DORA Compliance

Digital Operational Resilience Act (EU Regulation 2022/2554)

DORA Compliance Status: Compliant
Effective Date: January 17, 2025 | Last Assessment: November 2025 | Next Review: February 2026
Active Compliance

Requirement Coverage

97.4%

38/39 requirements met

System Uptime

99.98%

last 12 months

Mean Time to Recovery

28 minutes

average resolution time

Major Incidents

0

in the last 12 months

DORA Compliance Pillars

PillarArticlesDescriptionRequirementsImplementedStatus
ICT Risk Management
Articles 5-16Framework for managing ICT-related risks across the organization1212
Compliant
ICT-Related Incident Management
Articles 17-23Classification, reporting, and response to ICT incidents88
Compliant
Digital Operational Resilience Testing
Articles 24-27Testing programs including threat-led penetration testing65
Partial
ICT Third-Party Risk Management
Articles 28-44Managing risks from ICT third-party service providers1010
Compliant
Information Sharing
Article 45Cyber threat intelligence and information sharing arrangements33
Compliant
Total3938
97.4%

ICT Systems

Asset Inventory
Complete
Critical Systems Identified12
Configuration Management
Active
Change Management
Enforced

Incident Response

Response Plan
Documented
Classification Framework
Active
Communication Procedures
Defined
Root Cause Analysis
Required

Data Protection

Data Classification
Complete
Encryption at Rest
AES-256
Backup Strategy
3-2-1
Data Retention
Compliant

Critical & Important ICT Third-Party Providers

ProviderServiceCriticalityLocationContract EndLast AssessmentRisk
Amazon Web Services (AWS)Cloud Infrastructure
Critical
EU (Frankfurt)December 2027October 2025
Low
Microsoft AzureDisaster Recovery
Critical
EU (Amsterdam)June 2026September 2025
Low
RefinitivMarket Data
Important
UK (London)March 2026August 2025
Low
BloombergTrading & Analytics
Important
US (New York)December 2025November 2025
Low
CloudflareDDoS Protection & CDN
Important
GlobalSeptember 2026July 2025
Low

Digital Operational Resilience Testing Schedule

Test TypeFrequencyLast TestNext TestStatus
Vulnerability AssessmentMonthlyNovember 2025December 2025
On Track
Penetration TestingQuarterlyOctober 2025January 2026
On Track
Threat-Led Penetration Testing (TLPT)TriennialJuly 2025July 2028
Completed
Disaster Recovery TestSemi-AnnualSeptember 2025March 2026
On Track
Business Continuity ExerciseAnnualJune 2025June 2026
On Track

Recent ICT Incidents

API latency spike (95th percentile > 500ms)
November 5, 2025 | Duration: 45 minutes
Minor
Resolved
Database failover triggered during maintenance
October 12, 2025 | Duration: 12 minutes
Minor
Resolved
Proactive patching - zero downtime deployment
September 28, 2025 | Duration: 0 minutes
Maintenance
Completed

DORA Regulatory Reporting Requirements

Major ICT Incident Reporting
Major ICT-related incidents must be reported to the competent authority (NCA) within prescribed timeframes: Initial notification within 4 hours, intermediate report within 72 hours, final report within 1 month.
Register of ICT Third-Party Providers
Maintain and submit a register of information on all contractual arrangements with ICT third-party service providers, identifying critical or important functions supported.
Threat-Led Penetration Testing
Significant financial entities must conduct advanced testing using TIBER-EU framework at least every 3 years, with results reported to the competent authority.
Competent Authority
  • Primary NCA: Irish Central Bank (CBI)
  • Lead Overseer: European Supervisory Authorities (ESAs)
  • DORA Reporting Portal: Active
  • Last Submission: November 2025
Key Deadlines
  • ICT Third-Party Register: Annual (Q1)
  • TLPT Report: Every 3 years (Next: 2028)
  • ICT Risk Framework Review: Annual
  • Incident Classification Report: On occurrence