Skip to content

DORA

DORA across all five pillars on one data model

ICT risk management, incident classification, resilience testing, ICT third-party register and information sharing: all five pillars run in the same workspace as your BCMS, ISMS and DSMS. A BC exercise also serves as Pillar 3 evidence, and an ISMS access control already counts toward Pillar 1.

DORA pillars covered
5
Major incident reporting window
4h
Financial entity types in scope
20+

One control, several standards

Do the work once, satisfy it everywhere

Standards overlap far more than they differ. A control entered once is mapped to every framework whose requirement it answers, so the second audit inherits the evidence from the first.

One control, entered once, satisfies a requirement in each of the standards listed below.

One control

Supplier & third-party due diligence

  • DORARequirement satisfied
  • ISO 27001Requirement satisfied
  • ISO 22301Requirement satisfied
  • NIS2Requirement satisfied
  • GDPRRequirement satisfied

From control to policy

Where a control ends up

A control is not a line in a register. It belongs to a management system, and it is carried by the policies and procedures your people actually read, so it flows through both.

One control feeds the four management systems, which in turn carry it into the policies and procedures listed below.

One control

Supplier & third-party due diligence

Management systems

  • BCMSBusiness continuity
  • ISMSInformation security
  • DSMSData protection
  • AIMSAI governance

Policies and procedures

  • Information security policy
  • Supplier policy
  • Continuity plan

What changes for your team

01

ICT risk framework with accountable owners

DORA requires financial entities to maintain a comprehensive ICT risk management framework under Article 6. KaitoSec provides a pre-built framework template aligned with the regulatory technical standards of the European Supervisory Authorities, covering identification, protection, detection, response, and recovery.

02

Third-party ICT risk management

DORA places strict obligations on the management of ICT third-party providers, including mandatory contractual provisions and concentration risk assessment. KaitoSec tracks all ICT providers, their criticality classification, and contract compliance status in one register.

03

Incident classification and reporting

Represent the classification criteria, approvals and notification steps relevant to your scope. KaitoSec prepares the assessment and reporting data; accountable professionals confirm them.

The workflow

01

Track progress per pillar

Track implementation progress across all five DORA pillars: ICT risk management, incident management, digital operational resilience testing, ICT third-party risk, and information sharing. Each pillar shows completion percentage, open gaps, and upcoming deadlines.

02

TLPT Orchestration

Threat-Led Penetration Testing (TLPT) is required for significant financial entities on a three-year cycle. KaitoSec manages the TLPT lifecycle from planning through coordination to remediation tracking, and keeps the documentation ready for supervisory review. The remaining Pillar 3 resilience tests are planned, documented and linked to your BC plans and recovery strategies in exercise management.

03

Maintain the Article 28 register of information

Maintain the register of information on all contractual arrangements with ICT third-party providers required under DORA Article 28. KaitoSec tracks provider criticality, contractual provisions, concentration risk, and sub-outsourcing chains, and generates the register in the format required by the European Supervisory Authorities.

04

Business continuity and recovery planning

DORA requires financial entities to maintain ICT business continuity and recovery plans as part of their ICT risk management framework. KaitoSec connects your DORA obligations with structured BIA workflows, recovery strategy documentation, and testable BC plans. Link recovery targets to critical ICT services, document your strategies, and demonstrate compliance.

FAQ

Who is subject to DORA?

DORA applies to a wide range of EU financial entities including credit institutions, payment institutions, investment firms, insurance companies, crypto-asset service providers, and data reporting service providers. It also applies to critical ICT third-party service providers that serve these entities, including major cloud providers.

What are the five pillars of DORA?

DORA is structured around five pillars: ICT risk management (Articles 5–16), ICT incident management and reporting (Articles 17–23), digital operational resilience testing (Articles 24–27), ICT third-party risk management (Articles 28–44), and information and intelligence sharing (Article 45). KaitoSec provides dedicated workspaces for each pillar. ICT business continuity under Pillar 1 draws on the same BIA and BCMS methodology that underpins ISO 22301.

What is the major ICT incident reporting timeline under DORA?

Applicable deadlines depend on classification, competent authority and current technical standards. KaitoSec keeps configured deadlines and prepared reporting data with the incident; the accountable function confirms classification and submission.

How does DORA relate to NIS2?

NIS2 covers cybersecurity broadly across critical sectors, while DORA is a sector-specific regulation for financial services that goes into greater depth on ICT resilience, third-party risk, and resilience testing. Where a financial entity falls under both, DORA generally takes precedence for ICT risk matters. KaitoSec maintains a cross-mapping to avoid duplicating compliance work. That is the same implement-once argument behind resilience made easy.

What is Threat-Led Penetration Testing (TLPT) under DORA?

TLPT is an advanced, intelligence-led penetration testing methodology required for significant financial entities under DORA Article 26. Unlike standard penetration testing, TLPT simulates the tactics of sophisticated real-world adversaries against your live production systems. It must be conducted every three years using accredited testers and follows the TIBER-EU framework.