Frameworks

DORA — EU Digital Operational Resilience Act

Europe's operational-resilience law for finance — and a direct reach into ICT vendors.

Book a demo

DORA, applicable since January 2025, requires EU financial entities to manage ICT risk, report major incidents, test resilience, and govern third-party ICT providers — with critical providers subject to direct EU oversight. If you sell technology to European financial institutions, DORA arrived in your contracts already.

Five pillars, one theme

ICT risk management, incident reporting, resilience testing (up to threat-led penetration testing), third-party risk, and information sharing. The theme is proof: registers of ICT contracts, tested continuity plans, and exit strategies for critical vendors. Financial customers now push DORA-shaped clauses and questionnaires onto every serious tech supplier.

How Compriska helps

Compriska maintains the ICT risk register, tracks resilience testing and incidents with reporting clocks, and manages the third-party register and contractual obligations DORA demands — for financial entities and for the vendors serving them.

Frequently asked questions

We're a SaaS vendor, not a bank — why does DORA matter?

Because your EU financial customers must impose DORA-aligned terms on ICT providers and maintain a register of you. Expect contract addenda, questionnaires, and audit rights — being ready is a sales advantage.

Other frameworks

Automate DORA with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo