CyberFinance

DORA Programme & Gap Assessment

Full-scope DORA compliance for financial entities and their critical ICT providers.

The situation

DORA has applied since 17 January 2025 and supervisory attention has shifted from 'do you have a plan' to 'show us the evidence'.

We assess against all five pillars — ICT risk management, incident reporting, resilience testing, third-party risk and information sharing — and deliver a remediation programme scoped to the entity's proportionality tier rather than a generic checklist. We also serve ICT providers who need to satisfy their financial-sector clients.

What the client receives

Schedule of deliverables

  1. 01Applicability and proportionality assessment (including the simplified framework)
  2. 02Five-pillar gap assessment against DORA and the RTS / ITS package
  3. 03Remediation roadmap with regulatory deadline mapping
  4. 04ICT risk management framework documentation
  5. 05Major incident classification and reporting procedure
  6. 06Board and management-body accountability briefing
  7. 07Supervisory examination support

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • Regulation (EU) 2022/2554 (DORA)
  • DORA RTS / ITS package
  • EBA / ESMA / EIOPA guidelines
  • ISO/IEC 27001

Discuss this engagement

Tell us about your entity type and the pillar under supervisory attention and we will set out the scope, the method and the reporting format.

Contact us