All frameworks
    Regulatory auditEuropean Union; European Supervisory Authorities (EBA, ESMA, EIOPA) and national competent authorities

    DORA

    DORA: Digital Operational Resilience Act (Regulation (EU) 2022/2554)

    DORA is an EU regulation requiring financial entities to withstand and recover from ICT disruptions. It applies from January 2025.

    Last verified Jul 17, 2026

    Q&A

    What is DORA?

    DORA is an EU regulation requiring financial entities to withstand and recover from ICT disruptions. It applies from January 2025.

    Who needs DORA?

    EU financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more, plus the critical ICT third-party providers, including cloud and software vendors, that support them.

    How long does DORA take?

    DORA compliance is continuous. Resilience testing is performed on a regular basis, with advanced threat-led penetration testing required periodically for entities in scope for it.

    How much does a DORA audit cost?

    Costs depend on entity size and testing obligations. Threat-led penetration testing and third-party risk programs are significant line items for larger entities; smaller entities face proportionate requirements.

    What does a DORA audit cover?

    Assessment covers ICT risk management, incident reporting, resilience testing, and ICT third-party risk against DORA and its regulatory technical standards. Advanced testing may include threat-led penetration testing by qualified providers.

    What it is

    The Digital Operational Resilience Act sets uniform requirements for the security and resilience of the information and communication technology (ICT) that supports the EU financial sector. It has applied since 17 January 2025 and covers a broad range of financial entities as well as the critical ICT third-party providers that serve them.

    DORA is built on several pillars: ICT risk management, incident reporting, digital operational resilience testing, and management of ICT third-party risk. For the most significant entities, testing includes threat-led penetration testing (TLPT) carried out by qualified testers.

    Because it is a regulation with direct effect, DORA's requirements are consistent across member states, though supervision is shared between the European Supervisory Authorities and national competent authorities. The goal is demonstrable operational resilience, not a one-off certificate.

    Who needs it

    EU financial entities: banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, and more, plus the critical ICT third-party providers, including cloud and software vendors, that support them.

    What's audited

    Assessment covers ICT risk management, incident reporting, resilience testing, and ICT third-party risk against DORA and its regulatory technical standards. Advanced testing may include threat-led penetration testing by qualified providers.

    Typical timeline

    DORA compliance is continuous. Resilience testing is performed on a regular basis, with advanced threat-led penetration testing required periodically for entities in scope for it.

    Typical cost

    Costs depend on entity size and testing obligations. Threat-led penetration testing and third-party risk programs are significant line items for larger entities; smaller entities face proportionate requirements.

    What to verify on an auditor

    Choose assessors with financial-sector ICT risk expertise and familiarity with DORA's regulatory technical standards. For threat-led penetration testing, testers must meet the qualification requirements set out under the TLPT framework.

    Service pathways

    Not every service under this framework is fully available today. Hover a pathway for context.

    • Formal DORA certification
      DORA has no certification scheme. Article 6(6) requires internal audit of the ICT risk management framework instead.
      Not yet operational
    • Internal audit of ICT risk framework (Art. 6(6))
      Available
    • Register of Information (RoI) preparation and submission
      Available
    • Threat-Led Penetration Testing (TIBER-EU)
      TLPT must be performed by testers qualified under the TIBER-EU framework specifically, a narrow and specialized pool distinct from general penetration testers.
      Available