Who it applies to
▸Banks, insurers, investment firms, and payment and crypto-asset service providers
▸Critical ICT third-party providers serving the financial sector
▸In force across the EU since January 2025
What it requires
The obligations, clearly explained.
01
ICT risk management
A documented framework for identifying, protecting against, detecting, and recovering from ICT risk.
02
Incident reporting
Classification of major ICT incidents and reporting to the competent regulator.
03
Resilience testing
A digital resilience testing program, including threat-led penetration testing (TLPT) for significant entities.
04
Third-party risk
Oversight of ICT providers, including contractual requirements and concentration risk management.
How Raptoric helps
We do the engineering work, not just the documentation.
Threat-led testing
We run TLPT-style engagements that validate resilience against the regulation's requirements.
ICT risk assessment
We assess and document your ICT risk framework against the requirements of DORA.
Resilience testing
We test detection and response in the context of your incident reporting obligations.
Third-party review
We assess the ICT providers your operational risk depends on.
We deliver the testing and the evidence. Compliance is overseen by your national regulator and the European supervisory authorities.
Services that deliver it
FAQ
Questions, answered
Who does DORA apply to?
Banks, insurers, investment firms, payment and crypto-asset service providers, and their critical ICT providers across the EU. DORA is a regulation and applies directly, without national transposition.
Is DORA already in force?
Yes, it has applied since January 2025. Entities in scope that are not yet aligned are exposed to regulatory risk and should complete the alignment without delay.
What does DORA require around testing?
ICT risk management, incident reporting, and digital resilience testing, including threat-led penetration testing (TLPT) for significant entities. We run the testing and prepare the evidence.
Does DORA cover our third parties?
Yes. ICT third-party risk management is one of the regulation's core requirements. We assess the providers your operational risk depends on.
Further reading