DORA — the new digital resilience standard
The Digital Operational Resilience Act (DORA) regulates how financial sector entities manage ICT risk, respond to incidents and oversee suppliers. The regulation is already in force, but adaptation deadlines are approaching fast.
Who is covered?
DORA applies to banks, insurers, investment funds, payment firms, crypto exchanges and their technology providers, including cloud services and data centers.
Compliance checklist
- ICT risk management — comprehensive framework policy and asset register.
- Incident management — classification, escalation and reporting to the regulator.
- Resilience testing — regular penetration and scenario-based tests (TLPT).
- Supplier management — audit of contracts, SLAs and subcontractor access rights.
- Business continuity plan — procedures for restoring critical systems.
How CHORS supports DORA compliance
We help prepare documentation, conduct supplier audits, perform penetration tests and build incident reporting procedures. We work using a methodology that is understandable for both technical teams and management.