---
title: "DORA: controls supported by Noraina"
description: "Which DORA controls Noraina's infrastructure, backup and Cloudflare services support, how, and what evidence you get for the audit."
url: https://www.noraina.cloud/compliance/dora/
language: en
---
# DORA: controls supported by Noraina

Banks, insurers, investment firms, payment institutions and their critical ICT providers.

> Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

## DORA Regulation (EU) 2022/2554

EU regulation on digital operational resilience for the financial sector. References are articles of the regulation.

4 controls supported.

### Efficient Cloud Instances with replication

- Control: art.11 (Response and recovery); art.12 (Backup)
- How we help: A geographically separate recovery site with tested switchover supports your ICT response and recovery plans.
- Evidence you get: RPO/RTO statement, switchover test reports, site and provider details for your ICT third-party register.
- Status: Mapping under review

### Efficient Cloud Backup

- Control: art.12 (Backup)
- How we help: Backups held apart from your production systems and protected from change, with documented restoration procedures.
- Evidence you get: Backup policy settings, retention configuration, restore test records.
- Status: Mapping under review

### Efficient Cloud DNS (NorainaDNS)

- Control: art.11 (Response and recovery)
- How we help: Switches traffic to a secondary service automatically and, on the Enterprise plan, keeps critical domains resolvable through the failure of a single DNS provider, supporting the response and recovery arrangements DORA asks for.
- Evidence you get: DNS architecture description, failover configuration, failover event history.
- Status: Mapping under review

### Complete edge logging

- Control: art.10 (Detection)
- How we help: Edge logs and security events feed the mechanisms that detect anomalous activity.
- Evidence you get: Log inventory, alerting rules, retention settings.
- Status: Mapping under review

### Application and DDoS protection

- Control: art.9 (Protection and prevention)
- How we help: Protection and prevention controls at the edge for your customer-facing services.
- Evidence you get: Security configuration export and threat reports.
- Status: Mapping under review

### Zero Trust access and data protection

- Control: art.9 (Protection and prevention)
- How we help: Strong authentication and least-privilege access to ICT systems.
- Evidence you get: Access policy export and access logs.
- Status: Mapping under review


We reply with the controls we can cover, what stays on your side, and a realistic timeline. https://www.noraina.cloud/compliance/dora/#assessment
