Technical Standards · 2026 Edition

DORA RTS & ITS: Regulatory Technical Standards

Comprehensive guide to DORA's Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS). Download the complete PDF documentation and understand all compliance requirements.

Official DORA Technical Standards 13 RTS & ITS policy products Directly applicable EU law
Premium reference · 2026 edition

DORA RTS & ITS: The Complete Reference

Every one of the 13 RTS/ITS policy products, decoded pillar by pillar into plain implementation language: thresholds, timelines, templates and a ready-to-use checklist at the end of each chapter. 24 pages you can act on, instead of several hundred pages of ESA legal text you have to reconcile yourself.

  1. 1 Orientation: the five pillars, RTS vs ITS, the mandate map of all 13 policy products, adoption timeline
  2. 2 Pillar 1: RTS on the ICT risk management framework + the simplified framework, with checklist
  3. 3 Pillar 2: incident classification criteria and the 4h / 72h / 1-month reporting chain, with checklist
  4. 4 Pillar 3, TLPT RTS: TIBER-EU alignment, scoping, attestation, with checklist
  5. 5 Pillar 4: third-party policy RTS, ITS on the Register of Information, RTS on subcontracting, with checklist
  6. 6–7 The CTPP oversight framework & Pillar 5 information and intelligence sharing
  7. 8 Implementation toolkit: master compliance checklist + gap-analysis worksheet
  8. 9 Glossary & sources
PDF · 24 pages · A4 Delivered by email in seconds Every future edition, free Licence covers your whole entity

What are DORA RTS and ITS?

The Digital Operational Resilience Act (DORA) is supplemented by detailed Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS) developed by the European Supervisory Authorities (ESAs) - EBA, EIOPA, and ESMA. New to the regulation? Start with our complete guide to what DORA is, then return here for the technical detail.

Key Difference

RTS (Regulatory Technical Standards): Define detailed technical requirements and regulatory standards that financial entities must comply with.

ITS (Implementing Technical Standards): Provide practical implementation details, templates, and formats for reporting and compliance.

Implementing the standards with ISO 27001?

If you already run an ISO 27001 ISMS, it is the fastest roadmap to these standards. Read our ISO 27001 → DORA mapping guide (what maps cleanly, the regulatory delta, and the quick wins) or learn the full control mapping in the DORA Programme Manager certification.

Key Areas Covered by DORA RTS

ICT Risk Management

  • Governance arrangements and frameworks
  • Risk identification and assessment methodologies
  • ICT systems classification criteria
  • Documentation requirements
  • Internal audit procedures

Incident Reporting

  • Major incident classification criteria
  • Reporting timelines and templates
  • Notification thresholds
  • Root cause analysis requirements
  • Significant cyber threat reporting

Resilience Testing

  • Advanced testing methodologies (TLPT)
  • Testing frequency and scope
  • Threat-Led Penetration Testing (TLPT) framework
  • Test execution and reporting
  • Remediation action plans

Third-Party Risk

  • Critical ICT service provider criteria
  • Contractual arrangements requirements
  • Exit strategies and transition plans
  • Sub-outsourcing oversight
  • Register of information requirements

Information Sharing

  • Cyber threat intelligence sharing arrangements
  • Data protection and confidentiality
  • Trusted information sharing frameworks
  • Cross-border cooperation mechanisms

Oversight Framework

  • Designation criteria for critical providers
  • Oversight tools and powers
  • Inspection procedures
  • Enforcement mechanisms
  • Cooperation between authorities

DORA RTS Implementation Timeline

Application Date

17 January 2025: DORA became fully applicable across all EU Member States. Financial entities must comply with the Regulation and with the RTS and ITS adopted under it.

January 16, 2023

DORA Entry into Force: Regulation (EU) 2022/2554 entered into force, giving entities 24 months to prepare.

2023-2024

RTS & ITS Development: ESAs developed and finalized technical standards through public consultations.

July-December 2024

Final RTS Adoption: European Commission adopted final RTS packages covering all DORA pillars.

January 17, 2025

Full Application: DORA and the first-batch RTS/ITS become fully applicable across the EU.

February – July 2025

Second Batch in the Official Journal: oversight harmonisation (2025/295, 13 Feb), incident reporting RTS/ITS (2025/301 and 2025/302, 20 Feb), TLPT (2025/1190, in force 8 July) and subcontracting (2025/532, in force 22 July). The DORA level-2 framework is complete.

The Complete RTS, ITS & Joint Guidelines Catalogue (13 Texts)

DORA is supplemented by 13 texts developed jointly by the EBA, ESMA and EIOPA (the European Supervisory Authorities, or ESAs): eleven binding technical standards (RTS and ITS) and two sets of Joint Guidelines applied on a comply-or-explain basis. The standards were delivered in two batches: the "first batch" submitted to the European Commission in January 2024, and the "second batch" finalised mid-2024. Once adopted by the Commission as Delegated Regulations or Implementing Regulations, the standards are directly applicable across all 27 Member States, no national transposition required.

First batch RTS (submitted January 2024, in force since 2024)

  1. RTS on ICT risk management framework (Article 15), Commission Delegated Regulation (EU) 2024/1774: comprehensive minimum content for security policies, access management, encryption, cryptography, network segmentation, ICT change management, business continuity policy and crisis communication.
  2. RTS on simplified ICT risk management framework (Article 16(3)), same legal act, Delegated Regulation (EU) 2024/1774: proportionate framework for entities qualifying as small and non-interconnected. Reduced requirements but core principles (board accountability, incident management, third-party rules) preserved.
  3. RTS on classification of major ICT-related incidents and significant cyber threats (Article 18(3)), Commission Delegated Regulation (EU) 2024/1772, the criteria and materiality thresholds for "major" classification, plus criteria for "significant cyber threat" reporting. Defines the thresholds that determine whether the 4h/72h/1m clock starts.
  4. RTS on policy on ICT services supporting critical or important functions (Article 28(10)), Commission Delegated Regulation (EU) 2024/1773: what the third-party policy must contain, board ownership, integration with overall risk management.
  5. ITS on Register of Information (Article 28(9)), Commission Implementing Regulation (EU) 2024/2956: the template, taxonomy of ICT services, mandatory fields, submission cadence and quality expectations.

Second batch RTS & ITS (adoption completed through 2025)

  1. RTS on subcontracting of ICT services supporting critical or important functions (Article 30(5)), Commission Delegated Regulation (EU) 2025/532, adopted 24 March 2025, in force since 22 July 2025. Covers what a financial entity must determine and assess before allowing subcontracting: notification, sub-outsourcing visibility, concentration risk, data location transparency.
  2. RTS on threat-led penetration testing (Article 26(11)), Commission Delegated Regulation (EU) 2025/1190, in force since 8 July 2025, TIBER-EU-aligned methodology: threat intelligence, red teaming, scope definition, white team/blue team controls, reporting to NCAs, supervisory attestation.
  3. RTS on harmonisation of conditions enabling the conduct of oversight activities (Article 41(1)), Commission Delegated Regulation (EU) 2025/295, operational rules for the Lead Overseer regime: how the ESAs supervise designated CTPPs, information requests, recommendations.
  4. RTS specifying the criteria for the designation of CTPPs (Article 31(6)), Commission Delegated Regulation (EU) 2024/1502, two-step quantitative and qualitative assessment: number of financial entities served, systemic importance of those entities, substitutability of the provider.
  5. RTS on joint examination teams (Article 41(1)(c)), Commission Delegated Regulation (EU) 2025/420: composition, designation, tasks and working arrangements of the teams supporting the Lead Overseer in examinations of designated CTPPs.
  6. RTS and ITS on major incident reporting (Article 20): Commission Delegated Regulation (EU) 2025/301 (content and time limits of initial, intermediate and final reports) and Commission Implementing Regulation (EU) 2025/302 (standard forms and templates), both in the Official Journal on 20 February 2025. Submission via NCA portals.
  7. Joint Guidelines on the estimation of aggregated annual costs and losses from major ICT-related incidents (Article 11(11)), JC/GL/2024/34. Delivered as ESA guidelines rather than an RTS: methodology for aggregating direct and indirect costs of ICT incidents for supervisory reporting.
  8. Joint Guidelines on oversight cooperation between the ESAs and competent authorities (Article 32(7)), operational coordination for the oversight of designated CTPPs and supervisory dialogue.

Cross-reference: mandate → legal act → EUR-Lex

Every adopted act, with its DORA mandate and the directly citable Official Journal reference. Use the exact regulation number when you reference a requirement in a policy document or a supervisory response: "the RTS on subcontracting" is ambiguous, "Delegated Regulation (EU) 2025/532, Article 5" is not.

Standard DORA mandate Legal act Status Text
ICT risk management framework + simplified frameworkArt. 15, Art. 16(3)Delegated Regulation (EU) 2024/1774In force, applies alongside DORA since 17 Jan 2025EUR-Lex
Classification of major incidents and significant cyber threatsArt. 18(3)Delegated Regulation (EU) 2024/1772In force, applies alongside DORA since 17 Jan 2025EUR-Lex
Policy on ICT services supporting CIFs (third-party policy)Art. 28(10)Delegated Regulation (EU) 2024/1773In force, applies alongside DORA since 17 Jan 2025EUR-Lex
Register of Information (template & taxonomy)Art. 28(9)Implementing Regulation (EU) 2024/2956In force, annual submission via your NCA (first cycle 2025)EUR-Lex
CTPP designation criteriaArt. 31(6)Delegated Regulation (EU) 2024/1502In force, basis of the 2025 CTPP designationsEUR-Lex
Oversight fees charged to designated CTPPsArt. 43(2)Delegated Regulation (EU) 2024/1505In force: OJ 30 May 2024EUR-Lex
Harmonisation of oversight conduct (Lead Overseer regime)Art. 41(1)Delegated Regulation (EU) 2025/295In force: OJ 13 Feb 2025EUR-Lex
Incident reporting: content & time limits (4h / 72h / 1 month)Art. 20(a)Delegated Regulation (EU) 2025/301In force: OJ 20 Feb 2025EUR-Lex
Incident reporting: forms & templatesArt. 20(b)Implementing Regulation (EU) 2025/302In force: OJ 20 Feb 2025EUR-Lex
Joint examination teamsArt. 41(1)(c)Delegated Regulation (EU) 2025/420In force, adopted 16 Dec 2024EUR-Lex
Subcontracting of ICT services supporting CIFsArt. 30(5)Delegated Regulation (EU) 2025/532In force since 22 July 2025: OJ 2 July 2025EUR-Lex
Threat-led penetration testing (TLPT)Art. 26(11)Delegated Regulation (EU) 2025/1190In force since 8 July 2025: OJ 18 June 2025EUR-Lex
Aggregated costs & losses of major incidentsArt. 11(11)Joint Guidelines JC/GL/2024/34 (not an RTS)Applies: ESA guidelines, comply-or-explain at NCA levelEBA

Quick reference

The same cross-reference, decoded standard by standard with implementation checklists, is available in our RTS & ITS Complete Overview.

Worked Example: Which Standards Apply to a Cloud Outsourcing

The catalogue is abstract until you map it onto a concrete decision. Take a common one: a bank moves its payment processing platform to a public cloud provider. Payment processing is a critical or important function (CIF), so the move triggers obligations from six of the standards above, each demanding a specific artefact:

Standard What it requires here Artefact to produce
2024/1773 (third-party policy)The outsourcing decision must follow your board-approved policy on ICT services supporting CIFs: due diligence, risk assessment before signature, exit strategyPre-contract risk assessment + documented board or committee approval
DORA Art. 30 (contract itself)The cloud contract must contain the Article 30(3) mandatory clauses: audit and access rights, data location, termination rights, exit assistance, service levelsContract clause mapping, each Art. 30(3) point matched to a clause reference
2024/2956 (Register of Information)One row per contracted ICT service, flagged as supporting a CIF, with provider LEI, jurisdiction and dependency dataUpdated Register of Information before the next annual submission
2025/532 (subcontracting)You must assess the provider's subcontracting chain for the service (who actually runs the data centres, where support sits) and secure notification and objection rights for material changesSubcontracting chain assessment + contract clauses on chain visibility
2024/1772 + 2025/301 (incidents)An outage of the platform is assessed against the major-incident criteria; if major, the 4h / 72h / 1-month reporting chain starts, cloud provider incidents includedIncident classification procedure covering provider-originated incidents, with provider notification duties in the contract
2025/1190 (TLPT)If your entity is in TLPT scope, the systems supporting payment processing, now partly on cloud infrastructure, belong in the test scopeTLPT scope definition including the cloud-hosted components

The pattern generalises: CIF status is the switch that turns most of these standards on. Before mapping any outsourcing against the catalogue, settle whether the function it supports is critical or important, our CIF identification guide covers the methodology, and the third-party risk guide covers the Article 28-30 chain end to end.

Detailed RTS Requirements by Pillar

1. ICT Risk Management RTS

The RTS on ICT risk management framework (Commission Delegated Regulation 2024/1774) is the densest and most operationally significant of the technical standards. It runs to 70+ recitals and articles, covering the full ICT control surface a financial entity must maintain. Key chapters include security policies and procedures (governance level), human resources policy and security awareness, identity management and access control with multi-factor authentication for privileged access, cryptographic controls including key management, network security (segmentation, monitoring, secure configuration), ICT operations (change, capacity, vulnerability), ICT project management and acquisition, ICT business continuity policy with documented RTOs/RPOs, and crisis communication.

Requirement Area Key Provisions
GovernanceManagement body responsibilities, ICT risk management function, three lines of defence
Risk AssessmentComprehensive ICT risk assessment at least annually, documenting critical/important functions
Protection & PreventionSecurity policies, access controls (incl. MFA for privileged), change management, network security
CryptographyEncryption at rest, in transit, in use; key management aligned with recognised standards; cryptographic agility
DetectionContinuous monitoring, anomaly detection, logging and correlation, SOC capabilities
Response & RecoveryBusiness continuity plans, disaster recovery, backup strategies, validated RTO/RPO end-to-end
Learning & EvolvingPost-incident reviews, threat intelligence integration, control updates, lessons learned governance

2. Incident Reporting RTS

Financial entities must classify ICT-related incidents based on specific criteria:

Classification Criteria

Incidents are classified as "major" based on:

  • Number of clients/financial counterparties affected (thresholds vary by entity type)
  • Duration of downtime
  • Geographical spread
  • Data losses
  • Criticality of services affected
  • Economic impact

DORA RTS & ITS: The Complete Reference (24-page PDF)

The €29.99 reference covers all 13 RTS/ITS policy products in a single PDF, including this incident-reporting chapter in full: classification criteria, the 4h / 72h / 1-month chain, and a Pillar 2 checklist you can lift into your programme plan. For an incident deep-dive, see the Incident Response & Reporting Playbook (Pillar 2).

Get the complete RTS/ITS reference: €29.99

3. TLPT (Threat-Led Penetration Testing) RTS

Advanced testing framework for entities identified as significant:

4. Third-Party Oversight RTS

Detailed requirements for managing ICT third-party service providers:

StageRequirements
Pre-ContractingDue diligence, risk assessment, alternative provider analysis, concentration risk evaluation
ContractualArticle 30 mandatory clauses, SLAs, audit rights, termination rights, data access & location
MonitoringContinuous oversight, performance monitoring, incident reporting from providers, register updates
ExitExit strategies tested annually, transition plans, data retrieval procedures, alternative provider identified

5. RTS on Subcontracting

The RTS on subcontracting is the late-2024 standard that operationalises Article 30 paragraphs on sub-outsourcing of critical or important functions. Key obligations:

How RTS & ITS Become Binding Law

One of the most misunderstood aspects of the DORA framework is the legal pathway by which the technical standards become binding obligations. Unlike Directives, which require national transposition, DORA itself is a Regulation under Article 288 TFEU, directly applicable in all Member States with no need for national legislation. The RTS and ITS follow a similar route but with one extra step:

  1. Drafting: The ESAs (EBA, ESMA, EIOPA) draft the technical standards, often in joint mandate working groups, after public consultation.
  2. Submission to the Commission: The draft standards are submitted to the European Commission for adoption.
  3. Commission adoption: The Commission adopts the standards as Delegated Regulations (for RTS) or Implementing Regulations (for ITS), subject to a non-objection right by the European Parliament and Council.
  4. Publication and entry into force: The Commission Regulation is published in the Official Journal of the European Union and enters into force on the specified date, typically 20 days after publication, with potential delayed application.
  5. Direct effect: Once in force, the RTS/ITS are directly applicable in all Member States. Financial entities must comply without waiting for any national implementing legislation.

This means the question "is this RTS in force?" has a binary answer that you can verify on EUR-Lex. There is no national grace period, no transposition delay. The 17 January 2025 application date for DORA itself was the trigger, most RTS applied from that date or shortly after.

How RTS Interact with Existing Frameworks

For most financial entities, DORA RTS arrive in a regulatory landscape already shaped by sector-specific guidance from the ESAs, national supervisors, ENISA, NIS2 and global standards (ISO 27001, NIST CSF). Understanding the interaction matters for implementation efficiency.

EBA Guidelines on ICT and security risk management (EBA/GL/2019/04)

Largely superseded by the RTS on ICT risk management framework. The EBA opened a consultation in 2024 on repealing or amending these guidelines. In practice, banks should treat DORA + RTS 2024/1774 as authoritative; legacy EBA guidelines remain useful as implementation depth on specific topics (network segmentation, secure development) but no longer add binding obligations beyond what DORA mandates.

EBA Outsourcing Guidelines (EBA/GL/2019/02)

Partially superseded for ICT outsourcing by DORA Articles 28-30 plus the RTS on subcontracting. Non-ICT outsourcing (e.g., physical document management, certain operational outsourcing) continues to follow the EBA Outsourcing Guidelines. Banks need to maintain two parallel registers in many cases: DORA Register of Information for ICT and the EBA outsourcing register for non-ICT.

EIOPA Guidelines on outsourcing to cloud service providers

Under consultation in 2024 for repeal or alignment with DORA. Practically replaced by DORA Articles 28-30 + RTS on subcontracting for cloud outsourcing.

NIS2 Directive (Directive (EU) 2022/2555)

NIS2 covers a broader universe (energy, transport, health, digital infrastructure, financial services, public administration) but for financial entities DORA acts as lex specialis under NIS2 Article 4(1): DORA prevails over NIS2 obligations where they overlap. Financial entities subject to both DORA and NIS2 (e.g., a bank with a separately authorised data centre operator subsidiary) must navigate the dual framework carefully.

ISO 27001 and NIST CSF

Not binding under EU law but widely adopted. ISO 27001 controls map well to many DORA requirements; supervisors generally accept ISO 27001 certification as evidence of control design but require independent validation that DORA-specific requirements (e.g., incident classification, register of information) are met. NIST CSF provides a useful taxonomy but does not satisfy DORA on its own.

RTS & ITS FAQ

What is the difference between RTS and ITS?

RTS (Regulatory Technical Standards) define what financial entities must do: substantive technical requirements. ITS (Implementing Technical Standards) define how: templates, formats, procedural details. Both are binding directly applicable Commission Regulations once adopted, but RTS carry the substance, ITS the operational mechanics. For example, the RTS on classification defines the criteria for "major incident"; the ITS on incident reporting defines the template used to report it.

Are all 13 RTS and ITS already in force in 2026?

Yes. The first batch (ICT risk management framework, incident classification, third-party policy, Register of Information template) has applied alongside DORA since 17 January 2025. The second batch completed adoption during 2025: incident reporting RTS/ITS (2025/301 and 2025/302, OJ 20 February 2025), oversight harmonisation (2025/295, OJ 13 February 2025), TLPT (2025/1190, in force 8 July 2025) and subcontracting (2025/532, in force 22 July 2025). The cross-reference table above links every act to its EUR-Lex text.

Can a financial entity be sanctioned for non-compliance with an RTS, or only with DORA itself?

Both. The RTS, once adopted as Commission Delegated/Implementing Regulations, become binding EU law on the same legal footing as the DORA Regulation. Article 50 sanctions apply to breaches of any DORA-related obligation, which includes RTS-based requirements. NCAs can sanction breaches at their full discretion within the ceiling set by their own national law: DORA fixes no EU-wide turnover cap (Art. 50).

Does the RTS on simplified ICT risk framework reduce obligations significantly?

Yes for the entities that qualify. Simplified framework drops several documentation and process requirements (e.g., reduced testing programme, simpler ICT business continuity policy structure, lighter board reporting cadence). However, it preserves core principles: board accountability, incident management, third-party rules, register of information. Qualification is strict: small balance sheet, low complexity, no significant cross-border activity, no critical functions outsourced.

How do RTS interact with existing ISO 27001 / NIST CSF certifications?

ISO 27001 and NIST CSF are not equivalent to DORA RTS but the control overlap is significant. ISO 27001-certified entities typically meet 60-75% of the RTS on ICT risk management framework requirements out of the box. The remaining gap is mostly in DORA-specific items: incident classification per RTS thresholds, register of information format, third-party Article 30 clauses, board-level governance specifics. Supervisors accept ISO/NIST as evidence of design but require independent verification of DORA-specific delta.

What format is the Register of Information submitted in?

The ITS on Register of Information defines an XBRL/XML template with a structured taxonomy of ICT services. Submission is annual (by 30 April) via the national competent authority's portal. The 2025 first cycle revealed material data quality issues across the industry, with 35-50% of contracts having at least one missing or invalid mandatory field at most banks.

Does the TLPT RTS require strict TIBER-EU compliance?

It is aligned with TIBER-EU but not identical. The DORA TLPT RTS uses TIBER-EU as the methodological reference but adds specifics on supervisory attestation, NCA-coordination, white team/blue team protocols, and reporting. Entities already running TIBER-EU exercises typically meet the RTS with modest adaptation. New entrants treat the RTS as the primary reference and TIBER-EU implementation guidance as the operational handbook.

How often are RTS updated?

RTS are updated when the underlying DORA articles change, when ESAs identify implementation issues requiring clarification, or in response to evolving threat landscape and technology. The first major RTS review cycle is expected in 2027-2028, three years after initial application. In the interim, ESA Q&A documents provide interpretive updates without amending the RTS themselves.

Are RTS available in all EU languages?

Yes: once adopted as Commission Regulations, the RTS are published in all 24 official EU languages on EUR-Lex. The English version is typically the working version during ESA drafting; the legally binding version is each language version. Translation occasionally introduces interpretive nuances; cross-border groups typically work from the English text but verify alignment with local-language versions when supervisors raise specific points.

Official RTS/ITS Resources

Access authoritative sources for DORA technical standards:

Need Help with DORA RTS Compliance?

Implementing DORA RTS requirements can be complex. Our experts can help you:

Gap Analysis

Identify gaps between your current state and DORA RTS requirements

Implementation Roadmap

Develop a structured implementation plan with timelines and priorities

Policy & Documentation

Create compliant policies, procedures, and documentation

Training & Support

Train your teams on DORA RTS requirements and best practices

Contact Our DORA Experts

Related Resources

All RTS & ITS Standards: Complete Overview

All 13 Regulatory and Implementing Technical Standards for DORA in one searchable reference

TLPT: Threat-Led Penetration Testing Guide

Complete TLPT pillar page, who must test, TIBER-EU alignment, phases, scope requirements

What is DORA? Complete Guide

Plain-language explainer of the Digital Operational Resilience Act: 5 pillars, scope, penalties and compliance roadmap

DORA Compliance Checklist

Free interactive 45-point self-assessment across all 5 DORA pillars

DORA Audit: Requirements & Checklist

Supervisory inspections, internal audit duties under Article 6, audit scope by pillar and how to prepare

TLPT RTS: Full Technical PDF Guide

Complete TLPT framework: scope, methodology, and reporting templates from the RTS text

Incident Reporting RTS: Timelines & Templates

4-hour, 72-hour, and final report timelines with decision trees and classification criteria

RTS vs ITS: What's the Difference?

Deep-dive comparing Regulatory and Implementing Technical Standards under DORA

Latest RTS/ITS Regulatory Developments

Recent amendments and updates to DORA Technical Standards from ESAs

DORA Compliance Assessment

Take our free 5-minute assessment to evaluate your DORA readiness

Banking Sector Guide

Sector-specific guidance for banking institutions

DORA FAQ

50+ expert answers on compliance, deadlines and penalties

DORA vs NIS2: Key Differences

Both frameworks apply to many financial entities: lex specialis rule, dual compliance obligations, and where DORA takes precedence

Third-Party ICT Risk Management

Complete guide to the Register of Information, Article 30 mandatory clauses, the 19 designated CTPPs, and the due diligence framework

Critical or Important Functions (CIF)

The Article 3(22) concept most RTS obligations cascade from, definition, identification methodology and worked examples

Practitioner tools for DORA compliance teams

Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.

academy-bundle

DORA Certifications Bundle

399 € excl. VAT
academy

DORA for IT & Security Teams

199 € excl. VAT
academy

DORA for ICT Providers & Vendors

199 € excl. VAT
151
certificates issued
93
certified professionals
21
programmes awarded

Browse the full library · Excel toolkits · Certifications

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join the Webinar Waiting List