Skip to content
← All guidesDORA

DORA Compliance Guides

Digital Operational Resilience Act compliance for banks, fintechs, and payment firms — in force since January 2025.

DORA Compliance Checklist for Fintechs

DORA — the Digital Operational Resilience Act — has applied to financial entities in the EU since 17 January 2025.

3 min read

DORA ICT Third-Party Risk Management Explained

ICT third-party risk management is one of the most operationally demanding aspects of DORA.

4 min read

DORA Incident Reporting Requirements

DORA introduces the strictest incident reporting timelines of any EU regulation — stricter than NIS2 and stricter than GDPR.

4 min read

Operational Resilience Testing Under DORA

DORA mandates digital operational resilience testing for all financial entities.

4 min read

DORA for SaaS Vendors Selling to Banks

SaaS companies selling to banks, payment institutions, and other financial entities are not DORA entities themselves — but DORA's third-party risk requiremen...

4 min read

DORA vs NIS2: Which Applies to Your Company?

DORA and NIS2 both impose cybersecurity requirements on companies operating in the EU.

4 min read

How to Prepare for a DORA Audit

DORA audits are conducted by financial supervisory authorities — EBA, ESMA, EIOPA, and national competent authorities (e.g., ECB, PRA, BaFin, CBI).

4 min read

DORA Contract Clauses Banks Expect from Vendors

DORA Article 30 specifies the minimum contractual provisions that financial entities must include in contracts with ICT third-party service providers.

5 min read

DORA Critical ICT Providers: Designation and Requirements

DORA creates a category of ICT service providers designated as "critical third-party providers" (CTPPs) — subject to direct oversight by EU supervisory autho...

4 min read

DORA Enforcement: What Regulators Are Checking in 2026

DORA became fully applicable on 17 January 2025. One year in, the regulatory focus has shifted from guidance to examination.

4 min read

DORA for Insurtech Companies

Insurtech companies — startups and scale-ups using technology to provide insurance products or services — fall under DORA if they hold EU insurance or reinsu...

4 min read

DORA Register of Information: Template and Guide

The Register of Information (RoI) is one of DORA's most operationally demanding requirements and one of the first things regulators examine.

4 min read

DORA Business Continuity Planning Requirements

DORA Article 11 sets out specific requirements for business continuity policies and plans (BCP) for financial entities.

4 min read

DORA for Cloud Providers: AWS, Azure, GCP Obligations

AWS, Azure, and Google Cloud are not financial entities under DORA — they are ICT third-party service providers to financial entities.

4 min read

How to Map ICT Dependencies for DORA Compliance

ICT dependency mapping is a foundational exercise for DORA compliance.

4 min read

ComplyOne automates your compliance documentation — RoPA, DPAs, gap assessments, and more.

Free compliance check