About this Framework
The Digital Operational Resilience Act (DORA — EU 2022/2554) became mandatory for EU financial entities and critical ICT third-party providers from 17 January 2025. DORA requires ICT risk management frameworks, classification and reporting of major incidents within 4 hours, digital resilience testing including threat-led penetration testing (TLPT), and comprehensive ICT third-party risk registers with mandated contractual requirements.
Key Control Domains
ICT Risk Management Framework
ICT-Related Incident Classification & Reporting
Digital Operational Resilience Testing (TLPT)
ICT Third-Party Risk Management
Information Sharing Arrangements
Who Needs This?
- Banks and credit institutions in the EU
- Insurance and reinsurance companies
- Investment firms and asset managers
- Payment and e-money institutions
- Critical ICT third-party providers (cloud, data centres, software)
Compliance Benefits
- Regulatory compliance with EU financial sector law
- Stronger operational resilience against ICT disruptions
- Clear ICT vendor accountability and contractual requirements
- Reduced systemic risk across EU financial markets
Official Reference
EBA DORA Guidance
https://www.eba.europa.eu/regulation-and-policy/operational-resilience
Assessment Details
Share this Assessment
Share this permanent link with your team, clients or auditors.
https://grcopilot.app/frameworks/dora-digital-operational-resilience-act-assessment-framework