Standards & legislation

DORA

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) requires financial institutions to demonstrate digital resilience: ICT risk management, incident reporting, resilience testing and control of ICT third parties.

DORA in brief

DORA applies directly to banks, insurers, pension funds, investment firms and their critical ICT service providers. The regulation sets requirements for governance, ICT risk management, reporting of major incidents, periodic resilience testing and contractual control of outsourcing.

The library contains the NOREA DORA in Control framework with 95 controls, linked to the shared control set. That shows where DORA overlaps with ISO 27001 or BIO, and what is genuinely new.

Verified counts

Framework

95 controls

DORA in Control Framework v3.2 (version 3.2).

Legislation

64 articles

Verordening (EU) 2022/2554 - Digital Operational Resilience Act.

Cross-references

228 links

To 66 shared controls, the bridge to other frameworks.

Library

41 frameworks

This standard does not stand alone: the library counts 1,807 controls and 2,224 cross-references.

Domains in NOREA DORA in Control 3.2

  • Third- party risk management (6)
  • Risk management framework (6)
  • Response & recovery (6)
  • Architectural and network security (6)
  • Third- party (standard) contract management (5)
  • Management responsibilities (5)
  • Data and (legacy) system security (5)
  • ICT operations (4)
  • Change management (4)
  • Acquisition, development, and maintenance (4)

Get started with DORA

Request a demo or see how CRAFT supports this standard.

Frequently asked questions

Who does DORA apply to?

DORA applies directly to virtually the entire EU financial sector: banks, insurers, pension funds, investment firms, payment institutions and crypto service providers, plus the critical ICT service providers of those institutions.

What are DORA's five pillars?

ICT risk management, ICT incident handling and reporting, digital resilience testing, management of ICT third parties, and information sharing. Supervisors test on all five; the burden of proof lies with the institution.

How does the NOREA DORA framework cover the regulation?

The NOREA DORA in Control framework translates the regulation into 95 testable controls. In the Audirium library these are linked to the shared control set, making the overlap with ISO 27001 and BIO visible.