Skip to content

DORA

Digitally resilient under DORA

DORA requires financial organisations to run a coherent ICT risk management framework, including oversight of critical ICT suppliers.

Book an introductory call
  • Risk management
  • Business continuity

When DORA applies to your organisation

DORA has applied since 17 January 2025 to banks, insurers, investment firms, payment institutions and similar financial entities.

The regulation also sets requirements for critical ICT suppliers to these organisations, not just the organisations themselves.

  • Your organisation operates in the financial sector or provides critical ICT services to it

  • There is no complete register of ICT third parties yet

  • A regulator or client asks about your DORA compliance

What insufficient ICT risk management risks

Insufficient ICT risk management can lead to enforcement by regulators such as DNB or AFM.

An outage at a critical ICT supplier can directly affect service to your customers, with reputational damage as a result.

What the law asks of your ICT risk management

DORA requires an ICT risk management framework, a register of ICT third parties, incident reporting, and periodic digital resilience testing.

  • An ICT risk management framework, approved by management

  • A register of all ICT third parties and key contractual arrangements

  • Reporting obligations for major ICT incidents

  • Periodic digital resilience testing, including threat-led penetration testing for significant entities

  • Arrangements for sharing cyber threat information

From supplier register to tested resilience

Vedeum maps your ICT risks and suppliers and helps set up a risk management framework aligned with DORA.

  1. Baseline assessment

    We map the current situation against DORA.

  2. Supplier register

    We help set up a register of ICT third parties and key contracts.

  3. Implementation

    We help set up the ICT risk management framework and incident response.

  4. Testing & embedding

    We support digital resilience testing and periodic review.

Book a no-obligation introductory call

Tell us where your organisation stands. We will think through the first steps with you.

Book an introductory call