Build the technology and evidence an in-scope firm needs for DORA
We help with ICT risk, incident preparation, resilience testing and supplier evidence, working alongside your legal and compliance advisers.
Meet the requirements you will be assessed against
ICT risk management framework
You must maintain a framework that identifies, protects against, detects, responds to and recovers from ICT disruption. That means documented policies, defined risk tolerances, and continuous monitoring across your whole technology estate.
ICT incident reporting
Major ICT incidents must be classified, documented and reported within defined timeframes. The initial report is due within four hours of classification as major and no later than 24 hours after awareness.
Digital operational resilience testing
Regular testing of your ICT systems is mandatory, including vulnerability assessments, network security reviews, and for firms meeting the threshold, threat-led penetration testing (TLPT) at least every three years.
Third-party ICT risk management
Every outsourced ICT arrangement must be governed by written contracts with specific DORA-mandated clauses covering data access, audit rights, exit strategies, and subcontracting controls.
Information sharing
Firms are encouraged to participate in threat intelligence sharing arrangements with peers and authorities to strengthen collective resilience across the financial sector.
Proportionality principle
For entities within DORA's scope, the work is proportionate to size, risk profile and the complexity of the ICT services. Some entity types are outside scope or benefit from specific exemptions.
Why DORA changes financial services IT
DORA is an EU framework for specified financial entities and their management of ICT risk. It affects the way an in-scope firm documents systems, handles incidents, tests resilience and governs relevant suppliers.
Enforcement began on 17 January 2025. Since that date, digital operational resilience has been a board-level responsibility. Your ICT arrangements are not a procurement detail any more. They are a regulated function, open to supervisory scrutiny, mandatory testing and formal incident reporting.
For a London firm, the first question is scope. An EU entity covered by DORA has direct obligations. A UK firm may instead fall under the FCA’s operational resilience framework, face contractual requirements from an EU customer, or sit outside both regimes. The frameworks overlap, but they are not interchangeable.
Where mid-market firms get stuck on DORA
Large banks run dedicated technology risk teams. Sole traders sit below the threshold for the heaviest obligations. The firms that struggle sit in between.
Mid-sized in-scope firms often have limited internal technology-risk capacity. The work commonly slows around third-party contracts, the ICT risk framework and a testing programme sized to the actual risk.
That is the gap we fill.
The five DORA pillars
ICT risk management needs a living framework, not a policy written once and filed. Monitor your estate continuously. Identify, assess and mitigate risks on a documented cycle. Map every asset, every dependency and every point of failure.
Incident reporting needs your IT provider to classify incidents against DORA’s severity criteria. They escalate within the mandated timeframes and produce root-cause analysis a regulator will accept. Ad-hoc ticket queues and informal escalation paths do not survive scrutiny.
Resilience testing asks for more than an annual scan. You need vulnerability scanning, scenario-based testing and, above the threshold, threat-led penetration testing run by qualified external testers.
Third-party risk management is where most firms are furthest behind. Review every ICT contract against Article 30. Document exit strategies, audit rights, data handling obligations and subcontracting controls explicitly.
Information sharing stays voluntary. Firms that join sector threat-intelligence arrangements show a mature approach to resilience, and supervisors take note.
Managed IT that supports DORA readiness
Our managed IT support can provide the asset information, change records, monitoring and recovery evidence used by an in-scope firm. Contract terms and incident responsibilities are agreed for the services in scope rather than assumed to be identical for every client.
We start with a structured DORA gap analysis. We map your ICT arrangements against each pillar, show you where you fall short, and set out a remediation plan with dated milestones.
Then we coordinate resilience testing with specialist partners, run the vulnerability scanning cycle, and keep the documentation current. When your compliance officer or external auditor asks for evidence, it exists and you can reach it.
DORA has no finish line. Treat it as a one-off project and you will be back in remediation inside a year. Build it into how your IT is run and the evidence becomes a by-product of good operations.
The result is a maintained operating process rather than a document assembled once and left to date.
Last updated:
FAQ
Frequently asked questions
Does DORA apply to UK-based financial firms?
DORA directly applies to specified financial entities in the EU. A UK firm is not brought into direct scope merely because it has EU clients. Scope depends on its entity type, authorisations, establishment and operating model. UK firms may still face contractual requests from an in-scope EU customer or separate FCA and PRA resilience requirements. Confirm your position with legal or compliance advisers.
When did DORA enforcement begin?
DORA became enforceable on 17 January 2025. The European Supervisory Authorities began active supervision from that date. Firms that have not yet completed their implementation programmes are already operating outside compliance.
What does DORA mean for our IT provider relationship?
An in-scope firm must manage ICT supplier risk and include required provisions in relevant contracts, including access, audit, incident, exit and subcontracting terms. Direct EU oversight applies to providers formally designated as critical, not to every ICT supplier.
How long does a DORA readiness programme take?
For a typical London financial services firm with 20-200 staff, a structured DORA readiness programme takes 3-6 months. This covers gap analysis, policy development, contract remediation, testing programme design, and incident response procedure updates.
Can Nerdster act as our DORA-compliant ICT provider?
We can support the technology, documentation, testing and supplier information used in a DORA programme. Your firm remains responsible for determining scope and compliance, so we work with your legal and compliance advisers and agree the contract terms required for the services in scope.
What happens if we fail to comply with DORA?
EU competent authorities can impose administrative penalties and remedial measures. Beyond fines, non-compliance creates material risk during regulatory examinations, client due diligence reviews, and cyber insurance renewals. Reputational damage from a publicised ICT failure without proper resilience frameworks can be more costly than the penalties themselves.
Talk to our team about this standard
Tell us where you are with this standard. A London-based engineer replies within 2 hours during business hours.
Message sent
Thanks for getting in touch. We will reply within 2 hours on a business day.
Contact details
0330 043 7414
Mon-Fri 8am-6pm
[email protected]
We reply within 2 hours
71-75 Shelton Street
Covent Garden, London WC2H 9JQ
IT assessment
A review of your IT, your security posture and your compliance readiness, free of charge.
- 30-minute consultation call
- Infrastructure & security review
- Compliance gap analysis
- Custom recommendations report
Related compliance services
Find out where you stand today
Book a compliance review. We assess your readiness against the current requirements and give you a priority order for closing the gaps.
- No callout fees
- No-obligation assessment