Compliance

DORA Readiness.

The Digital Operational Resilience Act has applied since 17 January 2025 — to financial entities and to their ICT service providers. We clarify applicability, close gaps, and make implementation demonstrable.

DORA does not only hit banks and insurers. If you supply financial entities as an IT service provider, software vendor, or data centre operator, you are indirectly in scope as an ICT third-party provider — at the latest when the first client fills its information register and renegotiates contract clauses. The approach is the same as NIS-2: clarify applicability, measure the gaps, close them in priority order.

What this includes

  • Applicability analysis — as a financial entity or as an ICT third-party provider in the supply chain
  • Gap analysis against DORA's ICT risk management requirements
  • Incident reporting: classification, reporting chains, and deadlines for major ICT incidents
  • Digital operational resilience testing programme — including an assessment of whether threat-led penetration testing (TLPT) applies to you
  • ICT third-party risk management: information register, contractual requirements, exit strategies
  • Implementation support through to demonstrable conformity

How we run it

01

Applicability

Clarify your role: financial entity, ICT third-party provider, or both.

02

Gap analysis

Current state against DORA — risk management, reporting, testing, third parties.

03

Roadmap

Prioritised measures with effort classes, decidable at executive level.

04

Implementation

Build processes, registers, and evidence documentation — with your team.

What you get

  • Applicability assessment with reasoning — defensible towards clients and supervisors
  • Gap overview per requirement area with traffic-light rating
  • Prioritised remediation roadmap with effort classes
  • Templates for the reporting process and the information register
  • Results presentation to management

Why this matters

DORA has applied since 17 January 2025 — there is no transition period left. Financial entities must bind their ICT providers contractually and list them in the information register. Providers without solid answers lose not through fines, but through lost contracts.

Questions we get

We are not a bank — does DORA still affect us?

Very likely yes, if you deliver ICT services to financial entities: software, hosting, cloud, managed services, data centres. As an ICT third-party provider, the requirements reach you through your clients' contracts — the applicability analysis settles this quickly.

How does DORA relate to NIS-2?

For the financial sector, DORA is the more specific regulation and takes precedence over NIS-2 there. Many requirements overlap — risk management, incident reporting, supply chain — so implementations can credit each other. If both apply to you, we build one shared evidence structure instead of two parallel ones. See also our NIS-2 services.

Do we have to run a TLPT?

Threat-led penetration testing (TLPT) is mandatory only for financial entities designated by their supervisor. Everyone else runs a risk-based testing programme — we assess what your category actually requires and size the testing accordingly.

What does DORA readiness cost?

Fixed price after free scoping — analogous to our NIS-2 readiness check. Consulting services are also frequently eligible for public funding in Germany (BAFA and state programmes, subsidies up to 50–80%) — we handle the funding navigation.

Next step.

A 30-minute call clarifies your exposure — as a financial entity or as an ICT provider.

Request a briefing