DORA Compliance Guides
Digital Operational Resilience Act compliance for banks, fintechs, and payment firms — in force since January 2025.
DORA Compliance Checklist for Fintechs
DORA — the Digital Operational Resilience Act — has applied to financial entities in the EU since 17 January 2025.
3 min read
DORA ICT Third-Party Risk Management Explained
ICT third-party risk management is one of the most operationally demanding aspects of DORA.
4 min read
DORA Incident Reporting Requirements
DORA introduces the strictest incident reporting timelines of any EU regulation — stricter than NIS2 and stricter than GDPR.
4 min read
Operational Resilience Testing Under DORA
DORA mandates digital operational resilience testing for all financial entities.
4 min read
DORA for SaaS Vendors Selling to Banks
SaaS companies selling to banks, payment institutions, and other financial entities are not DORA entities themselves — but DORA's third-party risk requiremen...
4 min read
DORA vs NIS2: Which Applies to Your Company?
DORA and NIS2 both impose cybersecurity requirements on companies operating in the EU.
4 min read
How to Prepare for a DORA Audit
DORA audits are conducted by financial supervisory authorities — EBA, ESMA, EIOPA, and national competent authorities (e.g., ECB, PRA, BaFin, CBI).
4 min read
DORA Contract Clauses Banks Expect from Vendors
DORA Article 30 specifies the minimum contractual provisions that financial entities must include in contracts with ICT third-party service providers.
5 min read
DORA Critical ICT Providers: Designation and Requirements
DORA creates a category of ICT service providers designated as "critical third-party providers" (CTPPs) — subject to direct oversight by EU supervisory autho...
4 min read
DORA Enforcement: What Regulators Are Checking in 2026
DORA became fully applicable on 17 January 2025. One year in, the regulatory focus has shifted from guidance to examination.
4 min read
DORA for Insurtech Companies
Insurtech companies — startups and scale-ups using technology to provide insurance products or services — fall under DORA if they hold EU insurance or reinsu...
4 min read
DORA Register of Information: Template and Guide
The Register of Information (RoI) is one of DORA's most operationally demanding requirements and one of the first things regulators examine.
4 min read
DORA Business Continuity Planning Requirements
DORA Article 11 sets out specific requirements for business continuity policies and plans (BCP) for financial entities.
4 min read
DORA for Cloud Providers: AWS, Azure, GCP Obligations
AWS, Azure, and Google Cloud are not financial entities under DORA — they are ICT third-party service providers to financial entities.
4 min read
How to Map ICT Dependencies for DORA Compliance
ICT dependency mapping is a foundational exercise for DORA compliance.
4 min read
ComplyOne automates your compliance documentation — RoPA, DPAs, gap assessments, and more.
Free compliance check