CloudSignLab

DORA Regulation (EU) 2022/2554

Digital operational resilience for financial entities

DORA applies since 17 January 2025 to banks, insurers, investment firms, payment institutions and other financial entities. CloudSignLab links your controls to the DORA articles, keeps the register of information for your ICT providers and tracks incidents and continuity tests.

Digital operational resilience for financial entities

What DORA asks of you

  • ICT risk management (Articles 5 to 16)

    A documented framework to identify, protect, detect, respond and recover, approved and overseen by the management body.

  • ICT incident management and reporting (Articles 17 to 23)

    Classify ICT-related incidents and report major ones to the competent authority with initial, intermediate and final reports.

  • Resilience testing (Articles 24 to 27)

    A testing programme for ICT tools and systems, and threat-led penetration testing for the entities chosen by the authorities.

  • ICT third-party risk (Articles 28 to 30)

    A strategy for ICT third-party risk, contract requirements and a register of information on all contracts with ICT providers.

How CloudSignLab helps

  • DORA readiness from your controls

    Link controls to DORA articles 5 to 30 and 45 and see which requirements are covered and where evidence is missing.

  • Register of information

    Record the DORA fields of your ICT providers, such as LEI, ICT service and support of a critical or important function, and export the core of the register.

  • Incidents and continuity

    An incident register with deadlines, business continuity plans with recovery times, and the exercises that test them.

  • Supplier checks

    Send security questionnaires to ICT providers, score the answers and record decisions and the next review.

Read the guide to DORA and more frameworks →

Questions about DORA

Does DORA replace NIS2 for financial entities?

For the financial entities it covers, DORA is the specific rule for ICT risk; it takes precedence over the matching NIS2 obligations. Many groups still handle both, and CloudSignLab can track both on the same controls.

Can CloudSignLab file reports with the authority?

No. CloudSignLab helps you prepare: it keeps the register of information, the incident details and deadlines. Submitting reports stays with your entity, through the channel of your authority.

Bring DORA into one place

Start free and add your ICT providers to the register of information today.

Start free