EU-regulated financial entities including banks, insurers, investment firms, payment institutions, and crypto-asset service providers, plus their critical ICT third-party providers who are brought into scope through contractual and oversight requirements.
A documented ICT risk management framework, major-incident classification and reporting to regulators on defined timelines, regular digital operational resilience testing (including threat-led penetration testing for significant entities), and a register of information on all ICT third-party arrangements.
Incident reporting timelines are tight and specific (initial notification, intermediate report, and final report each on defined windows), which means detection and escalation processes have to be fast enough to meet a regulatory clock, not just an internal SLA.
ICT risk management framework gap assessment, third-party ICT provider register build-out, incident classification and reporting process design, and resilience testing program scoping including threat-led penetration testing where applicable.
Gap analysis against the ICT risk management framework and third-party register requirements.
Implement incident classification/reporting processes and resilience testing program.
Execute resilience testing, including threat-led penetration testing for significant entities.
ICT risk management framework documentation, the register of information on ICT third-party providers, incident classification and reporting records, and resilience testing results including any threat-led penetration testing reports.
Treating DORA as purely an IT-department concern when it explicitly requires management-body accountability; under-documenting the ICT third-party register, which regulators specifically examine given DORA's focus on concentration risk from critical vendors.
See where your ICT risk management framework stands against DORA's requirements.
Request a Gap Assessment →