Back to Frameworks
European Union
v2022
5 domains
26 controls

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, establishing uniform requirements for the security of network and information systems of EU financial entities and critical ICT third-party providers. Covers ICT risk management (governance, framework, identification, protection, detection, response/recovery, backup, learning), ICT-related incident management and major-incident reporting to competent authorities, digital operational resilience testing (including threat-led penetration testing), ICT third-party risk management (Register of Information, key contractual provisions, concentration risk) with a Union Oversight Framework for critical ICT third-party providers, and cyber threat information sharing. Applies from 17 January 2025.

Verified

DORA is a compliance framework from European Union with 5 domains and 26 controls that map to 35 other frameworks. The largest domains are DORA Chapter II: ICT Risk Management (11 controls), DORA Chapter III: ICT-Related Incident Management (4 controls), DORA Chapter IV: Digital Operational Resilience Testing (4 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

DORA Chapter II: ICT Risk Management

11 controls
Controls in the DORA Chapter II: ICT Risk Management domain of DORA11 controls
CodeTitle
DORA-Art.10Detection
DORA-Art.11Response and recovery
DORA-Art.12Backup policies and procedures, restoration and recovery
DORA-Art.13Learning and evolving
DORA-Art.14Communication
DORA-Art.16Simplified ICT risk management framework
DORA-Art.5Governance and organisation
DORA-Art.6ICT risk management framework
DORA-Art.7ICT systems, protocols and tools
DORA-Art.8Identification
DORA-Art.9Protection and prevention

DORA Chapter III: ICT-Related Incident Management

4 controls
Controls in the DORA Chapter III: ICT-Related Incident Management domain of DORA4 controls
CodeTitle
DORA-Art.17ICT-related incident management process
DORA-Art.18Classification of ICT-related incidents and cyber threats
DORA-Art.19Reporting of major ICT-related incidents
DORA-Art.23Operational or security payment-related incidents

DORA Chapter IV: Digital Operational Resilience Testing

4 controls
Controls in the DORA Chapter IV: Digital Operational Resilience Testing domain of DORA4 controls
CodeTitle
DORA-Art.24General requirements for the performance of digital operational resilience testing
DORA-Art.25Testing of ICT tools and systems
DORA-Art.26Advanced testing of ICT tools, systems and processes based on TLPT
DORA-Art.27Requirements for testers for the carrying out of TLPT

DORA Chapter V: ICT Third-Party Risk Management

4 controls
Controls in the DORA Chapter V: ICT Third-Party Risk Management domain of DORA4 controls
CodeTitle
DORA-Art.28ICT third-party risk: general principles
DORA-Art.29Preliminary assessment of ICT concentration risk at entity level
DORA-Art.30Key contractual provisions
DORA-Art.31Designation of critical ICT third-party service providers

DORA Chapters VI-VII: Information Sharing, Penalties and Data Protection

3 controls
Controls in the DORA Chapters VI-VII: Information Sharing, Penalties and Data Protection domain of DORA3 controls
CodeTitle
DORA-Art.45Information-sharing arrangements on cyber threat information and intelligence
DORA-Art.50Administrative penalties and remedial measures
DORA-Art.56Data protection

Your Compliance Coverage

If you comply with DORA, you already cover:

Maps to 35 other frameworks

26 total controls
FedRAMP Moderate
26 source controls mapped|76 target controls covered
100%
NIST SP 800-53 Revision 5.1 HIGH
26 source controls mapped|69 target controls covered
100%
FedRAMP High
26 source controls mapped|75 target controls covered
100%
NIST SP 800-53 Rev 5
26 source controls mapped|57 target controls covered
100%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
26 source controls mapped|84 target controls covered
100%
NIST SP 800-53 Rev 5 MODERATE
25 source controls mapped|68 target controls covered
96%
CIS Controls v8
25 source controls mapped|48 target controls covered
96%
ISO 27002:2022
25 source controls mapped|53 target controls covered
96%
ISO 27001:2022
25 source controls mapped|53 target controls covered
96%
NIST Cybersecurity Framework 2.0
24 source controls mapped|61 target controls covered
92%
SOC 2
24 source controls mapped|46 target controls covered
92%
NIS2 Directive
24 source controls mapped|24 target controls covered
92%
NIST SP 800-53 Rev 5 LOW
23 source controls mapped|53 target controls covered
88%
C5 (Germany)
21 source controls mapped|63 target controls covered
81%
NIST SP 800-161 Rev 1
18 source controls mapped|58 target controls covered
69%
CFTC System Safeguards (17 CFR 37, 38, 39, 49)
17 source controls mapped|35 target controls covered
65%
APRA CPS 230 Operational Risk Management
16 source controls mapped|40 target controls covered
62%
GDPR
13 source controls mapped|11 target controls covered
50%
EIOPA Guidelines on ICT Security and Governance (EIOPA-BoS-20/600)
12 source controls mapped|15 target controls covered
46%
EU AI Act
10 source controls mapped|11 target controls covered
38%
EU Payment Services Directive (PSD2)
8 source controls mapped|4 target controls covered
31%
EBA Guidelines on ICT and Security Risk Management (EBA/GL/2024/07)
8 source controls mapped|9 target controls covered
31%
EU Chips Act (Regulation (EU) 2023/1781)
2 source controls mapped|2 target controls covered
8%
EU Cyber Solidarity Act (Regulation (EU) 2025/38)
2 source controls mapped|1 target controls covered
8%
EU Markets in Crypto-Assets Regulation (MiCA)
2 source controls mapped|1 target controls covered
8%
ECB TIBER-EU Framework
2 source controls mapped|3 target controls covered
8%
EU Cyber Resilience Act
1 source controls mapped|2 target controls covered
4%
ISO/IEC 42001:2023
1 source controls mapped|1 target controls covered
4%
ISO 31000:2018
1 source controls mapped|1 target controls covered
4%
ISO 27005:2022
1 source controls mapped|1 target controls covered
4%
ISO/IEC 23894:2023
1 source controls mapped|3 target controls covered
4%
ISO 10006:2003
1 source controls mapped|1 target controls covered
4%
ISO 10005:2005
1 source controls mapped|1 target controls covered
4%
ISO 9001:2015
1 source controls mapped|1 target controls covered
4%
ISO 22301:2019
1 source controls mapped|1 target controls covered
4%

What is DORA and who does it apply to?

DORA is a compliance framework from European Union with 5 domains and 26 controls. The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, establishing uniform requirements for the security of network and information systems of EU financial entities and critical ICT third-party providers. Covers ICT risk management (governance, framework, identification, protection, detection, response/recovery, backup, learning), ICT-related incident management and major-incident reporting to competent authorities, digital operational resilience testing (including threat-led penetration testing), ICT third-party risk management (Register of Information, key contractual provisions, concentration risk) with a Union Oversight Framework for critical ICT third-party providers, and cyber threat information sharing. Applies from 17 January 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does DORA actually require?

DORA has 26 controls organised across 5 domains. The largest domains are DORA Chapter II: ICT Risk Management (11 controls), DORA Chapter III: ICT-Related Incident Management (4 controls), DORA Chapter IV: Digital Operational Resilience Testing (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of DORA do I already cover?

DORA maps to 35 other compliance frameworks. The top mapping partners are FedRAMP Moderate (100% coverage), NIST SP 800-53 Revision 5.1 HIGH (100% coverage), FedRAMP High (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement DORA?

Start your DORA compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about DORA requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 26 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required