Advisory·DORA Readiness

EU DORA Readiness Assessment.

A focused assessment of your readiness for EU DORA obligations — covering all five pillars of the regulation, with output calibrated to the applicable RTS and ITS technical standards.

Request this engagement
The five DORA pillars

Assessed against every technical standard.

The DORA Readiness Assessment covers all five regulatory pillars, with findings mapped to the applicable Regulatory Technical Standards and Implementing Technical Standards.

Pillar I

ICT Risk Management

Assessment of your ICT risk management framework against DORA Article 5–16 and the associated RTS — including governance, strategy, and risk appetite.

Pillar II

ICT-Related Incident Management

Review of incident classification, reporting workflows, and notification timelines against DORA Article 17–23 and the incident reporting ITS.

Pillar III

Digital Operational Resilience Testing

Assessment of your TLPT programme and vulnerability testing arrangements against DORA Article 24–27 and the TLPT RTS.

Pillar IV

ICT Third-Party Risk

Review of third-party risk management arrangements, contractual provisions, and the register of information against DORA Article 28–44.

Pillar V

Information-Sharing Arrangements

Assessment of your threat intelligence sharing arrangements and participation in sector information-sharing frameworks.

Ready to assess your DORA position?

Speak to a principal about commissioning a DORA readiness assessment for your organisation.

Speak to us