DORA Certification
Prove your Digital Operational Resilience Act expertise with a verifiable, role-specific credential: a free foundation course plus 20 expert programmes for EU financial professionals, or go all-access with the DORA Masterclass.
Prove your Digital Operational Resilience Act expertise with a verifiable, role-specific credential: a free foundation course plus 20 expert programmes for EU financial professionals, or go all-access with the DORA Masterclass.
A practical, regulation-anchored credential, not a generic completion badge.
Every lesson cites the relevant DORA articles and RTS/ITS technical standards, so what you learn maps directly to what auditors check.
Each programme ends in a timed exam. Pass the mark and you earn a certificate with your score: a real proof of competence.
A unique certificate ID and QR code link to a public verification page, so any employer can confirm it in seconds.
Add the credential to your LinkedIn profile in one click, or share it to your feed with a designed badge.
Want to see the ground the programmes cover before you enrol? Our DORA compliance checklist sets out every obligation by pillar, with the article that imposes it and the document that closes it.
DORA does not land on one desk: it lands on twelve. Find your role, see what the regulation now expects of it, and open the certification built for it.
Article 5 puts final accountability for ICT risk on the management body. Oversight has to be real, informed and evidenced.
The role firms staff first for DORA: the obligations map, second-line monitoring and every supervisory submission.
Someone has to run the whole programme: scope, five pillars, budget and evidence, delivered on the regulator's clock.
Every ICT contract must carry the Article 30 clause set, and the Register of Information has to prove it line by line.
A major incident starts the 4-hour, 72-hour and one-month reporting cascade. Classification is your call, under pressure.
Pillar 5 puts the whole supplier lifecycle under supervision, from due diligence and monitoring to a documented exit.
Articles 26 and 27 mandate threat-led penetration testing on live production systems at least every three years.
The ICT risk framework, detection, continuity and the technical evidence supervisors ask for all land on the IT function.
Secure SDLC, controlled change and CI/CD evidence are regulatory obligations under DORA, not just engineering good practice.
Re-papering, the liability regime, outsourcing and exit law, and supervisory engagement all run through the legal team.
A client-facing credential that proves your DORA competence before the engagement starts, verifiable by any client.
Financial clients must flow DORA down into your contracts. Readiness now decides who wins and keeps the deals.
21 self-paced programmes (one free, the rest expert credentials from €0 to €249) or take the Masterclass and get them all.
Prices exclude VAT. VAT is calculated at checkout based on your location. EU businesses: enter your VAT number for reverse charge.
One purchase, everything: all 21 certifications with every exam and verifiable certificate, lifetime access, plus the Govern & Implement starter pack to actually run DORA in your firm as its certified expert.
Master the fundamentals of DORA regulation. Perfect for professionals starting their compliance journey.
“Clear and on point, without unnecessary lengthy explanations. Relevant for my work. I can recommend.”
The complete project-manager certification: run a DORA implementation end to end, scope, governance, all five pillars, evidence and closure.
The client-facing credential for consultants, lawyers and auditors. Scope an engagement, build the client programme, evidence it, and prove your DORA competence with a verifiable certificate you show to clients.
“This certification is to the point through providing the necessary background information together with practical examples and…”
Cyber resilience for the AI era, aligned to DORA. Understand AI-orchestrated attacks (GTG-1002) and superhuman vulnerability discovery (Mythos), apply machine-speed defences, and evidence them against every DORA pillar.
The board-level DORA programme: the management body’s Article 5 duties and personal accountability, approving and challenging the ICT risk framework, reading incident, Register and TLPT reporting, and evidencing effective oversight to supervisors.
DORA from the supplier side: what your financial-sector clients must require of you under Articles 28–30, audit and sub-outsourcing obligations, the CTPP oversight regime, and a reusable DORA-readiness pack to win and keep contracts.
The complete DORA programme for the whole IT and security function: the ICT risk framework, resilience-by-design, detection and incident operations, TLPT, business continuity, and third-party technical oversight, with the evidence supervisors expect.
The build-and-ship DORA programme for the people who write and deploy the software: secure SDLC, controlled change & release, CI/CD and supply-chain security, testing in the pipeline, observability, and resilience-by-design architecture, with the evidence supervisors expect.
The complete DORA programme for legal, contract and procurement teams: the enforcement and liability regime done correctly, Article 30 clauses, re-papering, the Register of Information, outsourcing and exit law, and supervisory engagement.
The dedicated certification for contract, procurement and vendor managers. Master Article 30 clauses, the Register of Information, re-papering and vendor negotiation under DORA.
Deep dive into ICT risk management frameworks, business continuity, and operational resilience.
Master incident classification, reporting workflows, and regulatory communication.
Comprehensive training on managing ICT third-party providers, contracts, and continuous monitoring.
Become a certified TLPT tester. Learn threat-led penetration testing methodologies and best practices.
Design, document and test ICT business continuity and disaster recovery under DORA, from business impact analysis to scenario exercises.
Plan, run and close a DORA programme using ISO 27001 as your roadmap: full DORA↔ISO 27001 control mapping, the regulatory delta, priorities and quick wins.
Complete mastery program for leading organization-wide DORA implementation projects.
The dedicated certification for the role banks and insurers hire first: the obligations map, second-line monitoring, regulatory reporting and supervisory engagement.
Implement DORA on an ISO 27001 ISMS: extend the management system, map all 93 Annex A controls, build the regulatory delta, run one integrated control environment.
Provide independent third-line assurance over DORA: plan the audit by risk, test each pillar, evidence findings and report to the audit committee.
Master DORA’s hardest artefact end to end: the data model, sourcing, critical-function tagging, subcontracting chains, quality and supervisory submission.
Written by learners who passed the certification exam, published unedited after review.
“Clear and on point, without unnecessary lengthy explanations. Relevant for my work. I can recommend.”
“This certification is to the point through providing the necessary background information together with practical examples and useful tips.”
Reviews are from verified certified learners only. We offer 15% off a future purchase for leaving one after a certification, regardless of the rating given; reviews are published unedited.
Already run an ISO 27001 ISMS? It is the natural roadmap to DORA, and our Programme Manager certification maps the two in full.
A risk methodology, asset inventory, Statement of Applicability, incident, access, supplier and continuity controls, plus the audit & management-review machinery, much of DORA Pillar 1 and parts of Pillars 2–4 map straight onto your ISMS.
Regulatory incident reporting (4h / 72h / 1 month), Threat-Led Penetration Testing, the Register of Information, Article 30 contractual provisions and CTPP oversight: the parts ISO 27001 does not cover.
The DORA Programme Manager certification teaches exactly this bridge: a full DORA↔ISO 27001 control mapping, the regulatory delta, and the priorities and quick wins to deliver it on time.
One purchase that equips you to run DORA end to end in a financial firm: learn every domain through the certifications, then do the work with the included toolkits, assess your gaps, draft the policies, build the Register of Information, prepare incident reporting and TLPT, and brief the board, as the firm’s certified DORA expert.
Every programme in the Academy unlocks instantly: all lessons, every certification exam and every verifiable certificate, lifetime access. Sit them in any order, including the Certified DORA Advisor (CDA) credential, not sold in any other bundle. Pass them all and claim the capstone: DORA Masterclass Certified, one verifiable credential attesting the complete set.
8 professional deliverables: the Complete Implementation Guide, 5-Pillar Toolkit, RTS/ITS Obligations Matrix, Policy Pack, Board Pack, Register of Information Pack, Gap Analysis Workbook and the executive playbooks.
Define your objectives (role, goal, timeline) and get your step-by-step route through the certifications and toolkits, generated instantly and recalculated every time you pass an exam. Lead the whole DORA programme in your firm as its certified expert.
One payment · lifetime access · everything delivered to your inbox instantly · Prefer to earn it? Play the Mastery Path →
Bundle the certifications for a career path: one payment, lifetime access to every course in the track.
The second- and third-line career path: own compliance, audit it, and master the Register.
For ISMS-led teams: implement DORA on ISO 27001 and run the programme end to end.
The complete path for the technology function: the team programme plus every technical deep-dive.
The complete path for the delivery function: the build-and-ship programme plus every technical deep-dive for secure, resilient shipping.
The complete path for legal, contract and procurement: the team programme plus every contract deep-dive.
The governance path: board oversight duties, delivery leadership and second-line compliance in one place.
The supplier path: be DORA-ready for your financial clients. Article 30, third-party risk and an ISO 27001 base.
For banks & credit institutions: second-line compliance, ICT risk, continuity and third-party oversight for the whole team.
For insurers & intermediaries: compliance, ICT risk, incident reporting and third-party oversight, tuned to the insurance operating model.
For payment & e-money institutions: compliance, incident reporting, third-party oversight and continuity for high-availability rails.
For crypto-asset service providers: compliance, ICT risk, threat-led testing and incident reporting for a security-first sector.
For MiFID investment firms: compliance, ICT risk, third-party oversight and the Register of Information for delegation-heavy models.
The 13 core individual DORA certifications in one purchase, over 60% off buying them separately. (Team, board & role-specific courses are sold separately.)
Every graduate gets a unique-ID certificate, a public QR verification link, and a LinkedIn badge.
DORA-2026-XXXXXXXX)Anyone (an employer, a recruiter, an auditor) can confirm a certificate in seconds.
Nine self-paced certification programmes (one free). Each ends in a verifiable certificate with a unique ID, QR check and LinkedIn badge. Lifetime access.
Begin with the free foundation course, then add the expert credentials your role needs.
Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.
Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.