenario.
A complete register, contract gaps identified, and exit plans for the providers behind critical functions.
DORA Readiness Cost and Timeline
There is no list price. The cost follows your entity type, the number of critical functions and ICT providers, and how mature your controls are. A free scoping review gives you a tailored proposal.
What moves the cost
- Your role — financial entity, ICT provider, or both
- Critical functions — how many, and which systems support them
- Third parties — the number of ICT providers in your register
- Entities and countries — group structures and multiple supervisors
- Reuse — ISO 27001, ISO 22301, or SOC 2 evidence already in place
How long it takes
| Assessment and roadmap | 6–12 weeks, depending on scope |
|---|---|
| Closing gaps | Set by your roadmap and team capacity |
| Register of information | Updated and reported every year |
DORA vs NIS2, ISO 27001, ISO 22301, and SOC 2
DORA overlaps with the frameworks most financial and ICT firms already hold.
| Framework | What it is | How it relates to DORA |
|---|---|---|
| NIS2 | An EU directive on cybersecurity for essential and important entities | For financial entities, DORA applies as the sector-specific rule where it covers the same ground. |
| ISO 27001 | A certifiable information security standard | Covers much of DORA's ICT risk pillar, but not incident reporting deadlines or the register. |
| ISO 22301 | A certifiable business continuity standard | Supports DORA's continuity, recovery, and testing expectations. |
| SOC 2 | A CPA attestation report for service organizations | Useful evidence for ICT providers answering financial customers' DORA questions. |
How to Choose DORA Compliance Services
The questions worth asking before you sign, and how Accredify Global answers them.
| Question to ask | Accredify Global's answer |
|---|---|
| Can you certify us for DORA? | No one can. There is no DORA certification; we assess readiness and help you build evidence. |
| Do you test controls or only review policies? | We test on real events: incidents, backup restores, and vendor reviews. |
| Do you cover ICT providers as well as financial entities? | Yes. We assess both sides of the contract. |
| Do you perform threat-led penetration testing? | TLPT needs specialist testers under the TIBER-EU approach. Where it applies, we coordinate specialists within the same plan. |
| Do you give legal advice? | No. Where legal interpretation is needed, we coordinate it within the same plan. |
| How is it priced? | A tailored proposal after a free scoping review. |
Typical DORA Deliverables
Where you stand against each DORA pillar.
Remediation actions in priority order, with owners.
Register completeness, contract gaps, and exit plan status.
How your team performed against the reporting deadlines.
Records organized for your supervisor or financial customers.
A compliance report your management body can approve.
Frequently Asked Questions About DORA Compliance
Straight answers on scope, requirements, incident reporting, third parties, cost, and timeline.
What is DORA compliance?
DORA compliance means meeting the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554. Financial entities must manage ICT risk, report major ICT incidents, test their digital resilience, and control risk from their ICT third-party providers.
When did DORA come into effect?
DORA has applied since 17 January 2025. Supervisors now expect financial entities to show it working, including an annual register of information on ICT third-party arrangements.
Who does DORA apply to?
DORA applies directly to around 20 types of EU financial entities, including banks, insurers, investment firms, payment and e-money institutions, and crypto-asset service providers. It also affects their ICT third-party providers through required contract terms, and critical ICT providers through direct EU oversight.
Is DORA only relevant for EU banks?
No. It covers many types of financial entity. It is also highly relevant for ICT providers, including US SaaS, cloud, and managed service companies, that support regulated financial entities in the EU.
What are the five pillars of DORA?
ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing on cyber threats.
Is there a DORA certification?
No. There is no official DORA certification. Compliance is shown through evidence, supervisory review, and the contracts financial entities sign with their ICT providers. Accredify Global assesses readiness and helps you build that evidence.
What are the DORA incident reporting deadlines?
For a major ICT incident, the initial notification is due within 4 hours of classifying it as major. It must be no later than 24 hours after becoming aware. An intermediate report follows within 72 hours, and a final report within one month of the latest intermediate report.
What is the DORA register of information?
It is a register of all ICT third-party arrangements that a financial entity maintains and reports to its supervisor each year. It shows which providers support critical or important functions.
What are critical ICT third-party providers under DORA?
They are ICT providers designated by the European Supervisory Authorities for direct EU oversight. The first 19 were designated on 18 November 2025, including major cloud platforms. Financial entities still manage their own risk from these providers.
Does DORA compliance include third-party risk?
Yes. ICT third-party risk is one of DORA's five pillars. It covers the register of information, required contract terms, risk assessment, monitoring, concentration risk, and exit strategies.
What is threat-led penetration testing (TLPT) under DORA?
TLPT is advanced, intelligence-led testing of live production systems that significant financial entities must perform at least every three years. It uses specialist testers, and Accredify Global coordinates specialists where it applies.
What is the difference between DORA and NIS2?
Both are EU laws on digital resilience. NIS2 covers essential and important entities across many sectors, while DORA is the sector-specific rule for financial entities. Where they overlap, DORA applies to financial entities.
Can DORA work connect to existing security programs?
Yes. DORA overlaps with ISO 27001, ISO 22301, SOC 2, incident response, continuity planning, and vendor risk programs. We map existing evidence to DORA before planning new work.
How much does DORA compliance cost?
The cost depends on your role under DORA and the number of critical functions and ICT providers. Group structure, countries, and control maturity also matter. Accredify Global reviews your scope for free and sends a tailored proposal.
How long does a DORA readiness assessment take?
Most Accredify Global DORA readiness assessments and roadmaps take 6 to 12 weeks, depending on scope. Closing the gaps then follows your roadmap.
Find Out Where You Stand on DORA, Before Your Supervisor or Customer Asks
Tell us about your role, critical functions, and ICT providers. We'll confirm how DORA applies, recommend a timeline, and send a tailored proposal.
Book your free scoping review →Last reviewed by the Accredify Global compliance team.