DORA Regulation (EU) 2022/2554

EU regulation on digital operational resilience for the financial sector. Banks, insurers, investment firms, payment institutions and their critical ICT providers.

4 controls supported. References are articles of the regulation.

Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

  • Control
    • art.11Response and recovery
    • art.12Backup
    How we help
    A geographically separate recovery site with tested switchover supports your ICT response and recovery plans.
    Evidence you get
    RPO/RTO statement, switchover test reports, site and provider details for your ICT third-party register.
  • Mapping under review

    Control
    • art.12Backup
    How we help
    Backups held apart from your production systems and protected from change, with documented restoration procedures.
    Evidence you get
    Backup policy settings, retention configuration, restore test records.
  • Mapping under review

    Control
    • art.11Response and recovery
    How we help
    Switches traffic to a secondary service automatically and, on the Enterprise plan, keeps critical domains resolvable through the failure of a single DNS provider, supporting the response and recovery arrangements DORA asks for.
    Evidence you get
    DNS architecture description, failover configuration, failover event history.
  • Mapping under review

    Control
    • art.10Detection
    How we help
    Edge logs and security events feed the mechanisms that detect anomalous activity.
    Evidence you get
    Log inventory, alerting rules, retention settings.
  • Mapping under review

    Control
    • art.9Protection and prevention
    How we help
    Protection and prevention controls at the edge for your customer-facing services.
    Evidence you get
    Security configuration export and threat reports.
  • Control
    • art.9Protection and prevention
    How we help
    Strong authentication and least-privilege access to ICT systems.
    Evidence you get
    Access policy export and access logs.

Tell us what you are preparing for

We reply with the controls we can cover, what stays on your side, and a realistic timeline.

Where are you now?