DORA Regulation (EU) 2022/2554
Digital operational resilience for financial entities
DORA applies since 17 January 2025 to banks, insurers, investment firms, payment institutions and other financial entities. CloudSignLab links your controls to the DORA articles, keeps the register of information for your ICT providers and tracks incidents and continuity tests.

What DORA asks of you
ICT risk management (Articles 5 to 16)
A documented framework to identify, protect, detect, respond and recover, approved and overseen by the management body.
ICT incident management and reporting (Articles 17 to 23)
Classify ICT-related incidents and report major ones to the competent authority with initial, intermediate and final reports.
Resilience testing (Articles 24 to 27)
A testing programme for ICT tools and systems, and threat-led penetration testing for the entities chosen by the authorities.
ICT third-party risk (Articles 28 to 30)
A strategy for ICT third-party risk, contract requirements and a register of information on all contracts with ICT providers.
How CloudSignLab helps
DORA readiness from your controls
Link controls to DORA articles 5 to 30 and 45 and see which requirements are covered and where evidence is missing.
Register of information
Record the DORA fields of your ICT providers, such as LEI, ICT service and support of a critical or important function, and export the core of the register.
Incidents and continuity
An incident register with deadlines, business continuity plans with recovery times, and the exercises that test them.
Supplier checks
Send security questionnaires to ICT providers, score the answers and record decisions and the next review.
Questions about DORA
Does DORA replace NIS2 for financial entities?
For the financial entities it covers, DORA is the specific rule for ICT risk; it takes precedence over the matching NIS2 obligations. Many groups still handle both, and CloudSignLab can track both on the same controls.
Can CloudSignLab file reports with the authority?
No. CloudSignLab helps you prepare: it keeps the register of information, the incident details and deadlines. Submitting reports stays with your entity, through the channel of your authority.
Bring DORA into one place
Start free and add your ICT providers to the register of information today.
