Who does DORA apply to?+
Banks, insurers, investment firms, payment and crypto-asset service providers, and their critical ICT providers across the EU. DORA is a regulation and applies directly, without national transposition.
Is DORA already in force?+
Yes, it has applied since January 2025. Entities in scope that are not yet aligned are exposed to regulatory risk and should complete the alignment without delay.
What does DORA require around testing?+
ICT risk management, incident reporting, and digital resilience testing, including threat-led penetration testing (TLPT) for significant entities. We run the testing and prepare the evidence.
Does DORA cover our third parties?+
Yes. ICT third-party risk management is one of the regulation's core requirements. We assess the providers your operational risk depends on.