⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply framework · EU financial-sector resilience regulation

DORA compliance, chapter by chapter, article by article.

DORA — Regulation (EU) 2022/2554 — governs digital operational resilience for the EU financial sector: ICT risk management, incident reporting, resilience testing including threat-led penetration testing, ICT third-party risk, and information sharing. grComply seeds all five chapters down to specific Articles, with a real ICT third-party register, board-approval evidence for governance requirements, and hybrid or private on-prem deployment for institutions concerned about cloud concentration risk — DORA's own regulatory concern.

5 Chapters · Articles 5–45 — including a real ICT third-party provider register.
Back to all frameworks WhatsApp us
5Chapters seeded
EUJurisdiction
2025DORA application date
StructuralSeed depth

What is DORA? DORA (the Digital Operational Resilience Act, Regulation (EU) 2022/2554) is EU law requiring financial entities — and their critical ICT third-party providers — to manage ICT risk, report major incidents, test digital operational resilience, and oversee third-party ICT concentration risk, applicable across the EU financial sector from January 2025.

Why it's different

How grComply benefits your DORA programme

All five chapters mapped to the regulation's own structure

Chapter II–VI (ICT risk, incident reporting, resilience testing, third-party risk, information sharing), seeded down to specific Articles.

ICT third-party register is a real inventory, not a spreadsheet

The Article 28-3 register of contractual arrangements lives as trackable, versioned evidence.

Threat-led penetration testing evidence has a home

TLPT summaries and remediation status attach directly to Article 26, distinct from routine vulnerability scanning.

Major-incident reporting ties to the same incident model

Article 19 reporting uses the same structured incident process as any other framework — no separate DORA-only workflow to maintain.

Management-body approval is a first-class evidence type

Board-approval evidence exists as its own category, matching DORA's explicit governance-accountability requirement.

Hybrid or private on-prem for concentration-risk concerns

Deployment flexibility matches DORA's own regulatory concern about over-reliance on a small number of cloud providers.

Structure

Five chapters, seeded to the regulation's own Article structure

Seeded directly from Regulation (EU) 2022/2554's own chapter and Article numbering — a mapping to ISO 27001 or NIST CSF reads naturally for a client already holding one of those.

Chapter II — ICT risk management (Art. 5–16)

Governance and organisation of the ICT risk framework, identification of ICT-supported business functions and assets, protection and prevention, detection of anomalous activity, response and recovery, backup policies, and post-incident learning.

Chapter III — Incident management, classification and reporting (Art. 17–23)

The ICT-related incident management process, classification of incidents and cyber threats, and reporting of major incidents to competent authorities.

Chapter IV — Digital operational resilience testing (Art. 24–27)

General testing-programme requirements, testing of ICT tools and systems, and advanced testing via threat-led penetration testing (TLPT).

Chapter V — Managing ICT third-party risk (Art. 28–44)

General principles for third-party ICT risk, the required register of contractual arrangements, and key contractual provisions for ICT service agreements.

Chapter VI — Information and intelligence sharing (Art. 45)

Arrangements for sharing cyber threat information and intelligence across the financial sector.

Evidence, mapped

Evidence grComply already models for DORA

Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.

ControlEvidence typeExample
Art. 5 — ICT risk framework governanceBoard approvalManagement body approval of the ICT risk management framework
Art. 19 — Major-incident reportingAttestationMajor-incident report submitted to the competent authority, or template
Art. 26 — Threat-led penetration testingAttestationTLPT summary and remediation status
Art. 28-3 — Third-party registerInventory documentRegister of information on ICT third-party contractual arrangements
Art. 30 — Contractual provisionsContract documentICT service agreement with the required contractual provisions

Why this matters: DORA deliberately mirrors ISO 27001 and NIST CSF's structure so a financial entity already holding one of those isn't starting from zero — grComply's cross-framework mapping is what actually realises that intent, crediting shared evidence rather than leaving the resemblance purely conceptual.

Product screens

DORA, in the live workspace

The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to DORA.

FAQ

DORA in grComply

What is DORA?

DORA is Regulation (EU) 2022/2554, requiring EU financial entities and their critical ICT providers to manage ICT risk, report major incidents, test digital operational resilience, and oversee third-party concentration risk, applicable from January 2025.

Who needs to comply with DORA?

EU financial entities — banks, insurers, investment firms, payment institutions, and others — plus critical ICT third-party providers designated under the regulation's oversight framework.

Does grComply support the full DORA chapter structure?

Yes — all five chapters are seeded down to specific Articles: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing.

What is the ICT third-party register, and does grComply track it?

Article 28-3 requires a register of information on all contractual arrangements with ICT providers — grComply models this as a trackable, versioned inventory rather than a static spreadsheet maintained outside the platform.

How is threat-led penetration testing different from routine scanning?

TLPT (Article 26) is an advanced, intelligence-led testing exercise distinct from grComply's routine external/internal vulnerability scanning — its summary and remediation status attach to their own DORA-26 control, separate from ordinary scan findings.

Does DORA cross-map to ISO 27001 or NIST CSF?

Yes — DORA's chapter structure was deliberately written to mirror those frameworks, and grComply's cross-framework mapping lets equivalent controls (like incident detection or backup/recovery) credit both.

Can DORA run on-premise or hybrid?

Yes — hybrid or private on-prem deployment is available for institutions concerned about ICT concentration risk, which is itself one of DORA's core regulatory concerns.

What counts as a major ICT-related incident under DORA?

Classification follows Article 18's criteria; grComply's incident-classification control (DORA-18) documents the policy and severity thresholds used to make that determination consistently. See the full catalog on the Compliance Frameworks page.

See DORA mapped into your control library

Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →

Get in touch

Talk to us about DORA

Tell us where your DORA programme stands today, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to bring DORA into one control library?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us