EU 2022/2554 · Enforcement active in 2026

DORA without spreadsheets.
Inspection ready every day.

One system for risk, incidents, testing and providers. Built for Nordic and European financial entities. Running in under two weeks, without consultants.

No login needed for the test. 25 questions, your score in 3 minutes.
The DORA GRC dashboard: compliance score, work queue sorted by deadline and the four pillars.
134
requirements from DORA and RTS/ITS, preloaded
4+2
DORA pillars plus CRA and AI Act
<2 weeks
from signing to running, without consultants
EU
all data stored in the EU, built in Norway
THE PROBLEM

Supervisors no longer check whether you have controls. They check whether the controls work.

A binder and a spreadsheet will not do in 2026. The supervisor wants fresh evidence, timestamps and a record of who did what. That is exactly what this system gives you.

BEFORE

Risk in Excel, incidents over email

When the supervisor asks for a complete picture, you spend a week assembling it. And nobody knows whether the numbers hold.

BEFORE

134 requirements tracked by hand

What is covered, what is partly in place, what is missing entirely? Keeping that straight manually is a full-time job on its own.

AFTER

One system, always ready for inspection

Every register, every piece of evidence and every deadline in one place. The audit package exports in one click, with a timestamp on everything.

how it works

Up and running in days, not months

No consultants, no implementation project. You can have your first register live the same day.

1

Sign up & configure

Create your account, set up governance roles, and start building your ICT asset inventory. All 134 DORA and RTS/ITS requirements are pre-loaded. Nothing to map or configure.

2

Assess & document

Run a gap analysis against each article, build your risk register, and document critical function dependencies. The CIF Register connects everything automatically.

3

Monitor & report

Track where you stand across all four pillars, respond to incidents with built-in deadline tracking, and export a full audit snapshot when you need it.

Complete Coverage

All four DORA pillars
in one platform.

Every article, every RTS, every ITS: mapped to actionable modules. Not another checklist. An operational compliance system.

1
Pillar 1 · Art. 5–16

ICT Risk Management

Define management body responsibilities, document your ICT risk framework, and maintain your Critical or Important Functions register: the register that drives obligations across everything else.

Governance & Strategy
Asset Register (CIF)
Risk Register + Bowtie
Control Library
2
Pillar 2 · Art. 17–23

Incident Reporting

Classify, triage, and report ICT incidents with built-in ITS 2024/2956 templates. Track timelines and manage major incident workflows end-to-end.

Incident Classification
Major Incident Workflow
ITS Reporting Templates
Timeline & Audit Trail
3
Pillar 3 · Art. 24–27

Resilience Testing

Plan your annual testing programme against your CIF Register, track findings through to remediation, and manage the full TLPT lifecycle for entities in scope.

Testing Schedule
TLPT Management
Findings Register
RTS Compliance Mapping
4
Pillar 4 · Art. 28–44

Third-Party Oversight

Register all ICT providers, track the eight mandatory contractual clauses per Art. 30, and monitor concentration risk before your supervisor flags it.

Provider Register
Contract Register + ROI
Vendor Questionnaires
LEI / GLEIF Lookup
C
EU CRA · 2024/2847

EU Cyber Resilience Act

Track product security obligations, manage vulnerabilities with ENISA deadline tracking, and maintain Annex I compliance checklists for products with digital elements.

Product Register
Vulnerability Tracker
Annex I Checklist
SBOM Manager
A
EU AI Act · 2024/1689

EU AI Act Compliance

Register AI systems with automatic risk tier classification, track compliance across eight regulatory pillars, and manage incident reporting and oversight logs.

AI System Register
Risk Assessment Wizard
Compliance Dashboard
Incident & Oversight Log
capabilities

Built for DORA, not retrofitted

Every module maps to a DORA article. No generic GRC framework to configure, no consultants needed to make it relevant.

Art. 5–45 · RTS/ITS Level 2

134-Requirement Compliance Tracker

Every requirement from DORA Articles and Level 2 RTS/ITS measures, pre-loaded with article references and gap analysis. L1–L5 maturity scoring across your entire regulatory surface.

  • 134 requirements covering DORA Articles and RTS/ITS Level 2
  • L1 Initial → L5 Optimised maturity scale per requirement
  • One-click task creation from identified gaps
  • Per-pillar and per-article progress breakdown
The compliance view in DORA GRC: requirements per DORA theme with status and evidence.
Art. 17–23 · ITS 2024/2956

The reporting clock runs, the template is ready

Classify the incident against the ITS criteria and the system works out the deadlines for the initial notification, the intermediate report and the final report. The draft is filled in from what you have already recorded.

  • Countdown to the next deadline, always visible
  • ITS 2024/2956 templates built in
  • A full timeline for the supervisor
The incident view in DORA GRC: classification, deadlines and reporting status.
Art. 28–44 · ROI

The register of information builds itself

Record providers and contracts once. The register for the supervisor is generated from there, validated against the ITS format, with LEI lookup against GLEIF.

  • xBRL-CSV export ready for submission
  • CTPP providers flagged automatically
  • Exit plans and concentration risk in one place
The provider view in DORA GRC: contracts, criticality and register status.
Art. 5–15 · Work queue

One list, sorted by deadline

Incident reports, ROI submission, expired evidence and approvals all land in one queue. An empty queue means you are up to date. No hunting through 45 menu items.

  • Deadlines calculated from the DORA requirements
  • Every item links straight to the action
  • Delegate with one button
The dashboard in DORA GRC: work queue sorted by deadline.
ISO 27005 · ISO 31000

Bowtie Risk Visualization

Visualize risk causes, preventive controls, risk events, recovery controls, and consequences in the industry-standard Bowtie diagram: linked to your control library.

  • SVG-rendered interactive Bowtie diagrams
  • 5 threat categories and 5 consequence categories
  • Barrier bars linked to Control Library entries
  • Quick-launch from any risk register row
Phishing attack Vendor failure Config error RISK Service outage Data breach Regulatory fine CAUSES PREVENTIVE RECOVERY CONSEQUENCES
Art. 9 · Risk Appetite

Risk Heat Map & Trend Analytics

5×5 risk heat map with configurable tolerance thresholds, automatic risk appetite decisions, and historical trend charts showing how your risk posture evolves.

  • Inherent and residual risk scoring (1–5 scale)
  • Auto-calculated Accept / Review / Escalate decisions
  • Tolerance breach alerts on the dashboard
  • Historical trend charts from risk snapshots
Likelihood × Impact
1
2
3
4
5
2
4
6
8
10
3
6
9
12
15
4
8
12
16
20
5
10
15
20
25
Accept Review Escalate
Cross-Platform

Task & Workflow Engine

Create remediation tasks from compliance gaps, risk treatments, incidents, and test findings. Track priority, assignees, due dates, and completion: all with full audit trail.

  • Auto-generated TSK-NNN IDs with audit trail
  • Cross-page creation from gaps, risks, incidents, tests
  • Priority levels: Critical / High / Medium / Low
  • Overdue tracking and dashboard integration
TaskSourcePriorityStatus
TSK-001Art. 11 gapCriticalIn Progress
TSK-002Risk R-003HighOpen
TSK-003INC-2026-001CriticalDone
TSK-004Test findingsHighOpen
and more

Everything else you need

ICT Risk Framework

Three-level document hierarchy: policies, standards, and procedures. Version history, approval tracking, and gap analysis showing what's missing per article.

CIF Dependency Map

See which critical functions rely on which ICT assets and third parties. Useful when scoping tests or assessing whether your exit strategies are realistic.

Business Impact Analysis

Step-by-step BIA covering MTPD, RTO, and RPO. Criticality scoring across four impact dimensions, auto-tiered so you don't have to do the maths manually.

Incident Classification

Walk through classification against the ITS reporting criteria. Severity assessment and regulatory reporting stages are built in, so nothing gets missed when an incident is unfolding.

Full Audit Trail

Every action logged with timestamp and user. Searchable, filterable, and exportable as JSON. Exactly what you need when a regulator asks for evidence.

Role-Based Access

Three access levels: admin, analyst, viewer. Session-based auth, password policies, and full activity attribution on every record.

EU Cyber Resilience Act

Product security register, vulnerability tracker with ENISA 24h/72h/14d deadline chips, Annex I compliance checklist, and SBOM management per product.

EU AI Act Compliance

AI system register with automatic risk tier classification, 8-pillar compliance dashboard, structured risk assessment wizard, and incident logging.

Document Archive

R2-backed evidence repository for reports, assessments, and attachments. Linked to every entity in the platform with full version history.

Pricing

Simple, transparent pricing

No per-user fees. No implementation consultants. One platform, one price.

Starter
€490/mo
For smaller entities that need DORA under control.
  • Up to 5 users
  • All four DORA pillars
  • 134 requirements preloaded
  • Risk register and heat map
  • Incidents with deadline calculation
  • Export on every register
Try free
Professional
€990/mo
For banks and insurers that want to be inspection ready every day.
  • Up to 20 users
  • Everything in Starter
  • ROI export in xBRL-CSV
  • Audit package in one click
  • Evidence monitoring and reminders
  • Testing programme and TLPT support
  • CRA and AI Act modules
  • Priority support
Try free
Enterprise
By agreement
For groups with several legal entities and their own requirements.
  • Unlimited users
  • Everything in Professional
  • Dedicated instance in the EU
  • SSO with Entra ID
  • Several frameworks (ISO 27001, NIS2)
  • Named contact and SLA
Contact us
Prefer a walkthrough? Book a demo →
questions

Frequently asked questions

DORA (EU 2022/2554) is the EU regulation that requires financial entities to demonstrate digital operational resilience. Four pillars carry the obligations: ICT risk management, incident reporting, resilience testing and third-party risk oversight. A fifth area, information sharing under Article 45, is voluntary. DORA has been in force since January 2025 and applies to banks, insurers, investment firms, payment institutions, crypto-asset service providers, and their critical ICT providers.

Pretty much every regulated financial entity in the EU. Credit institutions, insurance undertakings, investment firms, payment institutions, electronic money institutions, crypto-asset service providers, and the ICT providers designated as critical (CTPPs). The regulation applies to over 22,000 entities across the EU.

The platform arrives pre-loaded with all 134 DORA and RTS/ITS requirements. Most teams have their first registers populated within a week or two. No consultants or implementation partners needed. How long the overall compliance programme takes depends on your starting point, not on setup time.

Data is encrypted in transit with TLS 1.3 and stored encrypted at rest in the EU. Access is role-based, multi-factor authentication (TOTP) is supported, every action is recorded in a full audit trail, and sessions expire automatically. We don't share data with third parties. See the Security Overview page for details.

Yes. The audit export produces a timestamped JSON snapshot of every register: governance roles, risks, controls, incidents, tests, providers, contracts, and tasks. User attribution on every entry. The audit log is separately exportable with full search and filtering.

The platform is built specifically for DORA. Multi-framework mapping to ISO 27001 and NIS2 is on the roadmap. The risk methodology follows ISO 27005 and ISO 31000, so the work you do here will translate when you get there.

get in touch

Talk to us

Evaluating the platform, or just have a question about DORA? Drop us a message.

How can we help?

Whether you want a walkthrough, have a specific DORA question, or just want to see the platform before committing, send us a message and we'll get back to you.

Typical response within 24 hours

Send a message

Free tool

Not sure where you stand with DORA?

25 questions, 3 minutes. You get a maturity score per pillar and a list of the biggest gaps. Free, and no account needed.

Take the maturity test

Still managing DORA in Excel?

Free trial. No credit card, no setup fees, no consultants.