DORA
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) requires financial institutions to demonstrate digital resilience: ICT risk management, incident reporting, resilience testing and control of ICT third parties.
About this standard
DORA in brief
DORA applies directly to banks, insurers, pension funds, investment firms and their critical ICT service providers. The regulation sets requirements for governance, ICT risk management, reporting of major incidents, periodic resilience testing and contractual control of outsourcing.
The library contains the NOREA DORA in Control framework with 95 controls, linked to the shared control set. That shows where DORA overlaps with ISO 27001 or BIO, and what is genuinely new.
In the library
Verified counts
95 controls
DORA in Control Framework v3.2 (version 3.2).
64 articles
Verordening (EU) 2022/2554 - Digital Operational Resilience Act.
228 links
To 66 shared controls, the bridge to other frameworks.
41 frameworks
This standard does not stand alone: the library counts 1,807 controls and 2,224 cross-references.
Structure
Domains in NOREA DORA in Control 3.2
- Third- party risk management (6)
- Risk management framework (6)
- Response & recovery (6)
- Architectural and network security (6)
- Third- party (standard) contract management (5)
- Management responsibilities (5)
- Data and (legacy) system security (5)
- ICT operations (4)
- Change management (4)
- Acquisition, development, and maintenance (4)
Related standards
ISO 27001 · NIS2 and the Dutch Cybersecurity Act · GDPR · BIO and BIO2 · NEN 7510 · ISO 42001 · Wpg (Dutch Police Data Act) · All standards
Get started with DORA
Request a demo or see how CRAFT supports this standard.
Frequently asked questions
Who does DORA apply to?
DORA applies directly to virtually the entire EU financial sector: banks, insurers, pension funds, investment firms, payment institutions and crypto service providers, plus the critical ICT service providers of those institutions.
What are DORA's five pillars?
ICT risk management, ICT incident handling and reporting, digital resilience testing, management of ICT third parties, and information sharing. Supervisors test on all five; the burden of proof lies with the institution.
How does the NOREA DORA framework cover the regulation?
The NOREA DORA in Control framework translates the regulation into 95 testable controls. In the Audirium library these are linked to the shared control set, making the overlap with ISO 27001 and BIO visible.