Frameworks
DORA — EU Digital Operational Resilience Act
Europe's operational-resilience law for finance — and a direct reach into ICT vendors.
Book a demoDORA, applicable since January 2025, requires EU financial entities to manage ICT risk, report major incidents, test resilience, and govern third-party ICT providers — with critical providers subject to direct EU oversight. If you sell technology to European financial institutions, DORA arrived in your contracts already.
Five pillars, one theme
ICT risk management, incident reporting, resilience testing (up to threat-led penetration testing), third-party risk, and information sharing. The theme is proof: registers of ICT contracts, tested continuity plans, and exit strategies for critical vendors. Financial customers now push DORA-shaped clauses and questionnaires onto every serious tech supplier.
How Compriska helps
Compriska maintains the ICT risk register, tracks resilience testing and incidents with reporting clocks, and manages the third-party register and contractual obligations DORA demands — for financial entities and for the vendors serving them.
Frequently asked questions
We're a SaaS vendor, not a bank — why does DORA matter?
Because your EU financial customers must impose DORA-aligned terms on ICT providers and maintain a register of you. Expect contract addenda, questionnaires, and audit rights — being ready is a sales advantage.
Other frameworks
Automate DORA with Compriska
See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.
Book a demo