Tracks
DORAOperational resilienceExpert

DORA Compliance

The five pillars, article by article, deliverable by deliverable

DORA is not a documentation exercise: the regulation makes the management body personally accountable, imposes a register of information of unprecedented granularity, and sets notification deadlines that are not negotiable. This path walks the five pillars starting from the deliverables a supervisor expects, not from the structure of the text.

What you will be able to do

  • Determine the scope of application and argue proportionality
  • Build an ICT risk framework the board can approve
  • Classify and report a major incident within the deadlines
  • Produce a register of information matching the authorities' template
  • Structure a testing programme, including TLPT

Intended audience

  • EU financial entities
  • ICT providers to the financial sector
  • Compliance and risk
  • Board members

Courses in this track

  1. 1DR-101FoundationFreeDORA at a glanceFive pillars, twenty entity categories, one personal accountability 4 lessons 50 min
  2. 2DR-201PractitionerICT risk management frameworkArticles 5 to 16: what the board must be able to approve 4 lessons 51 min
  3. 3DR-202PractitionerIncident classification and reportingThe clock starts at classification, not at detection 3 lessons 45 min
  4. 4DR-301ExpertICT third-party risk and register of informationThe most underestimated deliverable in the regulation 3 lessons 39 min
  5. 5DR-302ExpertResilience testing and TLPTFrom the mandatory annual test to authority-supervised red teaming 3 lessons 40 min