DORA
What is DORA?
The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, establishing uniform requirements for the security of network and information systems of EU financial entities and critical ICT third-party providers. Covers ICT risk management (governance, framework, identification, protection, detection, response/recovery, backup, learning), ICT-related incident management and major-incident reporting to competent authorities, digital operational resilience testing (including threat-led penetration testing), ICT third-party risk management (Register of Information, key contractual provisions, concentration risk) with a Union Oversight Framework for critical ICT third-party providers, and cyber threat information sharing. It comprises 26 controls organised across 5 domains, and applies in the European Union.
How DORA maps to other frameworks
All 26 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 5 domains DORA groups its controls into
Where DORA overlaps with the standards you already hold
Analysis of DORA
Training that covers DORA
What DORA means in your sector
What DORA means for your job
Questions people ask about DORA
What is DORA?
How many controls does DORA have?
Where does DORA apply?
What frameworks does DORA map to?
How do I get started with DORA compliance?
Query DORA programmatically
DORA, its 26 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
DORA API reference and MCP config →What DORA requires, control by control
Each page carries the requirement text for one DORA control and what an assessor expects to see as evidence.
- DORA-ART-10 Detection
- DORA-ART-11 Response and recovery
- DORA-ART-12 Backup policies and procedures, restoration and recovery
- DORA-ART-13 Learning and evolving
- DORA-ART-14 Communication
- DORA-ART-16 Simplified ICT risk management framework
- DORA-ART-17 ICT-related incident management process
- DORA-ART-18 Classification of ICT-related incidents and cyber threats
- DORA-ART-19 Reporting of major ICT-related incidents
- DORA-ART-23 Operational or security payment-related incidents
How much of another standard DORA already covers
Each crosswalk is judged control by control, and the mappings that were rejected are kept alongside the ones that held.
- DORA to APRA CPS 230 Operational Risk Management crosswalk
- DORA to C5 (Germany) crosswalk
- DORA to CFTC System Safeguards (17 CFR 37, 38, 39, 49) crosswalk
- CIS Controls v8 to DORA crosswalk
- Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 to DORA crosswalk
- DORA to FedRAMP Moderate crosswalk
- DORA to ISO 27001:2022 crosswalk
- DORA to ISO 27002:2022 crosswalk
How ready are you for DORA?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.