EU DORA · Digital Operational Resilience

Resilience the regulator can actually test.

The Digital Operational Resilience Act is now the operating reality for financial entities in the EU, and for the ICT providers who serve them. We build DORA programmes across all five pillars, from ICT risk, incident reporting and resilience testing to third-party risk and information sharing, with the evidence discipline of practising auditors.

We hold ourselves to the standards we audit: Cybercontrols is certified to
ISO/IEC 27001:2022Certified · SANCERT ISO/IEC 42001:2023Certified · SANCERT Cyber EssentialsCertified Government Commercial AgencyApproved Supplier · G-Cloud 15
What we deliver

All five pillars, one coherent programme.

DORA rewards organisations that treat it as one resilience system rather than five compliance projects. That is how we build it, and how we keep the register of information from becoming a career in itself.

01

Gap Assessment

Your current arrangements benchmarked against DORA and its technical standards: ICT risk framework, incident classification, testing programme, third-party register and contractual provisions, with a prioritised, costed remediation plan.

02

Implementation

The ICT risk management framework, incident reporting mechanics against the regulatory clocks, resilience testing programme, and third-party risk regime, built into your existing operations and aligned with ISO 27001 and business continuity good practice.

03

Ongoing Compliance

Maintenance of the register of information, annual testing cycles, threat-led testing preparation where required, board reporting, and monitoring of the regulatory technical standards as they evolve.

Why Cybercontrols

Financial regulation is an evidence discipline. So are we.

DORA supervision comes down to whether you can demonstrate, on demand, that resilience arrangements exist, operate and improve. Our Senior Lead Auditors assess management systems for certification bodies for a living, so the programmes we build are evidenced the way supervisors expect to find them. For ICT service providers to financial entities, we also handle the other side: responding to DORA contractual demands and, where relevant, preparing for critical third-party designation.

Five pillars, one system

ICT risk, incidents, testing, third parties and information sharing run as a single programme, not five silos.

Register of information, tamed

A maintainable register built once, kept current, ready for the annual regulatory submission.

ISO-aligned by design

Anchored on ISO 27001 and continuity good practice, so the same evidence serves certificates and supervisors.

Senior-led, always

Senior Lead Implementer and Senior Lead Auditor credentials on every engagement. No juniors, no hand-offs.

How it works

From scoping to supervisory confidence, without surprises.

Step 1

Scoping and proportionality

DORA scales with size and risk profile. We establish which obligations apply to you, in full or under the simplified regime, before anything is built.

Step 2

Gap analysis

A pillar-by-pillar assessment against the regulation and its technical standards, with findings classified honestly and a remediation plan in priority order.

Step 3

Build and embed

Framework, playbooks, register and testing programme deployed inside your operations, with contractual provisions flowed into ICT supplier agreements.

Step 4

Rehearse and evidence

Incident classification and reporting rehearsed against the regulatory timelines, testing executed and documented, board reporting established.

Step 5

Operate and improve

Annual cycles maintained, the register kept current, and the programme adjusted as supervisory expectations and technical standards mature.

Questions we hear most

DORA, answered plainly.

Who does DORA apply to?

Over twenty categories of financial entity, including banks, insurers, investment firms, payment and e-money institutions and crypto-asset service providers, plus, indirectly but forcefully, the ICT providers who serve them. If your customers are EU financial entities, DORA reaches you through their contracts.

We are a UK firm. Does DORA matter to us?

If you operate in the EU or serve EU financial entities, yes, through establishment or through contract. The UK's own operational resilience regime under the FCA and PRA runs on parallel lines, so a single well-designed programme can serve both.

How does DORA relate to ISO 27001 and ISO 22301?

They are the best available scaffolding: an ISMS covers much of the ICT risk pillar and a continuity capability much of the testing and recovery expectation. DORA adds financial-sector specifics, the incident taxonomy and clocks, the register of information and threat-led testing, which we build as a delta rather than a parallel universe.

What is the register of information?

A structured record of every contractual arrangement with ICT third parties, maintained continuously and submitted to your supervisor on request or on the annual cycle. Built well once, it is routine to maintain; built badly, it is a permanent tax. We build it well.

Ready to make resilience demonstrable?

A 30-minute scoping call with a senior lead auditor, and an honest reading of your distance from DORA compliance.