Regulation (EU) 2022/2554 has applied since 17 January 2025, binding financial entities and their critical ICT providers to five pillars of digital operational resilience. We implement all five with precision, from ICT risk frameworks to threat led testing readiness.
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, is the EU's regime for the financial sector's resilience to ICT disruption. Applying since 17 January 2025, it binds banks, insurers, investment firms, payment institutions and a wide range of other financial entities, together with their critical ICT third party providers, to five pillars: ICT risk management, incident reporting, digital operational resilience testing, third party risk management and information sharing.
Unlike a directive, DORA applies directly, and it is built to be tested: supervisors expect a documented ICT risk framework owned by the management body, major incidents classified and reported on defined timelines, a proportionate testing programme rising to threat led penetration testing at least every three years for designated entities, and contractual and concentration control over critical ICT providers.
We help financial institutions and ICT providers meet those expectations with precision: assessing where you stand against each pillar, implementing the frameworks and processes, rehearsing the response, and preparing you for the audits, reviews and inspections that now come with the territory, connected to the cyber resilience and continuity capability DORA ultimately measures.
DORA is the financial sector's lex specialis within a coordinated European architecture: NIS2 governs the other essential and important sectors, the CER Directive adds the physical and organisational dimension for critical entities, and Swiss groups carry the Information Security Act in parallel. The compliance calendar puts every regime's dates on one timeline, and our supply chain security practice covers the third party pillar in depth.
A wide range of financial entities operating in the EU, including banks, insurers, investment firms, payment and e money institutions, crypto asset service providers and more, plus the ICT third party providers serving them, with critical providers subject to direct EU level oversight.
TLPT is advanced testing in which realistic attack techniques are used against live production systems under controlled conditions, following the TIBER style approach. Designated entities must undergo it at least every three years; we prepare the scoping, governance and remediation around it.
DORA is lex specialis for the financial sector: where both could apply, DORA's requirements take precedence for financial entities, while NIS2 governs other critical sectors. Groups spanning both worlds need one capability mapped to two regimes; see our NIS2 service.
Yes, that is pillar four. You must maintain a register of ICT third party arrangements, embed mandatory contractual provisions, assess concentration risk, and hold monitoring and exit strategies for critical providers, who may themselves fall under direct oversight.
Whether the framework operates: incident classification on real events, evidence of tested continuity and recovery, testing findings remediated on schedule, and management body engagement. Our exercising and audit services build exactly that evidence.
From scope determination to Article 21 measures and 24 hour reporting readiness under Directive (EU) 2022/2555.
The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.
Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.
Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.
BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.
Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.
Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.
From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.
The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.
Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.
Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.
The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.
Ask us for a DORA gap assessment across the five pillars; the first question is whether you comply, the second is whether you can prove it.
Book a consultation