Financial services · DORA · in force since Jan 2025

DORA, governed and evidenced.

The Digital Operational Resilience Act is live and being audited now — the Register of Information first. CSOAI maps all five pillars, crosswalks the ~65% overlap with NIS2, plans your TLPT, and seals the evidence to Layer 0.

Art. 5–16
ICT risk management

Board-owned framework for ICT risk across the financial entity.

Art. 17–23
Incident reporting

Classify + report major ICT-related incidents on strict timelines.

Art. 24–27
Digital operational resilience testing

Regular testing, incl. threat-led penetration testing (TLPT / TIBER-EU).

Art. 28–44
Third-party ICT risk

Manage critical ICT providers; the Register of Information is the audit priority.

Art. 45
Information sharing

Share cyber-threat intelligence across financial entities.

Frequently asked

What is DORA and who does it apply to?

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) sets binding ICT and cyber-resilience rules for banks, insurers, investment firms, crypto-asset service providers and their critical ICT third parties across the EU. It has applied since 17 January 2025.

What is the DORA Register of Information?

The Register of Information (RoI) is a structured record of all contractual arrangements with ICT third-party providers. It is the priority audit target for supervisors in 2026 — several national deadlines have already passed and consolidation at the ESAs is under way.

How do DORA and NIS2 overlap?

DORA and NIS2 overlap by roughly 65% on ICT risk management, incident reporting and third-party risk. For entities in scope of both, mapping the overlap once avoids duplicated controls — exactly what CSOAI's DORA×NIS2 crosswalk does.

How does CSOAI help with DORA compliance?

CSOAI maps DORA to a unified control set, crosswalks it to NIS2 (65% overlap) and the EU AI Act where AI is used in financial services, supports TLPT / TIBER-EU planning, and produces Layer-0 (Ed25519) signed evidence for supervisors.