Operational resilience
DORA readiness
ICT risk management, resilience testing and third-party risk frameworks aligned with the Digital Operational Resilience Act | built for CASPs and financial entities operating in the EU.
What it is
What does DORA actually require?
The Digital Operational Resilience Act sets binding rules for how EU financial entities | including CASPs authorised under MiCA | manage ICT risk, report major incidents, test operational resilience, and oversee critical third-party technology providers. For most digital asset businesses, this means formalising controls that may currently exist informally: vendor risk assessment, incident classification, and resilience testing all need documented, repeatable processes.
Packages
Choose the level of support you need
Assessment
Gap Analysis
A review of your current ICT risk and vendor management practices against DORA requirements.
Get started- ✓ICT risk framework gap review
- ✓Critical third-party mapping
- ✓Full framework build
- ✓Resilience testing plan
- ✓Incident reporting procedure
Build
Full Framework
Complete ICT risk management framework, vendor register and incident reporting procedure.
Get started- ✓ICT risk management framework
- ✓Critical third-party risk register
- ✓Incident classification & reporting procedure
- ✓Resilience testing plan
- ✓Ongoing framework maintenance
Build + Maintain
Managed DORA Programme
Full framework plus ongoing maintenance as vendors, systems and guidance evolve.
Get started- ✓Everything in Full Framework
- ✓Annual resilience testing coordination
- ✓Vendor register maintenance
- ✓Regulatory guidance monitoring
In detail
What's inside the service
ICT risk management framework
Governance, roles and controls for identifying, protecting against and responding to ICT risk.
Critical third-party register
A documented register of critical ICT providers with risk assessments and contractual review.
Incident classification & reporting
Clear thresholds and procedures for classifying and reporting major ICT-related incidents.
Resilience testing plan
A testing programme scaled to your risk profile, from basic vulnerability assessments to advanced testing where required.
Governance alignment
DORA documentation coordinated with your AML/CTF and licensing governance so the two don't contradict each other.
Ongoing maintenance
A framework that gets reviewed as vendors, systems and regulatory guidance change.
FAQ
Frequently asked questions
Who does DORA apply to?+
DORA applies to a broad range of EU financial entities, including CASPs authorised under MiCA, as well as critical ICT third-party providers serving those entities.
What is the core deliverable of DORA readiness work?+
An ICT risk management framework, a register of critical third-party providers with associated risk assessments, an incident classification and reporting procedure, and a resilience testing plan.
How does DORA readiness relate to our AML/KYC programme?+
They're separate frameworks but should be governed consistently. We coordinate DORA and AML/CTF documentation so incident reporting, vendor risk and governance don't contradict each other across the two programmes.