REGULIX.ai
Regulix › DORA compliance software
Regulation (EU) 2022/2554

DORA compliance software for financial entities and CASPs

Nineteen obligations across twelve control areas of Regulation (EU) 2022/2554, assessed from a read-only connection, with the governing article cited on every finding.

Start a free assessment Browse the regulation library

What DORA requires

The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since 17 January 2025. It makes information and communication technology resilience a binding, supervised obligation for financial entities across the Union, and crypto-asset service providers authorised under MiCA fall within its scope.

DORA is organised around five pillars:

The obligations Regulix assesses

The engine encodes nineteen DORA obligations across twelve control areas, spanning Chapters II to V. Each is assessed independently and returns a pass or a finding with the governing article and a remediation.

Control areaArticles
Governance and management-body oversightArt 5
ICT risk management framework, systems and toolsArt 6 to 7
Identification of assets and dependenciesArt 8
Protection and preventionArt 9
Detection of anomalous activityArt 10
Response, recovery, backup and continuityArt 11 to 12
Learning and evolvingArt 13
Crisis communicationArt 14
Incident management and classificationArt 17 to 18
Major-incident and payment-incident reportingArt 19, 23
Resilience and threat-led testingArt 24 to 27
Third-party risk, concentration and contractsArt 28 to 30

The register of information

Article 28(3) requires financial entities to maintain a register of information on all contractual arrangements with ICT third-party service providers, aligned to the template set by the European Supervisory Authorities and kept current as contracts change.

In practice this is one of the most commonly incomplete DORA controls, because it drifts the moment a contract is signed, renewed or terminated without the register being updated. Regulix tests whether the register exists and flags it as a finding with the governing article when it is not current.

What this does not do

Regulix provides configuration-level and attestation-level assurance. It assesses whether a control is present and evidenced, not whether it is operationally effective under adversarial conditions. Threat-led penetration testing under Articles 26 and 27, where an entity is designated significant, remains a separate exercise conducted by qualified testers.

The engine also does not cover the simplified framework under Article 16, which is an alternative regime for certain smaller entities, or the oversight framework for critical ICT third-party providers in Articles 31 to 44, which binds the providers and the supervisory authorities rather than the financial entity.

Saying so plainly matters more in this category than a longer feature list. A compliance tool that overstates its scope creates exactly the exposure it is meant to remove.

Frequently asked questions

When did DORA start to apply?

DORA has applied since 17 January 2025. It is already binding on financial entities within scope, including crypto-asset service providers authorised under MiCA.

Does DORA apply to crypto-asset service providers?

Yes. CASPs authorised under MiCA fall within the definition of financial entities in DORA, so the ICT risk management, incident reporting, resilience testing and third-party risk obligations apply.

What is the DORA register of information?

A register of all contractual arrangements with ICT third-party service providers, required by Article 28(3) and aligned to the template published by the European Supervisory Authorities. It has to be kept current as contracts change.

How many DORA obligations does Regulix assess?

Nineteen obligations across twelve control areas, covering Chapters II to V. Voluntary information sharing under Article 45 is not scored as an obligation, and the simplified framework and critical-provider oversight regime are outside scope.

Is this a substitute for a DORA audit?

No. It is a readiness and evidence layer. It shows continuously where your controls stand against each obligation and produces the evidence pack. A supervisory examination or an independent audit tests effectiveness, which is a different exercise.

Related

MiCA compliance software EU AI Act compliance software Regulatory intelligence library The Regulix platform

See where your firm stands

Connect a read-only data source and get a provision-level assessment across DORA and the other frameworks that apply to you.

Regulix provides decision support and evidence for compliance functions. It does not constitute legal advice, and it does not replace authorisation by a competent authority or sign-off by qualified counsel.