# DORA Regulation EU > Comprehensive DORA (Digital Operational Resilience Act) compliance platform for EU financial institutions. Operated by Cryptaguard, ISO 27001 certified DORA specialists. Covers all 13 RTS/ITS standards, 5 compliance pillars, interactive tools, and expert blog. EU Regulation 2022/2554 applicable since 17 January 2025. ## Core Reference Pages - [What is DORA? Complete Guide to EU Digital Resilience 2026](https://www.regulation-dora.eu/what-is-dora): Complete overview of EU Regulation 2022/2554, scope, 5 pillars, and compliance timeline - [DORA RTS PDF Download](https://www.regulation-dora.eu/rts): All 13 Regulatory and Implementing Technical Standards with implementation requirements - [DORA FAQ: Expert Answers on Compliance, Deadlines & Penalties](https://www.regulation-dora.eu/faq-dora): Expert Q&A covering scope, penalties, deadlines, and technical requirements - [DORA for Banks 2026: ECB Supervision, TLPT & ICT Roadmap](https://www.regulation-dora.eu/banking): Banking-sector specific compliance roadmap and checklist 2026 - [DORA for Insurance 2026: EIOPA Supervision & Solvency II Guide](https://www.regulation-dora.eu/insurance): Insurance-sector compliance guide - [DORA TLPT: Threat-Led Penetration Testing Requirements 2026](https://www.regulation-dora.eu/tlpt): Threat-Led Penetration Testing framework, TIBER-EU alignment, requirements - [DORA vs NIS2 2026: Interactive Comparison & Scope Decoder](https://www.regulation-dora.eu/dora-vs-nis2): Lex specialis relationship, dual-compliance guidance - [DORA Third-Party Risk: Register of Information & CTPP List](https://www.regulation-dora.eu/third-party-risk): ICT third-party risk management under DORA, Article 30 clauses, the 19 designated CTPPs - [DORA Register of Information: Templates, Format & Deadlines](https://www.regulation-dora.eu/register-of-information): DORA Article 28(3) register — 15 ITS 2024/2956 templates, xBRL-CSV format, Q1 2026 national deadlines, CTPP oversight link - [DORA CIF: Critical or Important Function Guide 2026](https://www.regulation-dora.eu/cif): Article 3(22) definition, identification criteria, T1/T2/T3 classification model - [Business Impact Analysis](https://www.regulation-dora.eu/business-impact-analysis): ISO/TS 22317:2021 method for deriving MTPD, RTO, RPO and MBCO, and the upstream input to the Article 3(22) determination and the Register of Information - [Iso 22301 Bcms Toolkit](https://www.regulation-dora.eu/iso-22301-bcms-toolkit): ISO 22301:2019 business continuity documentation for EU financial entities, every document dual-mapped to the DORA article it evidences, with a certification readiness instrument - [Crisis Management](https://www.regulation-dora.eu/crisis-management): Crisis activation criteria, pre-authorised decision rights, escalation and de-escalation, crisis communication and the Article 11(8) decision log; structured on ISO 22361:2022 and ISO 22320:2018, which are guidelines documents and are not certifiable - [Crisis Exercise](https://www.regulation-dora.eu/crisis-exercise): Exercise design, twelve scenarios, timed injects, evaluation and after-action review evidencing both limbs of DORA Article 11(6) — the yearly test of the continuity plans and of the crisis communication plans - [DORA Incident Reporting: 4h/72h/1M Timelines & Templates](https://www.regulation-dora.eu/dora-incident-reporting): Classification, 4h/72h/1-month timelines, RTS 2025/301 templates - [Free DORA Compliance Checklist 2026: 45-Point Self-Assessment](https://www.regulation-dora.eu/checklist): Step-by-step compliance checklist for financial institutions - [DORA Audit 2026: Requirements, Checklist & How to Prepare](https://www.regulation-dora.eu/dora-audit): What a DORA audit covers, who may perform it, and what supervisors check during an inspection - [DORA in France 2026: ACPR, AMF, OneGate & TIBER-FR](https://www.regulation-dora.eu/dora-france): Which authority supervises you in France (ACPR or AMF), which portal you file through (OneGate or GECO), the 31 March 2026 register deadline, and what TIBER-FR changes - [EU AI Act for Financial Institutions: What DORA Doesn't Cover](https://www.regulation-dora.eu/ai-act): What a DORA programme already covers and what the AI Act (Reg. 2024/1689) adds on top — cross-obligation table, provider vs deployer (Art. 25 trapdoor), post-Omnibus deadlines (Art. 50 transparency 2 Aug 2026; Annex III high-risk 2 Dec 2027) - [Ai Act Payment Institutions](https://www.regulation-dora.eu/ai-act-payment-institutions): Fraud detection is explicitly excluded from Annex III point 5(b); AML and SCA are not in Annex III; 1:1 KYC biometric verification is excluded from point 1. The one high-risk system for a payment institution is consumer credit scoring (BNPL) - [Ai Act Investment Firms](https://www.regulation-dora.eu/ai-act-investment-firms): Algorithmic trading and robo-advice are NOT in Annex III. They are governed by MiFID II Art. 17 and RTS 6 (Reg. 2017/589) plus the ESMA statement on AI of 30 May 2024. The AI Act reaches investment firms via HR screening, Art. 50 transparency, and retail credit - [Ai Act Crypto Casp](https://www.regulation-dora.eu/ai-act-crypto-casp): Blockchain analytics, AML monitoring, market surveillance, trading bots and 1:1 KYC verification are all outside Annex III. For a MiCA-authorised CASP the AI Act is Art. 50 transparency plus Art. 4 AI literacy, not a conformity programme ## Regulatory Reference Guides (Free Access) - [DORA Incident Reporting: Classification, Timelines & Templates](https://www.regulation-dora.eu/pdf/rts-incident-reporting.html): Classification criteria, timelines (4h initial / 72h report / 1 month final), decision trees - [DORA RTS](https://www.regulation-dora.eu/pdf/rts-incident-classification.html): Classification criteria for major ICT incidents - [DORA RTS](https://www.regulation-dora.eu/pdf/rts-ict-risk-management.html): RTS on ICT risk management framework requirements - [DORA RTS](https://www.regulation-dora.eu/pdf/rts-third-party-risk.html): Contractual requirements for ICT service providers - [DORA TLPT Requirements: Threat-Led Penetration Testing Guide 2026](https://www.regulation-dora.eu/pdf/rts-tlpt-guide.html): Threat-Led Penetration Testing, TIBER-EU alignment, reporting templates - [DORA RTS & ITS Explained: All 13 Technical Standards (2026)](https://www.regulation-dora.eu/pdf/dora-rts-its-complete-overview.html): All 13 RTS/ITS standards in one searchable reference ## Interactive Tools (Free) - [Get Your Free DORA Score](https://www.regulation-dora.eu/dora-dashboard): Get your institution's DORA compliance score - [DORA Compliance Tools by Pillar](https://www.regulation-dora.eu/tools/): 11 free DORA tools organized by pillar: gap analysis, incident classifier, TLPT checker, third-party risk scorer, cost calculator and more. No signup - [DORA Compliance Cost Calculator](https://www.regulation-dora.eu/tools/compliance-cost-calculator): Estimate DORA implementation costs by institution size - [Third-Party Risk Scorer](https://www.regulation-dora.eu/tools/third-party-risk-scorer): Assess ICT third-party provider risk level - [ICT Incident Analyzer](https://www.regulation-dora.eu/tools/ict-incident-analyzer): Classify and assess ICT incidents under DORA criteria - [TLPT Readiness Checker](https://www.regulation-dora.eu/tools/tlpt-readiness-checker): Assess readiness for threat-led penetration testing - [DORA Implementation Timeline Calculator](https://www.regulation-dora.eu/tools/compliance-timeline-calculator): Plan your DORA implementation timeline - [Resource Estimator](https://www.regulation-dora.eu/tools/resource-estimator): Estimate staffing and budget for DORA compliance - [DORA Gap Analysis Tool: Free Compliance Assessment 2026](https://www.regulation-dora.eu/tools/gap-analysis): Identify compliance gaps across all 5 DORA pillars - [Am I in DORA Scope?](https://www.regulation-dora.eu/tools/scope-determination): Free DORA scope checker. Answer 7 questions to see if DORA applies to your entity, which pillars apply, and your next steps. Indicative, no signup. EU financial entities - [Is Your Group Exposed to DORA? Free Non-EU Check 2026](https://www.regulation-dora.eu/tools/dora-exposure-check): Free DORA exposure check for non-EU groups and parent companies. Answer 5 questions to see if your group is exposed - via an EU entity, ICT services, or client contracts - and what to do - [EU AI Act Exposure Check for Financial Firms](https://www.regulation-dora.eu/tools/ai-act-exposure-check): Classify an AI system under the EU AI Act — prohibited (Art. 5), high-risk (Annex III), GPAI (Art. 51-55), transparency-only (Art. 50) or minimal — and determine provider vs deployer status - [DORA Toolkit Finder: Which DORA Kit Do You Need? Free 2-Min Quiz](https://www.regulation-dora.eu/tools/toolkit-finder): Answer 7 questions and get a personalised DORA toolkit recommendation: the right templates, tools, services or certification for your profile and budget. Free, no signup - [DORA Regulation Fines & Penalties: Free Calculator 2026](https://www.regulation-dora.eu/tools/penalty-calculator): Estimate DORA exposure by institution type and severity. DORA sets no EU-wide maximum fine for financial entities (Art. 50 defers to national law) — this is an indicative estimate, not a - [DORA Information Sharing Readiness Checker (Pillar 5, Art. 45)](https://www.regulation-dora.eu/tools/information-sharing-checker): Free DORA Pillar 5 self-assessment. 14 questions on Article 45 information-sharing: trusted communities, the CA notification duty, TLP, GDPR safeguards. Instant readiness score. No signup ## Premium Guides - [DORA Compliance Benchmark & Maturity Model 2026](https://www.regulation-dora.eu/guides/dora-benchmarking-2025): DORA compliance benchmark, maturity model, KPI dashboard for financial institutions - [DORA Gap Analysis Workbook, Method & Report Template](https://www.regulation-dora.eu/guides/gap-analysis-workbook): DORA gap analysis template, compliance assessment workbook, DORA readiness assessment - [DORA ICT Risk Management Framework Guide (Art. 5-16)](https://www.regulation-dora.eu/guides/ict-risk-playbook): DORA ICT risk management framework, Articles 5-16, control catalogue and policy library - [DORA Third-Party Risk: Art. 30 Clauses & Exit Plans](https://www.regulation-dora.eu/guides/third-party-playbook): DORA third-party risk management, Article 30 contractual clauses, ICT provider exit strategy - [DORA Incident Reporting: Deadlines & ITS Templates](https://www.regulation-dora.eu/guides/incident-response-framework): DORA major incident reporting, 4-hour notification, 72-hour intermediate report, ITS template - [DORA TLPT Guide: Threat-Led Testing under TIBER-EU](https://www.regulation-dora.eu/guides/tlpt-implementation-guide): DORA TLPT requirements, TIBER-EU alignment, threat-led penetration testing scope and phases - [DORA Implementation Library: All 5 Pillar Playbooks](https://www.regulation-dora.eu/guides/allinone-bundle): DORA implementation guide bundle, all five pillars, complete documentation set - [DORA Policy Templates: 10 Editable Word Documents](https://www.regulation-dora.eu/guides/policy-pack): DORA policy templates, ICT security policy Word document, DORA documentation set - [DORA Board Reporting Pack & Briefing Templates](https://www.regulation-dora.eu/guides/board-pack): DORA board reporting template, management body accountability Article 5, executive briefing - [DORA Register of Information: Templates & Data Model](https://www.regulation-dora.eu/guides/roi-pack): DORA Register of Information template, Article 28(3), ITS 2024/2956 submission - [DORA Article 45: Threat Information Sharing Guide](https://www.regulation-dora.eu/guides/info-sharing-playbook): DORA information sharing Article 45, threat intelligence sharing arrangements, TLP handling ## Free Downloads & Templates - [Free DORA ICT Third-Party Questionnaire (Excel)](https://www.regulation-dora.eu/lead-magnets/dora-supplier-questionnaire): The DORA questionnaire your EU financial clients will send you, as a free editable Excel — mapped to Articles 28-30. Fill it in before they ask and win the contract - [Free DORA Compliance Plan (18-24 Months)](https://www.regulation-dora.eu/lead-magnets/dora-compliance-plan): A free, editable 18-24 month DORA implementation roadmap in Excel: phased activities across the five pillars, with windows, deliverables, owners and status tracking - [Free DORA Compliance Checklist 2026](https://www.regulation-dora.eu/lead-magnets/dora-checklist-2026): Download the free DORA compliance checklist, updated for 2026. 75 verifiable controls across all 5 pillars, with evidence prompts, owners and priorities - [Free DORA Gap Analysis Starter: 50-Control Excel Workbook 2026](https://www.regulation-dora.eu/lead-magnets/gap-analysis-template): Free Excel workbook covering the 50 DORA controls supervisors ask about first. Capture evidence, record status, assign owners and deadlines. No card required - [Free DORA Compliance Roadmap Generator](https://www.regulation-dora.eu/lead-magnets/compliance-roadmap-generator): Generate your personalized DORA compliance roadmap in minutes. Answer 10 questions to get a customized implementation timeline with priorities, milestones, and resource estimates - [Free DORA Compliance Mini Audit](https://www.regulation-dora.eu/lead-magnets/mini-audit-gratuit): Take our free 10-question DORA compliance mini audit and get your score instantly. Assess your readiness across all 5 pillars and receive a detailed report ## Academy & Training - [DORA Mastery Path](https://www.regulation-dora.eu/academy/path): Every DORA certification you earn scores points. Rank up from Explorer to Master, unlock growing Masterclass rewards, and claim the DORA Master certificate - [DORA Academy](https://www.regulation-dora.eu/academy/): Free and paid certification programmes for compliance professionals, with verifiable certificates - [DORA Compliance & Assurance Track](https://www.regulation-dora.eu/academy/track/compliance-assurance-track): DORA Compliance & Assurance Track — The second- and third-line career path: own compliance, audit it, and master the Register - [DORA × ISO 27001 Track](https://www.regulation-dora.eu/academy/track/iso27001-dora-track): DORA × ISO 27001 Track — For ISMS-led teams: implement DORA on ISO 27001 and run the programme end to end - [DORA for IT & Security Teams Track](https://www.regulation-dora.eu/academy/track/it-security-team-track): DORA for IT & Security Teams Track — The complete path for the technology function: the team programme plus every technical deep-dive - [DORA for Developers & DevOps Track](https://www.regulation-dora.eu/academy/track/devops-platform-track): DORA for Developers & DevOps Track — The complete path for the delivery function: the build-and-ship programme plus every technical deep-dive for secure, resilient shipping - [DORA for Legal & Contract Teams Track](https://www.regulation-dora.eu/academy/track/legal-contract-team-track): DORA for Legal & Contract Teams Track — The complete path for legal, contract and procurement: the team programme plus every contract deep-dive - [DORA for Boards & Executives Track](https://www.regulation-dora.eu/academy/track/boards-exec-track): DORA for Boards & Executives Track — The governance path: board oversight duties, delivery leadership and second-line compliance in one place - [DORA for ICT Providers Track](https://www.regulation-dora.eu/academy/track/ict-provider-track): DORA for ICT Providers Track — The supplier path: be DORA-ready for your financial clients — Article 30, third-party risk and an ISO 27001 base - [DORA for Banking Teams](https://www.regulation-dora.eu/academy/track/banking-team-track): DORA for Banking Teams — For banks & credit institutions: second-line compliance, ICT risk, continuity and third-party oversight for the whole team - [DORA for Insurance Teams](https://www.regulation-dora.eu/academy/track/insurance-team-track): DORA for Insurance Teams — For insurers & intermediaries: compliance, ICT risk, incident reporting and third-party oversight, tuned to the insurance operating model - [DORA for Payments Teams](https://www.regulation-dora.eu/academy/track/payments-team-track): DORA for Payments Teams — For payment & e-money institutions: compliance, incident reporting, third-party oversight and continuity for high-availability rails - [DORA for Crypto & CASP Teams](https://www.regulation-dora.eu/academy/track/crypto-team-track): DORA for Crypto & CASP Teams — For crypto-asset service providers: compliance, ICT risk, threat-led testing and incident reporting for a security-first sector - [DORA for Investment Firm Teams](https://www.regulation-dora.eu/academy/track/investment-team-track): DORA for Investment Firm Teams — For MiFID investment firms: compliance, ICT risk, third-party oversight and the Register of Information for delegation-heavy models - [DORA Certifications Bundle](https://www.regulation-dora.eu/academy/track/all-access): DORA Certifications Bundle — The 13 core individual DORA certifications in one purchase — over 60% off buying them separately. (Team, board & role-specific courses are sold separately.) ## Premium Content - [Premium Content](https://www.regulation-dora.eu/premium-content/): Access exclusive DORA compliance content: live webinars, expert consultations, premium reports, and private workshops. Accelerate your compliance journey - [DORA Expert Webinars](https://www.regulation-dora.eu/premium-content/webinars/): Join expert-led DORA compliance webinars. Live interactive sessions, on-demand recordings, and certification programs. Free and premium options available - [DORA Premium Reports & Toolkits 2026](https://www.regulation-dora.eu/premium-content/reports): Eleven practitioner-built DORA compliance products: 5-pillar playbooks, Register of Information pack, board templates, benchmark report, consultant kit. Instant download from €49 - [DORA Expert Consultations](https://www.regulation-dora.eu/premium-content/consultations): One-to-one DORA advisory sessions with our founder and lead consultant: strategy, technical review, gap assessment, ongoing support for EU financial entities - [DORA Private Workshops](https://www.regulation-dora.eu/premium-content/workshops): Expert-led DORA compliance workshops for your team. Half-day awareness sessions to 3-day implementation programs. Custom training packages available - [Consultant Kit](https://www.regulation-dora.eu/premium-content/consultant-kit): Launch your DORA consulting practice in one purchase: a 5-pillar gap-analysis maturity workbook (Excel) with board dashboard, the Executive All-in-One Toolkit, Register of Information pack ## Blog (Expert Analysis) - [Database Change Governance Under DORA](https://www.regulation-dora.eu/blog/dora-database-change-governance): Article 9(4)(d) and Article 17 of RTS 2024/1774 make every production database change an evidence question. What a reviewer tests, and how to answer it - [DORA Training Requirements: Board and Staff (2026)](https://www.regulation-dora.eu/blog/dora-training-requirements-board-staff): DORA makes training compulsory twice: Article 13(6) for staff and Article 5(4) for the management body. Who is in scope, what evidence counts, how to build it - [ISO 22301 to DORA: The Complete Mapping Guide (2026)](https://www.regulation-dora.eu/blog/iso-22301-to-dora-mapping-guide): Run an ISO 22301 BCMS? You are closer to DORA than you think. Clause-by-clause mapping, the deltas the standard leaves open, and the quick wins to close them - [The CIF Decision Record: Evidencing Why a Function Is Critical](https://www.regulation-dora.eu/blog/dora-cif-decision-record-evidencing-designations): Every entity has a list of critical or important functions. Almost none can show how each entry got there. A six-field record per function, including the ones you decided not to designate - [DORA Article 8: Mapping ICT Assets and Functions Before Your BIA](https://www.regulation-dora.eu/blog/dora-article-8-ict-asset-and-function-mapping): Identification comes before analysis. The four layers you need on paper, how granular to go, and why a mapping built from the CMDB upwards produces a register that fails its consistency - [DORA Impact Tolerance: Setting a Threshold You Can Defend](https://www.regulation-dora.eu/blog/dora-impact-tolerance-setting-defensible-thresholds): Tolerance, MTPD and RTO answer three different questions, and setting them in the wrong order is why so many critical-function designations cannot be evidenced. How to write one that - [The AI Act Delay: What the Digital Omnibus Actually Changes for Banks](https://www.regulation-dora.eu/blog/ai-act-omnibus-delay-what-it-changes-for-banks-2026): The Council approved the Digital Omnibus on 29 June 2026 and the high-risk deadlines moved to December 2027. But the transparency deadline did not move at all, and the Omnibus quietly added - [Credit Scoring Under Annex III: Are You the Provider or the Deployer?](https://www.regulation-dora.eu/blog/ai-act-credit-scoring-annex-iii-provider-or-deployer): Most banks buy their scoring models and assume they are deployers with light obligations. Article 25 says otherwise: fine-tuning a bought model on your own loan book makes you its provider - [One Incident, Two Regulators: DORA Article 19 vs AI Act Article 73](https://www.regulation-dora.eu/blog/dora-article-19-ai-act-article-73-dual-incident-reporting): A model that quietly discriminates may not be a DORA major incident at all, and is squarely an AI Act serious incident. Two regulators, two triggers, two clocks. How to extend your DORA - [GPAI in Finance: You Call an API. Does That Make You a Provider?](https://www.regulation-dora.eu/blog/gpai-obligations-finance-api-fine-tuning): No. The Commission set an indicative threshold: you only become the provider of a modified general-purpose model if your fine-tuning compute exceeds a third of the original training run - [How to Respond to Your EU Partners' DORA Requirements](https://www.regulation-dora.eu/blog/how-to-respond-to-eu-partners-dora-requirements): An EU financial client just sent you DORA contract clauses or a security questionnaire. Here is what they must ask (Articles 28-30) and how to respond and win - [Is Your Non-EU Financial Firm Exposed to DORA? (2026)](https://www.regulation-dora.eu/blog/dora-non-eu-financial-firms-exposure-2026): US, UK, Swiss or other non-EU financial firm? DORA may already apply to you - through EU branches, group entities or your EU clients. Here is how to tell - [DORA + EU AI Act: The Double Compliance Obligation for Financial Institutions](https://www.regulation-dora.eu/blog/dora-ai-act-convergence-financial-institutions-2026): Financial institutions using AI systems face simultaneous obligations under DORA and the EU AI Act. Here is how to map them efficiently and avoid duplicating compliance work - [Chaos Engineering & Resilience Testing Under DORA (2026)](https://www.regulation-dora.eu/blog/chaos-engineering-resilience-testing-dora): DORA requires you to test resilience on critical systems — not assume it. Chaos engineering turns that obligation into evidence: deliberately injecting failure to prove your systems - [DORA for Custom Software Vendors: How to Become a Compliant ICT Provider (2026)](https://www.regulation-dora.eu/blog/dora-for-custom-software-vendors): If you build or sell software to EU financial entities, DORA reaches you through your clients. Here is exactly what software vendors must support — Article 30 clauses, audit rights - [Application Modernization & Operational Resilience: A DORA-Driven Roadmap (2026)](https://www.regulation-dora.eu/blog/application-modernization-operational-resilience-dora): Legacy systems are one of the biggest hidden DORA risks. This guide shows how application modernization — decoupling, cloud, observability, automated recovery — directly supports DORA - [Software Architecture Choices That Reduce ICT Risk Under DORA (2026)](https://www.regulation-dora.eu/blog/software-architecture-reduce-ict-risk-dora): Resilience is an architecture decision long before it is a compliance one. Here are the design patterns — redundancy, isolation, graceful degradation, immutable backups, observability — - [Monitoring, Incident Reporting & Auditability by Design (DORA, 2026)](https://www.regulation-dora.eu/blog/monitoring-incident-reporting-auditability-by-design-dora): DORA’s 4h/72h/1-month incident reporting and its evidence demands are far easier when monitoring and audit trails are built into your systems. Here is how to make detection, regulatory - [SBOM vs AI-Discovered Zero-Days: Your Fastest DORA Defence](https://www.regulation-dora.eu/blog/sbom-ai-zero-days-dora-frontline-control): When an AI can surface a 27-year-old vulnerability in hardened software, the question stops being “is our code secure?” and becomes “do we even know what is in it?” A Software Bill - [Software Supply Chain Security & SBOM Under DORA (2026)](https://www.regulation-dora.eu/blog/software-supply-chain-security-sbom-dora): Your fourth parties are now in scope. DORA pushes ICT risk down the subcontracting chain, and a Software Bill of Materials (SBOM) is how engineering teams make that chain visible. Here is - [Cloud Exit Strategies & Concentration Risk Under DORA (2026)](https://www.regulation-dora.eu/blog/cloud-exit-strategy-concentration-risk-dora): DORA expects a credible, tested way to leave a critical cloud provider — and a clear view of concentration risk. Here is how engineering and procurement teams build exit strategies that - [DevSecOps & the Secure SDLC: Building DORA Compliance Into the Pipeline (2026)](https://www.regulation-dora.eu/blog/devsecops-secure-sdlc-dora): DORA wants security and resilience designed in, not bolted on. A secure software development lifecycle — DevSecOps — bakes the controls, testing and evidence DORA expects into the way - [Anthropic’s Mythos & AI-Orchestrated Attacks: What Banks and Insurers Must Do Under DORA](https://www.regulation-dora.eu/blog/mythos-ai-orchestrated-attacks-banks-insurers-dora): A frontier AI that finds thousands of zero-days, and the first AI-run cyber-espionage campaign against financial institutions, have put bank and insurer boards on edge. Here is what - [ISO 27001 to DORA: The Complete Mapping Guide (2026)](https://www.regulation-dora.eu/blog/iso-27001-to-dora-mapping-guide): If you already run an ISO 27001 ISMS, it is the fastest roadmap to DORA. This guide maps DORA to ISO 27001:2022 control-by-control, shows exactly what the standard does not cover, and gives - [Critical or Important Functions under DORA: the Term That Runs Everything (2026 Guide)](https://www.regulation-dora.eu/blog/dora-critical-important-functions-cif-guide): Almost every demanding obligation in DORA — TLPT scope, Article 30 contracts, the Register of Information, business continuity — keys off one defined term: the Critical or Important - [DORA and Third-Party ICT Providers: The Guide for Suppliers (Articles 28-30)](https://www.regulation-dora.eu/blog/dora-third-party-ict-providers-guide-for-suppliers): DORA is not just for banks. Learn what Articles 28 to 30 require from ICT providers and software vendors — and how to turn the constraint into a commercial advantage - [From BIA to CIF: How a Business Impact Analysis Identifies Your DORA Critical or Important Functions](https://www.regulation-dora.eu/blog/bia-to-cif-business-impact-analysis-dora-methodology): BIA is the methodological engine behind a defensible CIF inventory. ISO 22317 service catalogue, 5-axis impact scoring, MTPD threshold, Article 3(22) gate - [DORA TLPT Methodology: Phase-by-Phase Guide](https://www.regulation-dora.eu/blog/dora-tlpt-testing-methodology-phase-by-phase): DORA TLPT methodology: 5 TIBER-EU phases, Red/Blue/White team setup, 9-14 month timeline, EUR 270k-620k budget, vendor selection, attestation - [DORA Register of Information: Build Methodology](https://www.regulation-dora.eu/blog/dora-ict-third-party-risk-register-methodology): Step-by-step methodology to build the DORA Register of Information (RoI). 9 templates, xBRL-CSV format, CIF flagging, 6-step playbook, common pitfalls - [DORA Register of Information: Your Q1 2026 Submission Guide](https://www.regulation-dora.eu/blog/dora-register-information-q1-2026-submission-guide): Q1 2026 submission guide - [DORA Enforcement 2026: The Grace Period Is Over](https://www.regulation-dora.eu/blog/dora-enforcement-2026-end-grace-period): Active enforcement from January 2025 — what changed - [DORA Penalties Explained: What Happens When Financial Institutions Fail to Comply](https://www.regulation-dora.eu/blog/dora-penalties-fines-what-happens-non-compliance): DORA sets no EU-wide maximum fine for financial entities — Article 50 hands the amount to national law, so your ceiling depends on your competent authority. Here is how enforcement - [DORA Incident Reporting: The Exact Timelines and What Regulators Expect in 2026](https://www.regulation-dora.eu/blog/dora-incident-reporting-timeline-requirements-2026): 4-hour / 72-hour / 1-month reporting requirements - [TLPT Under DORA: Why Threat-Led Penetration Testing Is Not Just Another Pentest](https://www.regulation-dora.eu/blog/dora-tlpt-threat-led-penetration-testing-guide): Threat-led penetration testing explained - [DORA Register of Information: Complete Guide to the March 2026 Submission](https://www.regulation-dora.eu/blog/dora-register-of-information-2026-guide): The second annual Register of Information submission is due March 2026. Nearly half of financial entities identified this as the single most challenging DORA requirement. Here is how to get - [DORA in 2026: The Grace Period Is Over — What Active Enforcement Means for Your Institution](https://www.regulation-dora.eu/blog/dora-2026-enforcement-what-changes): Regulators are shifting from reviewing paperwork to demanding real-time proof of resilience. With only 50% of firms fully compliant, 2026 marks the start of active DORA enforcement across - [DORA Critical ICT Providers: Full List of 19 Designated CTPPs (2025-2026)](https://www.regulation-dora.eu/blog/critical-ict-third-party-designations-october-2025): All 19 designated CTPPs by ESAs and oversight framework - [Breaking: ESAs Publish First List of Critical ICT Third-Party Providers Under DORA](https://www.regulation-dora.eu/blog/esas-publish-critical-ict-third-party-providers-list-dora-2025): On November 18, 2025, the European Supervisory Authorities (ESAs) published the first official list of designated Critical Third-Party Providers (CTPPs) under DORA, including major cloud - [DORA Penalties and Fines 2026: What Happens If You're Not Compliant?](https://www.regulation-dora.eu/blog/dora-penalties-fines-enforcement-guide-2025): How enforcement actually works — national penalty regimes under Art. 50, CTPP periodic penalty payments under Art. 35, mitigation factors - [TIBER-EU Framework Updated for DORA: New TLPT Testing Requirements Explained](https://www.regulation-dora.eu/blog/tiber-eu-framework-dora-tlpt-testing-2025): The Eurosystem has updated the TIBER-EU framework to align with DORA's threat-led penetration testing (TLPT) requirements. Learn what this means for your testing program - [DORA Technical Standards: Latest Regulatory Developments and Amendments](https://www.regulation-dora.eu/blog/dora-technical-standards-updates-october-2025): The European Commission and ESAs have issued important amendments to DORA technical standards. Stay informed about the latest regulatory changes affecting your compliance program - [DORA Enforcement in 2026: Understanding Penalties and Supervisory Powers](https://www.regulation-dora.eu/blog/dora-enforcement-penalties-supervisory-powers-2025): With DORA enforcement now active, financial institutions face significant penalties for non-compliance. Learn about the supervisory powers, penalty frameworks, and how to manage enforcement - [DORA Register of Information: Compliance Status and Next Steps](https://www.regulation-dora.eu/blog/dora-register-information-compliance-update-2025): With the April 2025 deadline passed, financial institutions must now ensure their ICT service provider registers remain accurate and complete. Learn about ongoing obligations and best - [DORA Incident Classification and Reporting: Complete Regulatory Guide](https://www.regulation-dora.eu/blog/dora-incident-classification-reporting-guide): Understand how to classify ICT incidents under DORA and meet reporting requirements. This guide covers incident thresholds, classification codes, and reporting procedures - [DORA Banking vs Insurance: Sector-Specific Compliance Requirements Explained](https://www.regulation-dora.eu/blog/dora-banking-vs-insurance-sector-differences): While DORA applies to all financial institutions, banks and insurance companies face different implementation challenges. Learn the sector-specific differences and requirements - [DORA Compliance Checklist: Step-by-Step Implementation Guide (Updated 2026)](https://www.regulation-dora.eu/blog/dora-compliance-checklist-2025): A comprehensive checklist for DORA compliance covering all 5 pillars. Download our free checklist and verify your institution meets all current requirements - [Building an ICT Risk Management Framework Under DORA: A Practical Guide](https://www.regulation-dora.eu/blog/building-ict-risk-management-framework-dora): Pillar 1 of DORA requires a comprehensive ICT risk management framework. Learn how to build one from scratch with practical examples and templates - [DORA RTS vs ITS: Understanding Technical Standards and Implementation Requirements](https://www.regulation-dora.eu/blog/dora-rts-vs-its-complete-comparison): What's the difference between RTS (Regulatory Technical Standards) and ITS (Implementing Technical Standards) under DORA? This guide breaks down both standards and their implementation - [DORA and Cloud Services: Third-Party and Outsourcing Requirements Guide](https://www.regulation-dora.eu/blog/dora-cloud-outsourcing-third-party-requirements): DORA creates specific requirements for cloud services, outsourcing partners, and critical third-party service providers. Learn what your institution must do to ensure compliance - [DORA Compliance for Small Financial Institutions: Proportionality in Practice](https://www.regulation-dora.eu/blog/dora-compliance-small-financial-institutions): Small financial entities face unique challenges with DORA compliance. Learn how proportionality applies and practical steps to achieve compliance efficiently - [Cloud Services Under DORA: Complete Compliance Guide for Financial Institutions](https://www.regulation-dora.eu/blog/cloud-services-dora-compliance-guide): Using cloud services? Learn how DORA affects cloud adoption, what you need from your providers, and how to maintain compliance in multi-cloud environments - [DORA Is Now in Force: What Financial Institutions Must Do in 2026](https://www.regulation-dora.eu/blog/dora-deadline-2025-what-you-need-to-know): DORA has been in force since January 2025. Financial institutions must now demonstrate full compliance. Here's what the regulation requires and where to start - [DORA and Cyber Insurance: What Financial Institutions Need to Know](https://www.regulation-dora.eu/blog/dora-cyber-insurance-what-you-need-to-know): Can cyber insurance help with DORA compliance? Learn how insurance fits into your operational resilience strategy and what insurers now require - [Third-Party Risk Management Under DORA: A Complete Guide](https://www.regulation-dora.eu/blog/third-party-risk-management-under-dora): DORA Pillar 4 introduces stringent requirements for managing ICT third-party service providers. Learn how to ensure your vendors are compliant - [Preparing for DORA Audits: A Practical Guide for Financial Institutions](https://www.regulation-dora.eu/blog/preparing-dora-audits-practical-guide): Supervisory audits are coming. Learn how to prepare documentation, what auditors will look for, and how to demonstrate compliance effectively - [DORA vs NIS2: Understanding the Key Differences](https://www.regulation-dora.eu/blog/dora-vs-nis2-understanding-the-differences): Lex specialis relationship, dual-compliance guidance - [Incident Reporting Under DORA: A Step-by-Step Guide](https://www.regulation-dora.eu/blog/incident-reporting-under-dora-step-by-step-guide): DORA mandates strict incident reporting timelines and procedures. Learn how to establish compliant incident management processes - [Threat-Led Penetration Testing (TLPT) Under DORA: What to Expect](https://www.regulation-dora.eu/blog/threat-led-penetration-testing-tlpt-explained): DORA requires financial entities to conduct advanced threat-led penetration testing. Learn what TLPT involves and how to prepare ## Sector & Regulation Pages - [DORA Compliance Platform EU: Free Tools, RTS & Gap Analysis](https://www.regulation-dora.eu/): DORA EU compliance platform. Free tools, all 13 RTS/ITS standards decoded, gap analysis & assessment. Everything financial institutions need 2026 - [DORA Certification 2026](https://www.regulation-dora.eu/dora-certification): Verifiable DORA certification programmes, exam format, and what each credential covers - [Dora Professional](https://www.regulation-dora.eu/dora-professional): Citable DORA RTS/ITS reference dossier and editable white-label toolkit for law firms, consultancies and auditors. Article-level obligations, deadlines and client-ready deliverables - [Add Dora Compliance Services](https://www.regulation-dora.eu/add-dora-compliance-services): Add DORA compliance verification to your IT services. Certification, gap-analysis workbook and client-ready deliverables to start in weeks, not months - [Compare](https://www.regulation-dora.eu/compare): Compare every DORA kit and toolkit at a glance: gap-analysis workbook, assessment toolkits, playbooks, Register of Information, board pack, policies, white-label rights and certification - [Risk Assessment](https://www.regulation-dora.eu/risk-assessment): Consultant-grade DORA risk assessment toolkits: Cyber, IT/ICT, Operational Resilience and Third-Party. Excel questionnaires mapped to ISO 27001/27005/22301/27036 and DORA, with maturity and - [DORA Incident Report Generator: 4h / 72h / 1-month drafts](https://www.regulation-dora.eu/incident-report-generator): Generate DORA major-incident report drafts: initial (4h), intermediate (72h) and final (1-month). Auto deadlines, classification check and clean export - [DORA Register of Information Builder & Validator (xBRL-CSV)](https://www.regulation-dora.eu/register-of-information-builder): Build and validate your DORA Register of Information (Art. 28(3), ITS 2024/2956): guided templates, LEI/ISO/service-type validation, CSV export for the xBRL-CSV submission - [Payment Institutions](https://www.regulation-dora.eu/payment-institutions): DORA for payment institutions and e-money issuers: operational resilience for transaction flows, safeguarding accounts, and SCA-protected fraud controls - [Crypto Casp](https://www.regulation-dora.eu/crypto-casp): DORA operational resilience for MiCA-authorised crypto firms, built for 24/7 markets, custody and on-chain dependencies - [Investment Firms](https://www.regulation-dora.eu/investment-firms): DORA for MiFID II investment firms: trading-system resilience, algo controls and proportionate ICT risk management - [Asset Managers](https://www.regulation-dora.eu/asset-managers): DORA for the firms that run Europe's funds: protecting NAV integrity, valuation and the delegation chain - [Crowdfunding](https://www.regulation-dora.eu/crowdfunding): Proportionate DORA compliance for lean, ECSPR-authorised crowdfunding platforms - [Pension Funds](https://www.regulation-dora.eu/pension-funds): DORA operational resilience for occupational pension funds, built for lean, heavily outsourced schemes that depend on third-party administrators, asset managers and custodians - [Market Infrastructure](https://www.regulation-dora.eu/market-infrastructure): DORA operational resilience for central counterparties, central securities depositories and trading venues, built for systemic markets where outages are measured in minutes - [Accredited Firms](https://www.regulation-dora.eu/accredited-firms): Directory of accredited DORA advisory firms — vetted partners employing Certified DORA Advisors, with accreditation lookup - [DORA for Non-EU Financial Firms (Africa, US, GCC)](https://www.regulation-dora.eu/dora-non-eu): Non-EU bank, payment institution or fund? See how DORA reaches you, what your EU partners will require by contract, and how to get ready — free tools, templates and a 2-3 day Flash Audit - [Download DORA Compliance Resources](https://www.regulation-dora.eu/download): Free PDF guides and checklists - [DORA Regulation Resources](https://www.regulation-dora.eu/video): Access official DORA resources from EBA, EIOPA, ESMA, KPMG, PwC. Webinars, technical standards (RTS/ITS), implementation guides, and expert videos - [DORA Use Cases: Implementation Scenarios by Sector (2026)](https://www.regulation-dora.eu/usecases): Illustrative DORA implementation scenarios for banks, insurers, payment providers and investment firms. Typical workstreams, planning lessons, roadmap - [Contact DORA Experts](https://www.regulation-dora.eu/contact): Expert consultation and support - [DORA Blog](https://www.regulation-dora.eu/blog): Stay updated with the latest DORA regulation insights, compliance guides, and expert analysis. Your comprehensive resource for digital operational resilience - [DORA Regulation News & Updates](https://www.regulation-dora.eu/news): Stay updated with the latest DORA regulation news, regulatory updates from EBA, EIOPA, ESMA, implementation guides, and compliance deadlines - [About Us](https://www.regulation-dora.eu/about): ISO 27001 certified, founded 2023, led by Matthieu Roland (DORA Consultant) - [DORA Compliance Services](https://www.regulation-dora.eu/services): Advisory engagements: gap assessment, programme delivery, TLPT support, audit readiness - [DORA Server Hardening Requirements: Complete Checklist 2026](https://www.regulation-dora.eu/dora-server-hardening): DORA server hardening checklist aligned with RTS 2024/1774. ICT controls, access management, encryption, logging, vulnerability management. Free reference - [DORA Compliance Software 2026: Specialised SaaS Platform for EU Banks](https://www.regulation-dora.eu/dora-compliance-software): DORA compliance software for EU financial institutions. Automate Register of Information, CIF evaluation, incident reporting, vendor risk. Free 14-day trial ## Key Facts (for AI citation) - DORA = Digital Operational Resilience Act, EU Regulation 2022/2554 - Applicable since: 17 January 2025 - Scope: 22,000+ EU financial entities (banks, insurers, payment institutions, crypto-asset firms, ICT third-party providers) - 5 Pillars: ICT Risk Management, Incident Reporting, Resilience Testing (TLPT), Third-Party Risk, Information Sharing - Penalties for financial entities: set by the national law of the supervising Member State. Article 50 requires each Member State to give its competent authorities the power to impose administrative penalties and remedial measures, and leaves the amount to national transposition. DORA fixes no Union-level maximum fine for financial entities, and states no percentage of turnover for them. - Penalties for designated critical ICT third-party providers (CTPPs): periodic penalty payments of 1% of average daily worldwide turnover (Article 35). This is the only turnover-based percentage in the Regulation. - Criminal penalties: Member States may provide for them (Article 52). - Critical ICT Third-Party Providers: 19 designated by ESAs as of November 2025 - Incident timelines: 4-hour initial notification, 72-hour intermediate report, 1-month final report - Register of Information: required under Article 28(3); machine-readable xBRL-CSV per ITS (EU) 2024/2956 (15 templates); most 2026 national deadlines end of Q1 2026 (e.g. 31 March 2026), ESA consolidation by 30 April ## About - [About Cryptaguard / DORA Regulation EU](https://www.regulation-dora.eu/about): ISO 27001 certified, founded 2023, led by Matthieu Roland (DORA Consultant) — [LinkedIn](https://www.linkedin.com/company/105813695) - [Contact](https://www.regulation-dora.eu/contact): Expert consultation and support - [Download Centre](https://www.regulation-dora.eu/download): Free PDF guides and checklists - [Sitemap](https://www.regulation-dora.eu/sitemap.xml) - Localised editions of the core pages exist in 11 other EU languages (de, fr, it, es, nl, pl, pt, ro, cs, el, bg) under // — see sitemap.xml. They are translations of the pages listed above, not additional content. ## Sister Site - [regulation-ai.eu](https://www.regulation-ai.eu/en/): Our sister site, from the same publisher, covering the EU AI Act (Regulation 2024/1689) — all 113 articles, Annex I and Annex III, GPAI rules, the Digital Omnibus deadline changes, and 7 interactive tools, in all 24 EU official languages. Use it for the text of the AI Act itself; use regulation-dora.eu for what the AI Act adds to a DORA programme.