← Tracks
DORAOperational resilienceExpert
DORA Compliance
The five pillars, article by article, deliverable by deliverable
DORA is not a documentation exercise: the regulation makes the management body personally accountable, imposes a register of information of unprecedented granularity, and sets notification deadlines that are not negotiable. This path walks the five pillars starting from the deliverables a supervisor expects, not from the structure of the text.
What you will be able to do
- Determine the scope of application and argue proportionality
- Build an ICT risk framework the board can approve
- Classify and report a major incident within the deadlines
- Produce a register of information matching the authorities' template
- Structure a testing programme, including TLPT
Intended audience
- EU financial entities
- ICT providers to the financial sector
- Compliance and risk
- Board members
Courses in this track
- 1DR-101FoundationFreeDORA at a glanceFive pillars, twenty entity categories, one personal accountability 4 lessons 50 min
- 2DR-201PractitionerICT risk management frameworkArticles 5 to 16: what the board must be able to approve 4 lessons 51 min
- 3DR-202PractitionerIncident classification and reportingThe clock starts at classification, not at detection 3 lessons 45 min
- 4DR-301ExpertICT third-party risk and register of informationThe most underestimated deliverable in the regulation 3 lessons 39 min
- 5DR-302ExpertResilience testing and TLPTFrom the mandatory annual test to authority-supervised red teaming 3 lessons 40 min