DORA compliance software for financial entities and CASPs
Nineteen obligations across twelve control areas of Regulation (EU) 2022/2554, assessed from a read-only connection, with the governing article cited on every finding.
What DORA requires
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since 17 January 2025. It makes information and communication technology resilience a binding, supervised obligation for financial entities across the Union, and crypto-asset service providers authorised under MiCA fall within its scope.
DORA is organised around five pillars:
- ICT risk management, Articles 5 to 15, covering governance, the risk framework, asset identification, protection, detection, response, recovery, learning and communication
- ICT-related incident management and reporting, Articles 17 to 23, including classification and major-incident notification
- Digital operational resilience testing, Articles 24 to 27, including threat-led penetration testing for entities designated significant
- ICT third-party risk management, Articles 28 to 30, including the register of information and required contractual provisions
- Information and intelligence sharing, Article 45, which is voluntary
The obligations Regulix assesses
The engine encodes nineteen DORA obligations across twelve control areas, spanning Chapters II to V. Each is assessed independently and returns a pass or a finding with the governing article and a remediation.
| Control area | Articles |
|---|---|
| Governance and management-body oversight | Art 5 |
| ICT risk management framework, systems and tools | Art 6 to 7 |
| Identification of assets and dependencies | Art 8 |
| Protection and prevention | Art 9 |
| Detection of anomalous activity | Art 10 |
| Response, recovery, backup and continuity | Art 11 to 12 |
| Learning and evolving | Art 13 |
| Crisis communication | Art 14 |
| Incident management and classification | Art 17 to 18 |
| Major-incident and payment-incident reporting | Art 19, 23 |
| Resilience and threat-led testing | Art 24 to 27 |
| Third-party risk, concentration and contracts | Art 28 to 30 |
The register of information
Article 28(3) requires financial entities to maintain a register of information on all contractual arrangements with ICT third-party service providers, aligned to the template set by the European Supervisory Authorities and kept current as contracts change.
In practice this is one of the most commonly incomplete DORA controls, because it drifts the moment a contract is signed, renewed or terminated without the register being updated. Regulix tests whether the register exists and flags it as a finding with the governing article when it is not current.
What this does not do
Regulix provides configuration-level and attestation-level assurance. It assesses whether a control is present and evidenced, not whether it is operationally effective under adversarial conditions. Threat-led penetration testing under Articles 26 and 27, where an entity is designated significant, remains a separate exercise conducted by qualified testers.
The engine also does not cover the simplified framework under Article 16, which is an alternative regime for certain smaller entities, or the oversight framework for critical ICT third-party providers in Articles 31 to 44, which binds the providers and the supervisory authorities rather than the financial entity.
Saying so plainly matters more in this category than a longer feature list. A compliance tool that overstates its scope creates exactly the exposure it is meant to remove.
Frequently asked questions
When did DORA start to apply?
DORA has applied since 17 January 2025. It is already binding on financial entities within scope, including crypto-asset service providers authorised under MiCA.
Does DORA apply to crypto-asset service providers?
Yes. CASPs authorised under MiCA fall within the definition of financial entities in DORA, so the ICT risk management, incident reporting, resilience testing and third-party risk obligations apply.
What is the DORA register of information?
A register of all contractual arrangements with ICT third-party service providers, required by Article 28(3) and aligned to the template published by the European Supervisory Authorities. It has to be kept current as contracts change.
How many DORA obligations does Regulix assess?
Nineteen obligations across twelve control areas, covering Chapters II to V. Voluntary information sharing under Article 45 is not scored as an obligation, and the simplified framework and critical-provider oversight regime are outside scope.
Is this a substitute for a DORA audit?
No. It is a readiness and evidence layer. It shows continuously where your controls stand against each obligation and produces the evidence pack. A supervisory examination or an independent audit tests effectiveness, which is a different exercise.
Related
See where your firm stands
Connect a read-only data source and get a provision-level assessment across DORA and the other frameworks that apply to you.
Regulix provides decision support and evidence for compliance functions. It does not constitute legal advice, and it does not replace authorisation by a competent authority or sign-off by qualified counsel.