DORA, with your ICT suppliers in view.
DORA makes operational resilience, and the ICT providers behind it, a regulated obligation for EU financial entities. TruOps connects the two.
Mappings are typed exact, partial, or inferred, each with a citation.
The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, has applied since 17 January 2025 to most EU financial entities, including banks, insurers, investment firms, and payment institutions. It sets requirements in five areas: ICT risk management, ICT-related incident reporting, digital operational resilience testing, ICT third-party risk management (including a register of information), and information sharing.
- You are an EU financial entity and the register of information is still a spreadsheet
- ICT third parties are concentrated and you cannot show it
- DORA, NIS2, and ISO overlap and are being answered three times
- Instrument
- Regulation (EU) 2022/2554
- Applies from
- 17 January 2025
- Applies to
- EU financial entities and critical ICT third-party providers
- Pillars
- ICT risk · incidents · testing · third parties · information sharing
The five pillars
| Area | What it requires |
|---|---|
| ICT risk management | A documented framework, with management-body accountability |
| Incident reporting | Classification of ICT incidents and reporting of major ones to authorities |
| Resilience testing | A testing program; threat-led penetration testing for significant entities |
| ICT third-party risk | Contract requirements, exit strategies, and a register of information on ICT providers |
| Information sharing | Voluntary sharing of cyber threat information |
The actual challenge
DORA's hard part is not the ICT risk policy. It is knowing every ICT third party, what they do, how concentrated you are, and whether their contracts and tests match the rule.
- The register of information is a reporting artifact, disconnected from actual vendor oversight.
- Incident classification and testing evidence live in other teams' tools.
- Critical ICT providers are also in the TPRM queue, assessed with a generic SIG.
Bring one real document. Watch the program get set up from it.
What you are probably using today
Almost nobody starts DORA from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.
| What you use now | Where it breaks | With TruOps |
|---|---|---|
| Spreadsheets, shared drives, and email | The program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter. | Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period. |
| SOC 2 automation tools | They are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model. | Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have. |
| Enterprise GRC suites | They can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project. | AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project. |
| A register-of-information spreadsheet | It is filled for the filing and drifts immediately. Concentration is a guess. | Vendors, tiers, assessments, and findings sit in one place, and concentration is visible from the same data. |
Third parties are the hard part
DORA requires a register of information covering contractual arrangements with ICT third-party service providers and assessments of concentration risk. TruOps keeps vendors, their tiers, their assessments, and their findings in one place, and flags when too much depends on one provider.
How TruOps helps with DORA
Pick DORA as your anchor, or map it to the framework you already run. TruOps keeps DORA's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.
Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your DORA assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.
If this is your situation
Bring your ICT vendor list and current register. TruOps runs DORA requirements on the same engine as vendor oversight, so the filing and the program are the same records.
How TruOps helps
- Anchor or map
- Run DORA as your spine or map it to another framework; work counts once.
- Pre-filled assessment
- Your DORA assessment opens with the answers your evidence supports already filled, each cited.
- Honest coverage
- Partial coverage is reported as partial, with the remaining requirements listed.
- Continuous monitoring
- Technical controls checked against your tools hourly to quarterly.
- Findings with fixes
- Failed checks become grouped findings with a recommended action.
- Audit-ready snapshots
- Results saved as of their date, with the evidence trail attached.
Questions
When did DORA start to apply?
17 January 2025.
Who does DORA apply to?
Most EU financial entities, including credit institutions, payment and e-money institutions, investment firms, insurers, and crypto-asset service providers, plus oversight of critical ICT third-party providers.
What is the DORA register of information?
A register of all contractual arrangements with ICT third-party service providers, maintained by financial entities and reported to authorities.
How does DORA relate to NIS2?
DORA is sector-specific legislation for finance; where it applies, it takes precedence over the corresponding NIS2 obligations.
Do we have to rip out the tools we already use?
No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.
Can we bring our existing assessments, control lists, and vendor files?
Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.
Does TruOps replace our auditor, QSA, or certification body?
No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.
Related
EU cybersecurity obligations for essential and important entities.
→IndustriesFinancial servicesOverlapping regimes, heavy vendor oversight, and examiners who want proof.
→IndustriesBankingExaminer-ready programs, third-party oversight, and cyber maturity.
→Use casesVendor risk assessmentsTier, assess, and check vendors without drowning in questionnaires.
→LearnThird-party risk managementTPRM: managing the risks vendors bring.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.