DORA compliance, chapter by chapter, article by article.
DORA — Regulation (EU) 2022/2554 — governs digital operational resilience for the EU financial sector: ICT risk management, incident reporting, resilience testing including threat-led penetration testing, ICT third-party risk, and information sharing. grComply seeds all five chapters down to specific Articles, with a real ICT third-party register, board-approval evidence for governance requirements, and hybrid or private on-prem deployment for institutions concerned about cloud concentration risk — DORA's own regulatory concern.
What is DORA? DORA (the Digital Operational Resilience Act, Regulation (EU) 2022/2554) is EU law requiring financial entities — and their critical ICT third-party providers — to manage ICT risk, report major incidents, test digital operational resilience, and oversee third-party ICT concentration risk, applicable across the EU financial sector from January 2025.
How grComply benefits your DORA programme
All five chapters mapped to the regulation's own structure
Chapter II–VI (ICT risk, incident reporting, resilience testing, third-party risk, information sharing), seeded down to specific Articles.
ICT third-party register is a real inventory, not a spreadsheet
The Article 28-3 register of contractual arrangements lives as trackable, versioned evidence.
Threat-led penetration testing evidence has a home
TLPT summaries and remediation status attach directly to Article 26, distinct from routine vulnerability scanning.
Major-incident reporting ties to the same incident model
Article 19 reporting uses the same structured incident process as any other framework — no separate DORA-only workflow to maintain.
Management-body approval is a first-class evidence type
Board-approval evidence exists as its own category, matching DORA's explicit governance-accountability requirement.
Hybrid or private on-prem for concentration-risk concerns
Deployment flexibility matches DORA's own regulatory concern about over-reliance on a small number of cloud providers.
Five chapters, seeded to the regulation's own Article structure
Seeded directly from Regulation (EU) 2022/2554's own chapter and Article numbering — a mapping to ISO 27001 or NIST CSF reads naturally for a client already holding one of those.
Chapter II — ICT risk management (Art. 5–16)
Governance and organisation of the ICT risk framework, identification of ICT-supported business functions and assets, protection and prevention, detection of anomalous activity, response and recovery, backup policies, and post-incident learning.
Chapter III — Incident management, classification and reporting (Art. 17–23)
The ICT-related incident management process, classification of incidents and cyber threats, and reporting of major incidents to competent authorities.
Chapter IV — Digital operational resilience testing (Art. 24–27)
General testing-programme requirements, testing of ICT tools and systems, and advanced testing via threat-led penetration testing (TLPT).
Chapter V — Managing ICT third-party risk (Art. 28–44)
General principles for third-party ICT risk, the required register of contractual arrangements, and key contractual provisions for ICT service agreements.
Chapter VI — Information and intelligence sharing (Art. 45)
Arrangements for sharing cyber threat information and intelligence across the financial sector.
Evidence grComply already models for DORA
Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.
| Control | Evidence type | Example |
|---|---|---|
| Art. 5 — ICT risk framework governance | Board approval | Management body approval of the ICT risk management framework |
| Art. 19 — Major-incident reporting | Attestation | Major-incident report submitted to the competent authority, or template |
| Art. 26 — Threat-led penetration testing | Attestation | TLPT summary and remediation status |
| Art. 28-3 — Third-party register | Inventory document | Register of information on ICT third-party contractual arrangements |
| Art. 30 — Contractual provisions | Contract document | ICT service agreement with the required contractual provisions |
Why this matters: DORA deliberately mirrors ISO 27001 and NIST CSF's structure so a financial entity already holding one of those isn't starting from zero — grComply's cross-framework mapping is what actually realises that intent, crediting shared evidence rather than leaving the resemblance purely conceptual.
DORA, in the live workspace
The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to DORA.






DORA in grComply
What is DORA?
DORA is Regulation (EU) 2022/2554, requiring EU financial entities and their critical ICT providers to manage ICT risk, report major incidents, test digital operational resilience, and oversee third-party concentration risk, applicable from January 2025.
Who needs to comply with DORA?
EU financial entities — banks, insurers, investment firms, payment institutions, and others — plus critical ICT third-party providers designated under the regulation's oversight framework.
Does grComply support the full DORA chapter structure?
Yes — all five chapters are seeded down to specific Articles: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing.
What is the ICT third-party register, and does grComply track it?
Article 28-3 requires a register of information on all contractual arrangements with ICT providers — grComply models this as a trackable, versioned inventory rather than a static spreadsheet maintained outside the platform.
How is threat-led penetration testing different from routine scanning?
TLPT (Article 26) is an advanced, intelligence-led testing exercise distinct from grComply's routine external/internal vulnerability scanning — its summary and remediation status attach to their own DORA-26 control, separate from ordinary scan findings.
Does DORA cross-map to ISO 27001 or NIST CSF?
Yes — DORA's chapter structure was deliberately written to mirror those frameworks, and grComply's cross-framework mapping lets equivalent controls (like incident detection or backup/recovery) credit both.
Can DORA run on-premise or hybrid?
Yes — hybrid or private on-prem deployment is available for institutions concerned about ICT concentration risk, which is itself one of DORA's core regulatory concerns.
What counts as a major ICT-related incident under DORA?
Classification follows Article 18's criteria; grComply's incident-classification control (DORA-18) documents the policy and severity thresholds used to make that determination consistently. See the full catalog on the Compliance Frameworks page.
See DORA mapped into your control library
Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →
Talk to us about DORA
Tell us where your DORA programme stands today, and we'll route it to the right product specialist.
- A product specialist replies personally — not a bot
- No obligation after the first conversation
- WhatsApp support also available 24/7
By submitting, you agree to be contacted about your enquiry. We respect your privacy.
Book a meeting directly
Pick a time that works for you — 30 minutes with a product specialist, no sales script.
Ready to bring DORA into one control library?
We respond within one working day — or reach us instantly on WhatsApp.