Operational resilience

DORA readiness

ICT risk management, resilience testing and third-party risk frameworks aligned with the Digital Operational Resilience Act | built for CASPs and financial entities operating in the EU.

What it is

What does DORA actually require?

The Digital Operational Resilience Act sets binding rules for how EU financial entities | including CASPs authorised under MiCA | manage ICT risk, report major incidents, test operational resilience, and oversee critical third-party technology providers. For most digital asset businesses, this means formalising controls that may currently exist informally: vendor risk assessment, incident classification, and resilience testing all need documented, repeatable processes.

Packages

Choose the level of support you need

Assessment

Gap Analysis

A review of your current ICT risk and vendor management practices against DORA requirements.

Get started
  • ICT risk framework gap review
  • Critical third-party mapping
  • Full framework build
  • Resilience testing plan
  • Incident reporting procedure

Build + Maintain

Managed DORA Programme

Full framework plus ongoing maintenance as vendors, systems and guidance evolve.

Get started
  • Everything in Full Framework
  • Annual resilience testing coordination
  • Vendor register maintenance
  • Regulatory guidance monitoring

In detail

What's inside the service

ICT risk management framework

Governance, roles and controls for identifying, protecting against and responding to ICT risk.

Critical third-party register

A documented register of critical ICT providers with risk assessments and contractual review.

Incident classification & reporting

Clear thresholds and procedures for classifying and reporting major ICT-related incidents.

Resilience testing plan

A testing programme scaled to your risk profile, from basic vulnerability assessments to advanced testing where required.

Governance alignment

DORA documentation coordinated with your AML/CTF and licensing governance so the two don't contradict each other.

Ongoing maintenance

A framework that gets reviewed as vendors, systems and regulatory guidance change.

FAQ

Frequently asked questions

Who does DORA apply to?+

DORA applies to a broad range of EU financial entities, including CASPs authorised under MiCA, as well as critical ICT third-party providers serving those entities.

What is the core deliverable of DORA readiness work?+

An ICT risk management framework, a register of critical third-party providers with associated risk assessments, an incident classification and reporting procedure, and a resilience testing plan.

How does DORA readiness relate to our AML/KYC programme?+

They're separate frameworks but should be governed consistently. We coordinate DORA and AML/CTF documentation so incident reporting, vendor risk and governance don't contradict each other across the two programmes.

Ready when you are

Let's assess your DORA readiness