01
Beginner
No charge
DORA Fundamentals Certification
Master the fundamentals of DORA regulation. Perfect for professionals starting their compliance journey.
- Understand the 5 pillars of DORA
- Know key requirements and deadlines
- Identify impacts on your organization
- Navigate regulatory documentation
02
Expert
★ Most complete
Certified DORA Project Manager (CDPM)
The complete project-manager certification: run a DORA implementation end to end — scope, governance, all five pillars, evidence and closure.
- Scope a DORA programme: applicability, regime & critical functions
- Deliver all five pillars as evidenced, audit-ready deliverables
- Build the roadmap, critical path, budget & RAID controls
- Evidence, close and transition DORA to continuous compliance
03
Advanced
Certified DORA Advisor (CDA)
The client-facing credential for consultants, lawyers and auditors. Scope an engagement, build the client programme, evidence it — and prove your DORA competence with a verifiable certificate you show to clients.
- Scope a client engagement and classify the entity (Art. 2 / Art. 16)
- Build a prioritised, evidenced five-pillar programme
- Re-paper Article 30 contracts & build the Register of Information
- Assemble a supervisory-ready evidence file clients can rely on
04
Advanced
Certified DORA AI-Resilience Specialist
Cyber resilience for the AI era, aligned to DORA. Understand AI-orchestrated attacks (GTG-1002) and superhuman vulnerability discovery (Mythos), apply machine-speed defences, and evidence them against every DORA pillar.
- Understand AI-orchestrated attacks & superhuman vuln discovery
- Apply machine-speed detection, identity & deception controls
- Map the AI threat to all five DORA pillars
- Build an AI-threat-ready, supervisor-evidenced programme
05
Advanced
★ Most complete
DORA for Boards & Executives
The board-level DORA programme: the management body’s Article 5 duties and personal accountability, approving and challenging the ICT risk framework, reading incident, Register and TLPT reporting, and evidencing effective oversight to supervisors.
- Discharge the management body’s Article 5 duties & accountability
- Approve, resource and challenge the ICT risk-management framework
- Read the numbers: incidents, RTO/RPO, the Register, TLPT results
- Evidence effective board oversight for supervisors and the SREP
06
Advanced
★ Most complete
DORA for ICT Providers & Vendors
DORA from the supplier side: what your financial-sector clients must require of you under Articles 28–30, audit and sub-outsourcing obligations, the CTPP oversight regime, and a reusable DORA-readiness pack to win and keep contracts.
- Understand DORA flow-down and what clients require of providers
- Be ready to accept & negotiate the Article 30 clause set
- Handle audit rights, sub-outsourcing disclosure, exit & data return
- Navigate the CTPP oversight regime and answer client DDQs fast
07
Advanced
★ Most complete
DORA for IT & Security Teams
The complete DORA programme for the whole IT and security function: the ICT risk framework, resilience-by-design, detection and incident operations, TLPT, business continuity, and third-party technical oversight — with the evidence supervisors expect.
- Operate the ICT risk-management framework (Art. 5–16, RTS 2024/1774)
- Run detection, logging and the incident lifecycle to the 4h/72h/1-month cascade
- Scope and support TLPT (Art. 26–27) and ICT continuity, DR and backups
- Produce the technical evidence auditors and supervisors demand
08
Advanced
★ Most complete
DORA for Developers & DevOps
The build-and-ship DORA programme for the people who write and deploy the software: secure SDLC, controlled change & release, CI/CD and supply-chain security, testing in the pipeline, observability, and resilience-by-design architecture — with the evidence supervisors expect.
- Build a secure SDLC and controlled change process (Art. 9, RTS 2024/1774)
- Turn CI/CD into a control & evidence engine (SAST/SCA/DAST, SBOM, signing)
- Meet Art. 24–25 testing in the pipeline and build Art. 10 detection in
- Architect for failure, meet RTO/RPO (Art. 11–12) and build a tested exit
09
Advanced
★ Most complete
DORA for Legal & Contract Teams
The complete DORA programme for legal, contract and procurement teams: the enforcement and liability regime done correctly, Article 30 clauses, re-papering, the Register of Information, outsourcing and exit law, and supervisory engagement.
- Advise accurately on the penalties & liability regime (Art. 50 / Art. 35)
- Draft & negotiate every Article 30 clause and run a re-papering programme
- Own the Register of Information as a legal artefact (ITS 2024/2956)
- Master outsourcing, sub-outsourcing, exit law and supervisory engagement
10
Intermediate
Certified DORA Contract Manager (CDCM)
The dedicated certification for contract, procurement and vendor managers. Master Article 30 clauses, the Register of Information, re-papering and vendor negotiation under DORA.
- Draft & negotiate every Article 30 mandatory clause
- Build a DORA clause library & run a re-papering programme
- Own the Register of Information end to end
- Negotiate with hyperscalers & survive a supervisory audit
11
Intermediate
ICT Risk Management Professional
Deep dive into ICT risk management frameworks, business continuity, and operational resilience.
- Design comprehensive ICT risk frameworks
- Implement business continuity plans
- Conduct risk assessments and audits
- Manage operational resilience programs
12
Intermediate
Incident Reporting Specialist
Master incident classification, reporting workflows, and regulatory communication.
- Classify incidents according to DORA criteria
- Implement reporting workflows and timelines
- Communicate with competent authorities
- Manage incident documentation and tracking
13
Advanced
Third-Party Risk Management Expert
Comprehensive training on managing ICT third-party providers, contracts, and continuous monitoring.
- Build and maintain TPP registers
- Negotiate DORA-compliant contracts
- Implement continuous monitoring programs
- Manage sub-outsourcing and exit strategies
14
Advanced
TLPT Tester Certification
Become a certified TLPT tester. Learn threat-led penetration testing methodologies and best practices.
- Plan and scope TLPT engagements
- Execute threat-based attack scenarios
- Document findings and recommendations
- Conduct remediation validation
15
Advanced
Business Continuity, DRP & Test Exercises
Design, document and test ICT business continuity and disaster recovery under DORA — from business impact analysis to scenario exercises.
- Run a business impact analysis and set RTO/RPO
- Build a DORA-compliant ICT business continuity plan & DRP
- Design and run scenario, tabletop & full recovery tests
- Lead crisis management and post-exercise improvement
16
Advanced
DORA Programme Manager
Plan, run and close a DORA programme using ISO 27001 as your roadmap — full DORA↔ISO 27001 control mapping, the regulatory delta, priorities and quick wins.
- Use ISO 27001 as the DORA roadmap & map every control
- Pinpoint the DORA delta ISO does not cover (reporting, TLPT, Register, Art. 30)
- Prioritise with a risk/deadline matrix & bank early quick wins
- Run, evidence and close the programme to the deadline
17
Expert
DORA Implementation Director
Complete mastery program for leading organization-wide DORA implementation projects.
- Design enterprise-wide compliance programs
- Lead cross-functional implementation teams
- Manage budgets and resources
- Report to boards and regulators
18
Intermediate
DORA Compliance Officer
The dedicated certification for the role banks and insurers hire first: the obligations map, second-line monitoring, regulatory reporting and supervisory engagement.
- Build the DORA obligations map & monitor second-line
- Own incident reporting & the Register submission
- Engage supervisors & integrate with the SREP
- Run continuous, audit-ready compliance
19
Advanced
DORA × ISO 27001 Lead Implementer
Implement DORA on an ISO 27001 ISMS: extend the management system, map all 93 Annex A controls, build the regulatory delta, run one integrated control environment.
- Extend the ISMS (clauses 4–10) for DORA
- Map Annex A controls to every DORA obligation
- Build & govern the DORA delta inside the ISMS
- Run one audit cycle certifying ISO 27001 & DORA
20
Advanced
DORA Internal Auditor
Provide independent third-line assurance over DORA: plan the audit by risk, test each pillar, evidence findings and report to the audit committee.
- Build the DORA audit universe & risk-based plan
- Test each pillar for design & operating effectiveness
- Evidence findings, root cause & form an opinion
- Report and follow findings to verified closure
21
Intermediate
DORA Register of Information Specialist
Master DORA’s hardest artefact end to end: the data model, sourcing, critical-function tagging, subcontracting chains, quality and supervisory submission.
- Model the ITS templates & define an internal schema
- Source, tag criticality & capture subcontracting chains
- Validate, reconcile & submit to the supervisor
- Maintain the Register & power third-party oversight