Back to Frameworks
European Union
v2022
5 domains
26 controls

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, establishing uniform requirements for the security of network and information systems of EU financial entities and critical ICT third-party providers. Covers ICT risk management (governance, framework, identification, protection, detection, response/recovery, backup, learning), ICT-related incident management and major-incident reporting to competent authorities, digital operational resilience testing (including threat-led penetration testing), ICT third-party risk management (Register of Information, key contractual provisions, concentration risk) with a Union Oversight Framework for critical ICT third-party providers, and cyber threat information sharing. Applies from 17 January 2025.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

DORA Chapter II: ICT Risk Management

11 controls
Controls in the DORA Chapter II: ICT Risk Management domain of DORA11 controls
CodeTitle
DORA-Art.10Detection
DORA-Art.11Response and recovery
DORA-Art.12Backup policies and procedures, restoration and recovery
DORA-Art.13Learning and evolving
DORA-Art.14Communication
DORA-Art.16Simplified ICT risk management framework
DORA-Art.5Governance and organisation
DORA-Art.6ICT risk management framework
DORA-Art.7ICT systems, protocols and tools
DORA-Art.8Identification
DORA-Art.9Protection and prevention

DORA Chapter III: ICT-Related Incident Management

4 controls
Controls in the DORA Chapter III: ICT-Related Incident Management domain of DORA4 controls
CodeTitle
DORA-Art.17ICT-related incident management process
DORA-Art.18Classification of ICT-related incidents and cyber threats
DORA-Art.19Reporting of major ICT-related incidents
DORA-Art.23Operational or security payment-related incidents

DORA Chapter IV: Digital Operational Resilience Testing

4 controls
Controls in the DORA Chapter IV: Digital Operational Resilience Testing domain of DORA4 controls
CodeTitle
DORA-Art.24General requirements for the performance of digital operational resilience testing
DORA-Art.25Testing of ICT tools and systems
DORA-Art.26Advanced testing of ICT tools, systems and processes based on TLPT
DORA-Art.27Requirements for testers for the carrying out of TLPT

DORA Chapter V: ICT Third-Party Risk Management

4 controls
Controls in the DORA Chapter V: ICT Third-Party Risk Management domain of DORA4 controls
CodeTitle
DORA-Art.28ICT third-party risk: general principles
DORA-Art.29Preliminary assessment of ICT concentration risk at entity level
DORA-Art.30Key contractual provisions
DORA-Art.31Designation of critical ICT third-party service providers

DORA Chapters VI-VII: Information Sharing, Penalties and Data Protection

3 controls
Controls in the DORA Chapters VI-VII: Information Sharing, Penalties and Data Protection domain of DORA3 controls
CodeTitle
DORA-Art.45Information-sharing arrangements on cyber threat information and intelligence
DORA-Art.50Administrative penalties and remedial measures
DORA-Art.56Data protection

Your Compliance Coverage

If you comply with DORA, you already cover:

Maps to 19 other frameworks

26 total controls
EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
12 source controls mapped|15 target controls covered
46%
NIST Cybersecurity Framework 2.0
11 source controls mapped|9 target controls covered
42%
EU Payment Services Directive (PSD2)
8 source controls mapped|4 target controls covered
31%
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
8 source controls mapped|9 target controls covered
31%
NIST SP 800-53 Rev 5
6 source controls mapped|7 target controls covered
23%
EU Markets in Crypto-Assets Regulation (MiCA)
2 source controls mapped|1 target controls covered
8%
EU Cyber Solidarity Act (Regulation (EU) 2025/38)
2 source controls mapped|1 target controls covered
8%
EU Chips Act (Regulation (EU) 2023/1781)
2 source controls mapped|2 target controls covered
8%
ECB TIBER-EU Framework
2 source controls mapped|3 target controls covered
8%
GDPR
1 source controls mapped|2 target controls covered
4%
EU Cyber Resilience Act
1 source controls mapped|2 target controls covered
4%
ISO/IEC 42001:2023
1 source controls mapped|1 target controls covered
4%
ISO 31000:2018
1 source controls mapped|1 target controls covered
4%
ISO 27005:2022
1 source controls mapped|1 target controls covered
4%
ISO/IEC 23894:2023
1 source controls mapped|3 target controls covered
4%
ISO 10006:2003
1 source controls mapped|1 target controls covered
4%
ISO 22301:2019
1 source controls mapped|1 target controls covered
4%
ISO 9001:2015
1 source controls mapped|1 target controls covered
4%
ISO 10005:2005
1 source controls mapped|1 target controls covered
4%

Frequently Asked Questions

What is DORA?

DORA is a compliance framework from European Union with 5 domains and 26 controls. The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, establishing uniform requirements for the security of network and information systems of EU financial entities and critical ICT third-party providers. Covers ICT risk management (governance, framework, identification, protection, detection, response/recovery, backup, learning), ICT-related incident management and major-incident reporting to competent authorities, digital operational resilience testing (including threat-led penetration testing), ICT third-party risk management (Register of Information, key contractual provisions, concentration risk) with a Union Oversight Framework for critical ICT third-party providers, and cyber threat information sharing. Applies from 17 January 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does DORA have?

DORA has 26 controls organised across 5 domains. The largest domains are DORA Chapter II: ICT Risk Management (11 controls), DORA Chapter III: ICT-Related Incident Management (4 controls), DORA Chapter IV: Digital Operational Resilience Testing (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does DORA map to?

DORA maps to 19 other compliance frameworks. The top mapping partners are EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600) (46% coverage), NIST Cybersecurity Framework 2.0 (42% coverage), EU Payment Services Directive (PSD2) (31% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with DORA compliance?

Start your DORA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about DORA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 26 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required