Enforcement Active Since Jan 2025

The DORA
Compliance Hub

Free tools, authoritative resources, and vetted provider matching for EU financial entities navigating the Digital Operational Resilience Act.

DORA is not a future obligation — it's active law. Supervisory authorities are enforcing. Use our tools to assess your posture, understand your requirements, and connect with qualified testing providers.

22,000+
Financial entities in scope
across the EU
€10M
Maximum fine per violation
or 1% daily turnover
3 Years
TLPT cycle for significant entities
Art. 26 DORA
4 Hours
Incident initial notification
major ICT incidents

Latest DORA Updates

Regulatory news, guidance, and enforcement developments

All Updates →
Q1 2026
Enforcement

ESA Supervisory Convergence Report on DORA Implementation

Joint ESA report highlights consistent enforcement gaps in ICT third-party risk registers and incident classification across EU member states.

Dec 2025
Guidance

EBA Publishes Updated Q&A on TLPT Scope Determination

Clarifications on which entities meet the significance threshold for mandatory TLPT, including revised guidance on cross-border operations.

Oct 2025
Framework

TIBER-EU Framework v2.1 Released by ECB

Updated TIBER-EU framework aligns with DORA RTS on TLPT, introducing mandatory purple teaming requirements and revised threat intelligence standards.

Vetted Network

Need a TLPT Provider?

Finding a qualified, DORA-compliant TLPT provider is not straightforward. Providers must meet strict requirements under DORA Article 26 and the ESA Joint RTS on TLPT.

  • Pre-vetted against DORA Article 26 tester requirements
  • Experience with TIBER-EU / TIBER-XX national frameworks
  • Coordinated intelligence-led testing approach
  • Post-test remediation support included
Find a Provider

Get Matched Free

Tell us your requirements and we'll connect you with a qualified provider within 24 hours.

By submitting, you agree to our Privacy Policy

Which Entities Are In Scope?

DORA Article 2 defines the scope. If your organisation is in this list and operates in or serves the EU market, compliance is mandatory.

Credit Institutions
Investment Firms
Insurance Undertakings
Payment Institutions
E-Money Institutions
Crypto-Asset Service Providers
ICT Third-Party Providers
Credit Rating Agencies
Trade Repositories
Check My Compliance Status

Free, instant, no registration required for initial results

DORA's Five Compliance Pillars

The regulation is structured around five core pillars. Each financial entity must demonstrate compliance across all relevant areas.

01

ICT Risk Management

Arts. 5–16

Governance framework, risk appetite, and ICT asset management.

02

Incident Reporting

Arts. 17–23

Major ICT incident classification, reporting timelines, and notifications.

03

Digital Resilience Testing

Arts. 24–27

Vulnerability assessments, penetration testing, and mandatory TLPT.

04

Third-Party Risk

Arts. 28–44

Contractual requirements, oversight of critical ICT providers.

05

Intelligence Sharing

Art. 45

Voluntary sharing of cyber threat information within the EU.