DORA · Digital Operational Resilience Act

ICT resilience is
now a regulatory
requirement.

Since January 2025, DORA applies to all EU-regulated financial entities — including CASP licence holders. It mandates ICT risk management, incident reporting, and TLPT penetration testing. Non-compliance blocks your licence.

10w
Audit-ready in ~10 weeks

Our structured package delivers full DORA compliance documentation in a defined timeline.

5
ICT pillars

Risk management, incident classification, resilience testing, third-party risk, and information sharing.

100%
Regulator-aligned

All documentation follows EBA/ESMA guidelines and regulator review criteria.

ICT risk framework

What must a DORA ICT risk management framework contain?

DORA requires a formal ICT risk management framework: an asset register, threat taxonomy, control library, and documented risk appetite. We build this from scratch or audit what you have.

01

ICT asset register

Identification and classification of all critical ICT assets, systems, and data — the foundation of your DORA framework.

02

Threat & vulnerability assessment

Structured analysis of ICT risks, mapped to your business functions and DORA's classification requirements.

03

Control library & gap analysis

Review of existing controls against DORA requirements — identifying gaps and prioritising remediation.

04

ICT business continuity plan

Documented BCP and DRP aligned to DORA's recovery time and recovery point objectives.

Incident handling & TLPT

How do CASPs report ICT incidents and run TLPT under DORA?

DORA defines strict timelines for ICT incident classification and reporting to regulators. TLPT (Threat-Led Penetration Testing) is mandatory for larger CASPs. We prepare and manage both.

01

Incident classification framework

Criteria and workflows for classifying ICT incidents as major or minor under DORA's taxonomy — with escalation paths and internal notification procedures.

02

Regulator notification procedures

Templates and processes for the three DORA reporting stages: initial notification (4 hours), intermediate (72 hours), and final report (1 month).

03

TLPT readiness & coordination

Scoping the test, selecting a certified TLPT provider, and preparing your team for the red-team exercise that regulators require for larger CASPs.

04

Third-party ICT risk management

Register of critical ICT third-party providers (cloud, custody, payment), contractual requirements review, and concentration risk assessment.

In short

What is DORA compliance, and what does DORA require from CASPs?

DORA compliance means meeting Regulation (EU) 2022/2554, the Digital Operational Resilience Act, which since January 2025 applies to every EU-regulated financial entity, including MiCA CASP licence holders. DORA requires a documented ICT risk management framework, classification and three-stage reporting of ICT incidents to the national regulator (initial notification within 4 hours, intermediate within 72 hours, final report within 1 month), annual resilience testing, with threat-led penetration testing (TLPT) at least every three years for the CASPs regulators designate, a register of critical ICT third-party providers with DORA-compliant contract clauses, and participation in threat-intelligence sharing. Regulators check DORA compliance as part of a CASP application and during ongoing supervision, and non-compliance blocks the licence. Protegra delivers the complete DORA audit package — risk register, gap report, ICT security policy, BCP/DRP, incident classification and notification procedures, third-party ICT risk policy — in approximately 10 weeks from kick-off, starting with a discovery phase and a fixed-fee proposal.

PillarDeliverableWhen
ICT Risk ManagementAsset register, threat taxonomy, control library and gap report, documented risk appetite, ICT security policy, BCP/DRPWk 1–2 discovery, Wk 3–4 risk assessment, Wk 5–6 policy drafting
Incident ReportingClassification criteria, escalation matrix and regulator notification templates for the three stages: initial 4 hours, intermediate 72 hours, final report 1 monthWk 7–8
Resilience TestingAnnual basic testing for all CASPs; TLPT scoping and certified provider selection for significant CASPs (generally €30M+ assets under custody or €10M+ daily trading volume)Annual; TLPT only if significant
Third-Party ICT RiskRegister of critical ICT providers (cloud, custody, payment), contract clause review, concentration risk assessment, third-party ICT risk policyWk 5–6
Information SharingParticipation in EU cyber-threat intelligence sharing arrangements — voluntary, but expected by regulators as evidence of maturityVoluntary
DORA Audit PackageAll five pillars as one regulator-ready documentation set, internal walkthrough and management sign-offWk 9–10 handover; ~10 weeks in total

Sources: Regulation (EU) 2022/2554 (DORA) — ICT risk management, incident reporting, resilience testing and third-party ICT risk; delivery stages and timelines as published on this page.

Resilience,
by design.

DORA pillars

What are the five pillars of DORA compliance?

DORA organises ICT obligations into five interdependent pillars. Our compliance package addresses each — delivered as a documented, regulator-ready package.

ICT Risk Management

Governance framework, asset register, threat taxonomy, control library, and documented risk appetite. The foundation pillar.

Incident Reporting

Classification criteria, internal escalation, and three-stage reporting to your national regulator within strict DORA timelines.

Resilience Testing

Annual basic testing for all CASPs. TLPT (red-team exercises) for significant entities — coordinated with certified external providers.

Third-Party ICT Risk

Register of critical vendors, contractual alignment to DORA requirements, and concentration risk analysis for cloud and custody providers.

Information Sharing

Participation in EU cyber-threat intelligence sharing arrangements — voluntary but increasingly expected by regulators as evidence of maturity.

DORA Audit Package

All five pillars delivered as a structured, regulator-ready documentation set — ready for your CASP licence application or annual review.

10-week delivery

How does a CASP become DORA-ready in ~10 weeks?

Wk 1–2

Kick-off & discovery

Structured questionnaire, system inventory, existing documentation review. We map your ICT environment.

Wk 3–4

ICT risk assessment

Asset register, threat analysis, control gap assessment. We produce your risk register and gap report.

Wk 5–6

Policy drafting

ICT security policy, BCP/DRP, incident response plan, third-party ICT risk policy — all to DORA specification.

Wk 7–8

Incident & reporting procedures

Incident classification flowcharts, regulator notification templates, and internal escalation matrix.

Wk 9–10

Review & handover

Internal walkthrough, management sign-off, and delivery of the complete DORA audit package for regulator submission.

FAQ

What do CASPs ask most about DORA compliance?

01Does DORA apply to all CASP licence holders?
Yes. From January 2025, all MiCA-regulated entities — including CASP licence holders — are subject to DORA. Regulators expect to see DORA compliance as part of your CASP application and during ongoing supervision.
02What is TLPT and do I need it?
TLPT (Threat-Led Penetration Testing) is a live red-team exercise against your production systems, conducted by an accredited provider. It is mandatory for "significant" CASPs — generally those with €30M+ in assets under custody or €10M+ in daily trading volume. We assess your classification and manage the process if required.
03Can I use cloud providers (AWS, GCP, Azure) under DORA?
Yes, but cloud providers are classified as "critical ICT third-party providers" under DORA. Your contracts must include specific DORA-compliant clauses, and you must maintain a register of critical vendors with concentration risk analysis. We review your contracts and prepare the required documentation.
04How long does DORA compliance take?
Our structured package delivers audit-ready DORA documentation in approximately 10 weeks from kick-off. The timeline depends on the complexity of your ICT environment and how much existing documentation you have. We start with a discovery phase to scope the work accurately.
Get started

Get DORA-ready in 10 weeks.

Leave your details — we'll review your ICT environment scope and reply within 24 hours with a project plan and fixed-fee proposal.

Blog

Latest news from Protegra