ICT resilience is
now a regulatory
requirement.
Since January 2025, DORA applies to all EU-regulated financial entities — including CASP licence holders. It mandates ICT risk management, incident reporting, and TLPT penetration testing. Non-compliance blocks your licence.
Our structured package delivers full DORA compliance documentation in a defined timeline.
Risk management, incident classification, resilience testing, third-party risk, and information sharing.
All documentation follows EBA/ESMA guidelines and regulator review criteria.
What must a DORA ICT risk management framework contain?
DORA requires a formal ICT risk management framework: an asset register, threat taxonomy, control library, and documented risk appetite. We build this from scratch or audit what you have.
ICT asset register
Identification and classification of all critical ICT assets, systems, and data — the foundation of your DORA framework.
Threat & vulnerability assessment
Structured analysis of ICT risks, mapped to your business functions and DORA's classification requirements.
Control library & gap analysis
Review of existing controls against DORA requirements — identifying gaps and prioritising remediation.
ICT business continuity plan
Documented BCP and DRP aligned to DORA's recovery time and recovery point objectives.
How do CASPs report ICT incidents and run TLPT under DORA?
DORA defines strict timelines for ICT incident classification and reporting to regulators. TLPT (Threat-Led Penetration Testing) is mandatory for larger CASPs. We prepare and manage both.
Incident classification framework
Criteria and workflows for classifying ICT incidents as major or minor under DORA's taxonomy — with escalation paths and internal notification procedures.
Regulator notification procedures
Templates and processes for the three DORA reporting stages: initial notification (4 hours), intermediate (72 hours), and final report (1 month).
TLPT readiness & coordination
Scoping the test, selecting a certified TLPT provider, and preparing your team for the red-team exercise that regulators require for larger CASPs.
Third-party ICT risk management
Register of critical ICT third-party providers (cloud, custody, payment), contractual requirements review, and concentration risk assessment.


