Knowing that the Digital Operational Resilience Act (DORA) makes training compulsory is the easy half. Article 13(6) requires ICT security awareness programmes and digital operational resilience training as compulsory modules for all employees and senior management, and Article 5(4) adds regular, specific training for the members of the management body; our guide to DORA training requirements sets out both. This guide is the other half: how to get a whole team trained, certified and on record within a quarter, without the rollout stalling in week three.
Before day one: three decisions
- An owner. One named person runs the rollout: assigns the training, follows completion and keeps the record. Usually the compliance or ICT risk function. A rollout owned jointly by two departments is owned by nobody.
- A budget line. Article 5(2)(g) has the management body allocate and periodically review the budget for these programmes, by name. Put the line in the budget before you enrol anyone, not after the first invoice.
- A definition of done. Decide now what counts as trained: attended, completed, or passed an exam. The stricter the definition, the better the evidence. A certificate with a score, a date and an identifier anyone can check is the strictest form, and the easiest to show.
Days 1 to 15: map every role to a programme
Article 13(6) asks for a level of complexity commensurate to the remit of each function. Turn that into a table before anyone is enrolled: every role, its starting programme, and the article that puts it in scope. Write it by role, not by name, so the map survives the day someone leaves.
| Role | Starting programme | Legal anchor |
|---|---|---|
| Everyone, as the baseline | DORA Fundamentals Certification (free) | Art. 13(6) |
| IT, infrastructure and security | DORA for IT & Security Teams | Art. 13(6) |
| Software engineering, DevOps, platform | DORA for Developers & DevOps | Art. 13(6) |
| Legal, contracts, procurement | DORA for Legal & Contract Teams | Art. 13(6), Art. 30 |
| Compliance and risk | DORA Compliance Officer Certification | Art. 13(6) |
| Internal audit | DORA Internal Auditor Certification | Art. 13(6) |
| Management body | DORA for Boards & Executives | Art. 5(4) |
| Staff of ICT providers, where appropriate | DORA for ICT Providers & Vendors | Art. 13(6), Art. 30(2)(i) |
Two points while you build it. If generic ICT security awareness (phishing, passwords, how to report an incident) already runs through a security awareness provider, keep it: the DORA programmes cover the resilience side, role by role. And treat the table as a starting point: a team weak on supplier documentation will want more of its people through third-party risk and the Register of Information. The team manager handbook carries a longer version of this map, with a second programme for each role.
Days 15 to 30: make it compulsory, then enrol everyone on one day
Write the modules into the staff training scheme as compulsory, with the cadence and the definition of done. That edit is what Article 13(6) actually asks for, and it is what turns a training initiative into evidence.
Then enrol everyone on the same day, with one short internal message: why the organisation is doing this, which programme is theirs, and by when. Four to six weeks for the first programme is realistic for people doing it alongside their job. Ask IT to allow the sender address first: access links that land in quarantine are the most common reason a rollout starts slowly.
Days 30 to 75: follow progress, not attendance
- Check in week three. Look at who has not started. A reminder in week three is a nudge; in week six it is a chase.
- Book the time. Teams that block two hours a week in their calendars finish; teams that rely on spare time do not.
- Give the management body its own track. Schedule it as a board agenda item rather than an e-learning reminder, and log it separately: date, topic, duration, attendee. Article 5(4) is a duty of each member.
- Bring providers in last, and only where the contract says so. Article 30(2)(i) makes the conditions of their participation a contractual provision. Where the clause exists, invite the provider staff who work on your services; where it does not, add it at the next renewal.
Days 75 to 90: file the evidence
A review asks for a list, not screenshots. At the end of the quarter, export one row per person and per programme and file it with the training policy:
- who, by role, and which programme;
- when they were enrolled and how far they got;
- the exam score, the result and the date;
- the certificate identifier, verifiable online;
- the management body log under Article 5(4), in the same file.
Report the completion rate to the management body with the gaps named. Then reassign any seat that was never used: a seat given to someone who will use it is worth more than one left idle.
After day 90: keep it current
DORA fixes no frequency for staff training, and asks for the management body’s training “on a regular basis” without defining it. The defensible answer is a cadence written into the policy, plus triggers: a new joiner, a change of role, a major ICT-related incident, a change to the ICT risk management framework. Check once a year who holds which role, and keep the refresh in next year’s budget. Certificates already issued stay valid when someone changes job; what lapses is the coverage of the role.
Five ways a rollout fails
- One module for everyone: too thin for the ICT teams, too technical for everybody else.
- Training without a record: the sessions happened, and nobody can show who attended.
- The management body trained once, at go-live, and never again.
- Providers forgotten until a contract renewal surfaces the Article 30(2)(i) clause.
- Certificates sitting in personal inboxes instead of the training file.
Running it with team licences
Every course, track and the Masterclass of the DORA Academy can be bought as a team licence, from two seats, with a price per seat that falls as the team grows. One manager adds people by email or by uploading the HR export, follows progress and exam results, reassigns a seat when someone leaves, and exports the training record described above. Each person sits their own exam and receives a certificate in their own name, with a public verification page. Payment is by card, or by bank transfer against your purchase order. Start with the free DORA Fundamentals certification as the baseline, and see every programme on the DORA certification page.
Frequently asked questions
How long does it take to train a team on DORA?
Plan a quarter for the first full cycle. Each role programme is a few hours of self-paced study, so the limit is rarely the content: it is calendar time and follow-up. Four to six weeks for the first programme, a second programme where the role needs depth, and the evidence file at the end of the quarter.
Do we have to train everyone at the same time?
No. Article 13(6) makes the modules compulsory in the staff training scheme; it does not make them simultaneous. Enrolling everyone on one day simply makes follow-up easier. What the record has to show is that everyone in scope completed them.
What evidence should we keep?
The training policy naming the modules as compulsory, the role map, one completion row per person and per programme with the score and the date, the management body log under Article 5(4), and the provider participation clause where it applies.
Should the staff of our ICT providers be trained too?
Where appropriate, yes. Article 13(6) provides for including ICT third-party service providers in the relevant training schemes, and Article 30(2)(i) makes the conditions of their participation part of the contract.
What happens when someone leaves mid-programme?
Reassign the seat to their successor. Certificates already issued stay valid and remain the person’s own; the role map tells you who now needs the training.