DORA Compliance

DORA has applied since 17 January 2025. If you are a financial entity — banking, insurance, investment services, fund managers, payment and e-money institutions or an authorised crypto-asset service provider — or a third-party ICT provider to one of them, Regulation (EU) 2022/2554 already binds you. There is no transposition to wait for: an EU regulation applies directly.

The five pillars, and where almost everyone gets stuck

ICT risk management. A documented framework, approved and overseen by the management body, with critical or important functions identified. The classic failure here is having policies nobody has ever mapped against real assets.
Incident management and reporting. Classification against materiality criteria and notification to the authority on very short deadlines. If it has not been rehearsed, it will not be met.
Digital operational resilience testing. An annual testing programme and, for entities the authority designates, threat-led penetration testing (TLPT) — the kind of exercise the TIBER-EU framework formalises.
Third-party ICT risk. The register of information you must maintain and report, the minimum contractual clauses of article 30, and a real exit strategy for every critical provider. This is the pillar that generates most work and the one most often underestimated.
Information sharing on cyber threats between financial entities.
The register of information on ICT providers is not a contract inventory: it is a structured data set in a defined format that the authority collects periodically. Entities that built it at the last minute know this.

What we do

Phase 1
Gap analysis
We measure the real distance between what the regulation demands and what you have today, control by control. No generic checklists: we review evidence, not statements of intent.
Phase 2
Action plan
Every gap becomes a task with an owner, an effort estimate and a priority based on risk. You decide what comes first knowing what protects you most.
Phase 3
Remediation
We work alongside you through delivery: policies, procedures, technical controls and evidence, until compliance holds up in front of an auditor.

Scope of work

Identification of critical or important functions and the ICT assets that support them.
Review of the ICT risk management framework against articles 5 to 16 and their regulatory technical standards.
Classification and reporting procedure for major incidents, with materiality criteria applied to your reality rather than copied.
Design of the resilience testing programme: what is tested, how often and how it is documented.
Build or review of the register of information on third-party ICT providers and a contractual gap analysis against article 30.
Exit strategies for providers supporting critical functions.

How we work

1
Scoping
Which group entities are in, which functions are critical or important, and which providers sustain them. Without that map everything else is paperwork.
2
Gap analysis by pillar
We work through all five pillars against evidence: policies, contracts, incident records, test reports. Every finding is referenced to the article that requires it.
3
Prioritised action plan
Ordered by regulatory exposure and by real operational risk, with owners and effort estimates so you can budget it.
4
Supported delivery
Drafting policies and procedures, building the register of information, reviewing contracts and designing the testing programme.
5
Technical testing
When resilience has to be demonstrated, the testing is run by the same offensive team behind our penetration tests and Red Team operations.

What you get

A map of critical or important functions and their dependency on third parties.
Gap analysis by pillar and by article, with maturity level and evidence.
Action plan, prioritised and budgetable.
Register of information on ICT providers in the required format.
Contractual gap report against article 30, clause by clause.
Resilience testing programme, documented and defensible in front of the supervisor.
Who does the work. The same team that audits, not an account manager. Governance, risk and compliance: CISSP, CISM, ISO 27001 Lead Auditor, ENS and Risk Analysis (CCN), certified DPO, CCSP and CDPP (ISMS Forum) and PMP (PMI). On the technical side: OSCP, CRTO II and eWPTX, ranked in the top 1% of the CCN-CERT Atenea platform. We have run compliance projects for crypto exchanges, universities and public administrations.

Questions we get asked

We are small. Does DORA still apply?
The regulation applies proportionality: the depth of the requirement scales with size, risk profile and the nature of the activity. What does not scale is the obligation to have the framework. The difference is in depth, not in existence.
We are an ICT provider to a bank. What lands on us?
The requirements will reach you through contracts: audit rights, service levels, incident notification, subcontracting and exit strategy. Financial entities are renegotiating contracts right now, and arriving with the evidence ready sets you apart from other providers.
Do you run the TLPT?
We run threat-led penetration testing with the same team behind our Red Team operations. If your competent authority designates you for a formal exercise under a supervised framework, we prepare you for it and support you technically.
We already comply with ISO 27001. Does that help?
It helps as a base for the ICT risk management pillar, but DORA adds three things those frameworks do not cover in that detail: the third-party register of information, the article 30 contractual requirements and the formal testing programme. That is where we focus the effort.
Put a number on your DORA gap
Half an hour with an auditor to scope it: which entities are in, which functions are critical and where a useful gap analysis would start.

Book 30 min with an auditor

Phone: +34 686 250 244 (Mon-Fri, 9:00 to 18:00 CET)  ·  Email: info@jaymonsecurity.com
We reply within 2 working hours.
Spain