Framework
Full specification

DORA

Oh no! No description found. But not to worry. Read from Tasks below how to advance this topic.

The Digital Operational Resilience Act (DORA) is the EU law on digital operational resilience. It aims to strengthen resilience in all aspects of financial institutions.

The Digital Operational Resilience Act (DORA) is the EU law on digital operational resilience. DORA aims to achieve a uniform high level of digital resilience across the EU. It sets out uniform requirements for information networks and systems that support financial business processes.

DORA sets out requirements for, among other things, protection, detection, isolation, recovery and remediation in the event of a security incident. Further requirements include extensive risk and incident management, cyber threat and vulnerability sharing, requirements for resilience testing and reporting incidents to authorities.

Tasks
28
Scope
EU
Here's what
DORA
requires and how to comply.

Below you'll find all of the requirements of this framework. In Cyberday, we map all requirement to global tasks, making multi-compliance management easy. Do it once, and see the progress across all frameworks!

Requirements
Article 5: Governance and organisation
Article 6: ICT risk management framework
Article 8: Identification
Article 9b: Prevention
Article 10: Detection
Article 11: Response and recovery
Article 12: Backup policies and procedures, restoration and recovery procedures and methods
Article 13: Learning and evolving
Article 14: Communication
Article 17: ICT-related incident management process
Article 18: Classification of ICT-related incidents and cyber threats
Article 19: Reporting of major ICT-related incidents and voluntary notification of significant cyber threats
Article 24: General requirements for the performance of digital operational resilience testing
Article 25: Testing of ICT tools and systems
Article 26: Advanced testing of ICT tools, systems and processes based on TLPT
Article 27: Requirements for testers for the carrying out of TLPT
DORA
learning hub

Explore our comprehensive resources and improve your security with the themes of this framework.

How Cyberday helps with
DORA

Discover specific ways our platform streamlines your ISO 27001 compliance process, from automated controls to audit preparation.

Explore use case
Free
DORA
assessment

Take our comprehensive assessment to identify gaps in your current implementation and get personalized recommendations.

Start assessment
Read more about
DORA

Dive deeper with our articles, case studies, and expert insights on framework implementation.

Read article
Guide to compliance

Get a concise overview of all requirements, controls, and implementation steps in our quick guide.

Get the guide
Framework comparison

See how the overlap and differences with any other framework to optimize your compliance strategy.

Compare framework
Join a live
DORA
webinar

Participate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.

Register for webinar
Join our live webinars

Participate in expert-led sessions covering implementation strategies, common pitfalls, and best practices for compliance.

Register for webinar
What are frameworks?

Understand the basics of cyber security frameworks with our comprehensive guide.

Read the article

The ISMS component hierachy

When building an ISMS, it's important to understand the different levels of information hierarchy. Here's how Cyberday is structured.

Framework

Sets the overall compliance standard or regulation your organization needs to follow.

Requirements

Break down the framework into specific obligations that must be met.

Tasks

Concrete actions and activities your team carries out to satisfy each requirement.

Policies

Documented rules and practices that are created and maintained as a result of completing tasks.

Never duplicate effort. Do it once - improve compliance across frameworks.

Reach multi-framework compliance in the simplest possible way
Security frameworks tend to share the same core requirements - like risk management, backup, malware, personnel awareness or access management.
Cyberday maps all frameworks’ requirements into shared tasks - one single plan that improves all frameworks’ compliance.
Do it once - we automatically apply it to all current and future frameworks.