Ready for a DORA Readiness Assessment?
Understand where your organization stands against DORA's five pillars as EU regulators move into active supervisory enforcement.
DORA has applied identically across all EU member states for financial entities since January 17, 2025, and is now entering its first real supervisory enforcement cycle. Cyberox helps financial entities and their critical ICT third-party providers close remaining gaps.
Last reviewed: September 2026. Verify current requirements against the official regulator before acting — sources linked below.
DORA applies to a broad range of financial entities — banks, insurance and reinsurance companies, investment firms, payment and e-money institutions, crypto-asset service providers — and to their critical ICT third-party service providers, including cloud and technology vendors.
DORA requires a comprehensive ICT risk-management framework covering governance, identification of ICT risk, protection and prevention, detection, response and recovery, and continuous learning and improvement.
Financial entities must classify and report major ICT-related incidents to regulators within defined timeframes, with harmonized reporting formats across the EU.
DORA requires regular testing of ICT systems, with more sophisticated entities required to undergo threat-led penetration testing (TLPT) on a recurring basis.
DORA introduces a formal Register of Information for ICT third-party providers and, for the most critical providers, a direct EU oversight regime — reflecting how central cloud and technology vendors have become to financial-sector operations.
Regulators are now moving into active supervisory enforcement of DORA, with reported gaps between claimed and actual readiness across the industry. Confirm your specific obligations and current enforcement posture with your national competent authority or legal counsel.
With regulators now actively supervising DORA compliance, we help financial entities and their ICT vendors close the gap between paper policies and demonstrable operational resilience.
The EU's broader cybersecurity directive — relevant if you also fall under NIS2's essential/important sector scope.
Learn moreTechnical testing services that can be scoped toward DORA's resilience-testing requirements, including TLPT preparation.
Learn moreVendor and supplier risk assessment methodology applicable to DORA's ICT third-party risk pillar.
Learn moreUnderstand where your organization stands against DORA's five pillars as EU regulators move into active supervisory enforcement.