REGULATION · DORA
DORA resilience you can evidence to your supervisor.
Since January 2025, DORA applies to virtually the entire EU financial sector. Mindlapse operationalizes its five pillars on one platform, with every measure verified continuously, the way ESAs expect it to operate.
WHAT IS DORA?
The EU’s digital operational resilience act for finance.
DORA (Regulation (EU) 2022/2554) is the Digital Operational Resilience Act: a directly applicable EU regulation that harmonizes how financial entities manage ICT risk. It applies since 17 January 2025 to banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, market infrastructures and more, plus, through oversight, their critical ICT third-party providers.
Unlike a directive, DORA needs no national transposition: its requirements, and the technical standards (RTS/ITS) that detail them, apply as written, supervised by national authorities and the European Supervisory Authorities (EBA, EIOPA, ESMA).
DORA stands on five pillars: ICT risk management, ICT incident management and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing. Each demands not just policies, but demonstrable, tested, documented operation.
THE FIVE PILLARS
What DORA actually asks of you.
ICT risk management (Ch. II)
A complete framework (strategy, protection, detection, response, recovery, learning) owned by the management body, documented and reviewed.
Incident management & reporting (Ch. III)
Classify ICT incidents against ESA criteria and report major incidents to your authority on harmonized timelines and templates.
Resilience testing (Ch. IV)
A proportionate testing program: from vulnerability assessments to threat-led penetration testing (TLPT) every three years for significant entities.
ICT third-party risk (Ch. V)
A register of information on all ICT contracts, risk assessment before contracting, mandatory contractual clauses, exit strategies and concentration analysis.
Governance & proof
The management body bears final responsibility. Supervisors ask for the register, test results, incident logs and evidence that the framework operates.
HOW MINDLAPSE HELPS
Five pillars, one verified platform.
DORA requirements are pre-mapped to controls; the register of information and vendor risk live in TPRM; the Cockpit keeps the management body genuinely informed.
ICT risk-management framework
Smart Compliance maps DORA (and its RTS) to your control set and monitors each control continuously with sourced, dated verdicts.
Incident classification & reporting readiness
Risk Intelligence maintains scenarios, criticality and escalation owners so classification and harmonized reporting start from current, verified context.
Register of information (third parties)
TPRM holds your ICT third-party register as living data (contracts, criticality, dependencies) exportable in supervisory formats.
Third-party risk assessment & monitoring
Context-aware questionnaires with AI-drafted answers, automated scoring and contradiction detection, plus continuous reassessment when attestations expire or scope changes.
Management-body accountability
The Cyber Cockpit turns verified posture into board-grade views: resilience state, concentration risks, open decisions, defensible in front of a supervisor.
DORA - FAQ
Frequently asked, directly answered.
Who does DORA apply to?
Over twenty categories of financial entities: credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, insurers and intermediaries, market infrastructures, fund managers, ratings agencies and more, and, via the ESAs’ oversight regime, critical ICT third-party providers serving them.
Since when does DORA apply?
DORA entered into force on 16 January 2023 and applies in full since 17 January 2025. As a regulation it is directly applicable in every member state, without national transposition.
What is the register of information?
A structured register of all contractual arrangements with ICT third-party providers (services, criticality, dependencies, locations) that entities must maintain and report to supervisors. In Mindlapse it is living data maintained by TPRM, not an annual spreadsheet exercise.
How do DORA and NIS2 interact?
DORA is lex specialis for financial entities: where both could apply, DORA’s ICT risk and reporting requirements take precedence, while NIS2 governs sectors outside finance. Mindlapse maps both to one control set, so shared measures are implemented once and evidenced for each regime.
Does Mindlapse run our TLPT tests?
No. Testing is performed by qualified testers. Mindlapse manages the program around it: scoping from your value chain, findings as risks and controls, remediation tracking and the evidence trail supervisors expect.
DORA, OPERATIONALIZED
Your resilience posture, supervisor-ready.
Bring your register of information. We’ll show what living, verified third-party data looks like.