DORA GRC Blog

Insights on DORA compliance, ICT risk management, and digital operational resilience

How DORA GRC Helps EU Financial Entities Achieve Full DORA Compliance

DORA entered into force on 17 January 2025. Here is how DORA GRC covers all four regulatory pillars — ICT risk, incident reporting, resilience testing, and third-party oversight — in a single purpose-built platform.

News & Updates 5 March 2026 4 min read

78 Threat Scenarios, Zero Blank Pages: How to Build a DORA Risk Register That Holds Up

Article 8 tells you to identify your ICT risks. It does not tell you where to start. Here is why we ship 78 ready-made threat scenarios, and how to turn a scenario library into a risk register you actually own.

News & Updates 24 August 2026 By DORA GRC Team 5 min read

The DORA Contract Checklist: Every Clause Article 30 Requires

Most firms remediated their ICT contracts in 2024 against draft rules. Supervisors are now reading the clauses against the final ones. Here is the full Article 30 checklist: the provisions every contract needs, and the extra layer for critical functions.

Third-Party Oversight 23 August 2026 5 min read

Best DORA Compliance Software in 2026: A Brutally Honest Comparison

Every "best DORA software" list you have read was written by a vendor who put themselves first. So is this one. The difference: we tell you when the others are the better buy, and when we are the wrong one.

DORA Regulation 22 August 2026 7 min read

Critical or Important Functions Under DORA: How a BIA Gives You the Answer

Almost every DORA obligation is scoped by one classification: is this function critical or important? Here is what the definition actually says, and how a business impact analysis turns the classification from opinion into evidence.

Compliance 22 August 2026 By DORA GRC Team 4 min read

When Is an Incident "Major" Under DORA? The Classification Thresholds Explained

The reporting deadlines get all the attention, but the harder question comes first: is this incident major at all? Here are the RTS 2024/1772 criteria, the counting rules, and the mistakes supervisors flag.

Incident Reporting 18 August 2026 By DORA GRC Team 4 min read

Bowtie Diagrams for ICT Risk: Show a DORA Risk on One Page

Risk registers are tables nobody reads. A bowtie diagram shows the same risk as a picture: what causes it, what stops it, and what happens if the barriers fail. Here is how it works and why we built it into DORA GRC.

News & Updates 18 August 2026 By DORA GRC Team 4 min read

DORA Exit Strategies: Who Needs One and What It Must Contain

Every ICT service supporting a critical or important function needs a documented and tested exit strategy. Here is what Article 28(8) requires, the mistakes supervisors flag, and a practical way to build yours.

Third-Party Oversight 17 August 2026 4 min read

The ESAs' Frontier AI Statement: What Supervisors Now Expect Under DORA

On 31 July 2026 the ESAs published expectations for how financial entities should handle AI risk under DORA. Here is what the statement says and five things to do this quarter.

News & Updates 16 August 2026 By DORA GRC Team 4 min read

DORA Subcontracting One Year On: What Regulation (EU) 2025/532 Actually Requires

The DORA subcontracting rules have applied since 22 July 2025, and subcontractor data is still the weakest part of most Register of Information submissions. What the rules require, what they leave out, and a 30-day plan.

Third-Party Oversight 16 August 2026 By DORA GRC Team 5 min read

AI is now a DORA risk: what the ESAs and Nordic supervisors are warning about

The ESAs' first DORA incident report flagged AI as an emerging ICT risk. Finanstilsynet dedicated an entire section of ROS 2026 to AI governance failures. Here is what financial entities need to understand about AI as an operational resilience risk under DORA.

Compliance 18 July 2026 8 min read

DORA fines are here: What the first enforcement actions mean for you

The informal tolerance period that defined 2025 is over. NCAs across Europe have started issuing compulsion payments and remediation orders. Here is what the first wave of DORA enforcement looks like in practice.

DORA Regulation 18 July 2026 By DORA GRC Team 6 min read

DORA incident reporting is changing: the single EU hub explained

The ESAs opened a call for input on the future of DORA incident reporting, closing 3 July 2026. The big idea in play is a single EU hub. Here is what it means.

Incident Reporting 1 July 2026 By DORA GRC Team 5 min read

DORA incident report 2026: what 3,383 incidents reveal

The ESAs' first DORA incident report is out. The headline number looks big, but the real story is provider concentration and the reports that never got finished.

Incident Reporting 1 July 2026 By DORA GRC Team 7 min read

ESAs Spring 2026 Risk Report: What It Means for DORA Compliance

The ESAs' Spring 2026 joint risk assessment connects geopolitical instability, AI-driven disruption, and cyber threats to the financial sector's operational resilience. Here's what it signals for DORA compliance priorities.

News & Updates 10 April 2026 By DORA GRC Team 8 min read

DORA Enforcement in 2026: What the Numbers Actually Show

Three major industry surveys paint a consistent picture: most financial entities entered 2026 with significant DORA compliance gaps. Here's what the data says — and what's actually happening on the enforcement side.

DORA Regulation 10 April 2026 By DORA GRC Team 8 min read

Nordic Regulators Are Aligned: Digital Resilience Is a Top Supervisory Priority in 2026

All four Nordic financial supervisors have published their 2026 priorities. ICT risk, cyber resilience, and operational continuity feature prominently in every single one. Here is what that convergence means for firms operating under DORA in the Nordics.

DORA Regulation 9 April 2026 By DORA GRC Team 7 min read

DORA GRC April 2026: Audit Package Builder, AI Contract Review, and What We Shipped This Quarter

We built the feature we kept hearing about from compliance teams preparing for their first NCA inspections: a one-click audit documentation package. Here is what shipped in Q1 2026 and what is coming next.

DORA Regulation 5 April 2026 By DORA GRC Team 5 min read

DORA TLPT: Are You Required to Do It, and What Does It Actually Involve?

Not every financial entity needs to perform threat-led penetration testing under DORA. But if your competent authority says you do, the process is substantial — 12 to 18 months from start to attestation. This guide walks through who gets identified, the specific thresholds, what the test involves, and how to document your conclusion.

Compliance 4 April 2026 By DORA GRC Team 13 min read

DORA Proportionality: What It Actually Means and How to Document It

Proportionality is one of the most misunderstood parts of DORA. It does not exempt anyone from compliance — but it does let you scale your implementation to fit your organisation. This guide explains what Article 4 requires, who qualifies for the simplified framework, and how to document your proportionality assessment so it holds up under supervisory review.

Compliance 3 April 2026 By DORA GRC Team 13 min read

DORA for Investment Firms: What MiFID-Licensed Entities Need to Know

DORA applies to all MiFID II-licensed investment firms — from asset managers to algorithmic trading firms. This guide covers which obligations apply, how they interact with existing MiFID II requirements, and what to prioritise first.

Compliance 3 April 2026 By DORA GRC Team 9 min read

DORA for Payment Institutions and E-Money Issuers: What Applies to You

DORA applies to all PSD2-licensed payment institutions and EMD2-licensed e-money issuers — no size exemption. This guide covers which obligations apply, where proportionality helps, and where it does not.

Compliance 3 April 2026 By DORA GRC Team 8 min read

The DORA CTPP List Is Out: What It Means If Your Cloud Provider Is Designated

The ESAs published the first official list of Critical ICT Third-Party Providers in November 2025. Here is what financial entities need to do now if their cloud provider, data vendor, or core technology integrator made the list.

DORA Regulation 2 April 2026 By DORA GRC Team 7 min read

The EU Digital Omnibus Explained

The EU's Digital Omnibus proposal promises a single entry point for cyber incident reporting across DORA, NIS2, and GDPR. Here is what it actually changes, what it does not touch, and why your current DORA obligations remain fully in force.

DORA Regulation 2 April 2026 9 min read

DORA Register of Information 2026: What Regulators Are Telling Firms After the March Deadline

The first full submission cycle for the DORA Register of Information (RoI) has closed. Firms across the European Economic Area were required to submit their registers of ICT third-party arrangements — reflecting contractual positions as of 31 December 2025 — to their national competent authorities (NCAs) in time for the ESAs' consolidated deadline of 31 March 2026.

Third-Party Oversight 31 March 2026 By DORA GRC Team 10 min read

360° Intelligence Hub: See Every Connection Across Your ICT Estate

The 360° Intelligence Hub connects assets, providers, functions, risks, incidents, contracts, and controls in a single view. No more switching between modules to understand your DORA compliance posture.

News & Updates 20 March 2026 By DORA GRC Team 6 min read

DORA Register of Information: Complete Guide to ITS 2024/2956

A practical guide to the DORA Register of Information. Covers the 15 templates, the EBA validation rules that trip up 93% of submissions, NCA-specific deadlines and portals, and how to avoid the most common errors.

Compliance 20 March 2026 By DORA GRC Team 10 min read

What Financial Supervisors Are Targeting in DORA Audits: Country-by-Country

A country-by-country breakdown of what European financial supervisors are focusing on in their DORA audits for 2026. Covers Norway, Sweden, Denmark, Finland, Germany, Netherlands, France, Ireland, Luxembourg, Italy, and the UK.

Compliance 20 March 2026 By DORA GRC Team 12 min read

DORA Compliance Checklist Template 2026: Free Excel & PDF Download

Download our free DORA compliance checklist template with 95 items across all five pillars. Includes a professional Excel workbook with maturity scoring, auto-calculated dashboard, and a companion PDF guide.

Compliance 20 March 2026 By DORA GRC Team 5 min read

The 4-Hour Clock: DORA Major Incident Reporting Step by Step

A critical system goes down at 09:15. By 13:15 your regulator expects to know about it. That is the reality of DORA major incident reporting.

Incident Reporting 17 March 2026 By DORA GRC Team 8 min read

EU AI Act and DORA: Managing AI System Risk in Financial Services

Financial services firms are adopting AI at a significant pace. Two major EU regulations now apply to AI systems used by financial entities: the EU AI Act and DORA.

Compliance 17 March 2026 By DORA GRC Team 7 min read

DORA vs NIS2: Dual Compliance Without Doubling the Work

Many compliance teams in the EU financial sector are now looking at two major regulations at the same time. DORA came into force in January 2025. NIS2 national transpositions are either live or arriving.

DORA Regulation 17 March 2026 By DORA GRC Team 7 min read

EU CRA, NIS2, DORA, EU AI Act: Which Regulation Applies to You?

If you operate in the EU or serve EU customers, you have probably noticed a wave of new cybersecurity and resilience regulations coming into effect. DORA, NIS2, the EU Cyber Resilience Act (CRA), and the EU AI Act all landed within a short window of each other, and it is not always obvious which ones actually apply to your organisation. This post walks through each regulation, who it targets, and where they overlap. No legal jargon, just a practical guide to help you figure out your obligations.

Compliance 12 March 2026 By DORA GRC Team 5 min read

How to Run DORA Vendor Assessments Without a Spreadsheet

A walkthrough of the Vendor Questionnaire module in DORA GRC — how to send structured security assessments to ICT providers, track responses, auto-score results, and document compliance with Art. 28(1)(d).

DORA Regulation 7 March 2026 By DORA GRC Team 5 min read

DORA Compliance Checklist 2026: Everything EU Financial Entities Must Have in Place

DORA has been enforceable since January 2025. This practical checklist covers all five pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and governance — with direct article references so you can audit your programme against the actual regulation.

DORA Regulation 3 March 2026 By DORA GRC Team 11 min read

What Is DORA? The Complete Guide to the EU's Digital Operational Resilience Act

The Digital Operational Resilience Act (DORA) is the EU's landmark regulation requiring financial entities to withstand, respond to, and recover from ICT disruptions. This complete guide covers everything you need to know — from scope and requirements to deadlines and enforcement.

DORA Regulation 2 March 2026 By DORA GRC Team 10 min read

Ready to simplify DORA compliance?

Purpose-built platform for EU financial entities. Book a personalised demo.

Book a demo →