DORA without spreadsheets.
Inspection ready every day.
One system for risk, incidents, testing and providers. Built for Nordic and European financial entities. Running in under two weeks, without consultants.
Supervisors no longer check whether you have controls. They check whether the controls work.
A binder and a spreadsheet will not do in 2026. The supervisor wants fresh evidence, timestamps and a record of who did what. That is exactly what this system gives you.
Risk in Excel, incidents over email
When the supervisor asks for a complete picture, you spend a week assembling it. And nobody knows whether the numbers hold.
134 requirements tracked by hand
What is covered, what is partly in place, what is missing entirely? Keeping that straight manually is a full-time job on its own.
One system, always ready for inspection
Every register, every piece of evidence and every deadline in one place. The audit package exports in one click, with a timestamp on everything.
Up and running in days, not months
No consultants, no implementation project. You can have your first register live the same day.
Sign up & configure
Create your account, set up governance roles, and start building your ICT asset inventory. All 134 DORA and RTS/ITS requirements are pre-loaded. Nothing to map or configure.
Assess & document
Run a gap analysis against each article, build your risk register, and document critical function dependencies. The CIF Register connects everything automatically.
Monitor & report
Track where you stand across all four pillars, respond to incidents with built-in deadline tracking, and export a full audit snapshot when you need it.
All four DORA pillars
in one platform.
Every article, every RTS, every ITS: mapped to actionable modules. Not another checklist. An operational compliance system.
ICT Risk Management
Define management body responsibilities, document your ICT risk framework, and maintain your Critical or Important Functions register: the register that drives obligations across everything else.
Incident Reporting
Classify, triage, and report ICT incidents with built-in ITS 2024/2956 templates. Track timelines and manage major incident workflows end-to-end.
Resilience Testing
Plan your annual testing programme against your CIF Register, track findings through to remediation, and manage the full TLPT lifecycle for entities in scope.
Third-Party Oversight
Register all ICT providers, track the eight mandatory contractual clauses per Art. 30, and monitor concentration risk before your supervisor flags it.
EU Cyber Resilience Act
Track product security obligations, manage vulnerabilities with ENISA deadline tracking, and maintain Annex I compliance checklists for products with digital elements.
EU AI Act Compliance
Register AI systems with automatic risk tier classification, track compliance across eight regulatory pillars, and manage incident reporting and oversight logs.
Built for DORA, not retrofitted
Every module maps to a DORA article. No generic GRC framework to configure, no consultants needed to make it relevant.
134-Requirement Compliance Tracker
Every requirement from DORA Articles and Level 2 RTS/ITS measures, pre-loaded with article references and gap analysis. L1–L5 maturity scoring across your entire regulatory surface.
- 134 requirements covering DORA Articles and RTS/ITS Level 2
- L1 Initial → L5 Optimised maturity scale per requirement
- One-click task creation from identified gaps
- Per-pillar and per-article progress breakdown
The reporting clock runs, the template is ready
Classify the incident against the ITS criteria and the system works out the deadlines for the initial notification, the intermediate report and the final report. The draft is filled in from what you have already recorded.
- Countdown to the next deadline, always visible
- ITS 2024/2956 templates built in
- A full timeline for the supervisor
The register of information builds itself
Record providers and contracts once. The register for the supervisor is generated from there, validated against the ITS format, with LEI lookup against GLEIF.
- xBRL-CSV export ready for submission
- CTPP providers flagged automatically
- Exit plans and concentration risk in one place
One list, sorted by deadline
Incident reports, ROI submission, expired evidence and approvals all land in one queue. An empty queue means you are up to date. No hunting through 45 menu items.
- Deadlines calculated from the DORA requirements
- Every item links straight to the action
- Delegate with one button
Bowtie Risk Visualization
Visualize risk causes, preventive controls, risk events, recovery controls, and consequences in the industry-standard Bowtie diagram: linked to your control library.
- SVG-rendered interactive Bowtie diagrams
- 5 threat categories and 5 consequence categories
- Barrier bars linked to Control Library entries
- Quick-launch from any risk register row
Risk Heat Map & Trend Analytics
5×5 risk heat map with configurable tolerance thresholds, automatic risk appetite decisions, and historical trend charts showing how your risk posture evolves.
- Inherent and residual risk scoring (1–5 scale)
- Auto-calculated Accept / Review / Escalate decisions
- Tolerance breach alerts on the dashboard
- Historical trend charts from risk snapshots
Task & Workflow Engine
Create remediation tasks from compliance gaps, risk treatments, incidents, and test findings. Track priority, assignees, due dates, and completion: all with full audit trail.
- Auto-generated TSK-NNN IDs with audit trail
- Cross-page creation from gaps, risks, incidents, tests
- Priority levels: Critical / High / Medium / Low
- Overdue tracking and dashboard integration
| Task | Source | Priority | Status |
|---|---|---|---|
| TSK-001 | Art. 11 gap | Critical | In Progress |
| TSK-002 | Risk R-003 | High | Open |
| TSK-003 | INC-2026-001 | Critical | Done |
| TSK-004 | Test findings | High | Open |
Everything else you need
ICT Risk Framework
Three-level document hierarchy: policies, standards, and procedures. Version history, approval tracking, and gap analysis showing what's missing per article.
CIF Dependency Map
See which critical functions rely on which ICT assets and third parties. Useful when scoping tests or assessing whether your exit strategies are realistic.
Business Impact Analysis
Step-by-step BIA covering MTPD, RTO, and RPO. Criticality scoring across four impact dimensions, auto-tiered so you don't have to do the maths manually.
Incident Classification
Walk through classification against the ITS reporting criteria. Severity assessment and regulatory reporting stages are built in, so nothing gets missed when an incident is unfolding.
Full Audit Trail
Every action logged with timestamp and user. Searchable, filterable, and exportable as JSON. Exactly what you need when a regulator asks for evidence.
Role-Based Access
Three access levels: admin, analyst, viewer. Session-based auth, password policies, and full activity attribution on every record.
EU Cyber Resilience Act
Product security register, vulnerability tracker with ENISA 24h/72h/14d deadline chips, Annex I compliance checklist, and SBOM management per product.
EU AI Act Compliance
AI system register with automatic risk tier classification, 8-pillar compliance dashboard, structured risk assessment wizard, and incident logging.
Document Archive
R2-backed evidence repository for reports, assessments, and attachments. Linked to every entity in the platform with full version history.
Simple, transparent pricing
No per-user fees. No implementation consultants. One platform, one price.
- Up to 5 users
- All four DORA pillars
- 134 requirements preloaded
- Risk register and heat map
- Incidents with deadline calculation
- Export on every register
- Up to 20 users
- Everything in Starter
- ROI export in xBRL-CSV
- Audit package in one click
- Evidence monitoring and reminders
- Testing programme and TLPT support
- CRA and AI Act modules
- Priority support
- Unlimited users
- Everything in Professional
- Dedicated instance in the EU
- SSO with Entra ID
- Several frameworks (ISO 27001, NIS2)
- Named contact and SLA
Frequently asked questions
DORA (EU 2022/2554) is the EU regulation that requires financial entities to demonstrate digital operational resilience. Four pillars carry the obligations: ICT risk management, incident reporting, resilience testing and third-party risk oversight. A fifth area, information sharing under Article 45, is voluntary. DORA has been in force since January 2025 and applies to banks, insurers, investment firms, payment institutions, crypto-asset service providers, and their critical ICT providers.
Pretty much every regulated financial entity in the EU. Credit institutions, insurance undertakings, investment firms, payment institutions, electronic money institutions, crypto-asset service providers, and the ICT providers designated as critical (CTPPs). The regulation applies to over 22,000 entities across the EU.
The platform arrives pre-loaded with all 134 DORA and RTS/ITS requirements. Most teams have their first registers populated within a week or two. No consultants or implementation partners needed. How long the overall compliance programme takes depends on your starting point, not on setup time.
Data is encrypted in transit with TLS 1.3 and stored encrypted at rest in the EU. Access is role-based, multi-factor authentication (TOTP) is supported, every action is recorded in a full audit trail, and sessions expire automatically. We don't share data with third parties. See the Security Overview page for details.
Yes. The audit export produces a timestamped JSON snapshot of every register: governance roles, risks, controls, incidents, tests, providers, contracts, and tasks. User attribution on every entry. The audit log is separately exportable with full search and filtering.
The platform is built specifically for DORA. Multi-framework mapping to ISO 27001 and NIS2 is on the roadmap. The risk methodology follows ISO 27005 and ISO 31000, so the work you do here will translate when you get there.
Talk to us
Evaluating the platform, or just have a question about DORA? Drop us a message.
How can we help?
Whether you want a walkthrough, have a specific DORA question, or just want to see the platform before committing, send us a message and we'll get back to you.
Send a message
Not sure where you stand with DORA?
25 questions, 3 minutes. You get a maturity score per pillar and a list of the biggest gaps. Free, and no account needed.
Take the maturity test