Since 1998

Licensed provider of company formation and corporate services

DORA Compliance for EMIs, PIs and CASPs

ICT risk frameworks, continuity planning, third-party oversight, digital operational resilience testing and training under DORA (Regulation (EU) 2022/2554).A programme that works in daily operations, with the evidence supervisors ask for.

  • Local compliance teams in 4 EU hubs
  • Legal, compliance and ICT expertise
  • 500+ licensing projects
View our approachGet a free assessment

Free, no-obligation assessmentWe reply within 1 business day

3 pillars
Assess, implement, test
7 areas
From ICT risk to training
ISO 27001
Aligned documentation
1 to 2 weeks
To start a gap assessment
RTS / ITS
Aligned with DORA standards

Overview

DORA compliance that works in daily operations

MAXCORP's DORA compliance services, mainly for EMIs, PIs and CASPs, cover ICT risk frameworks, continuity planning (BCP/DR), third-party oversight, ICT scenario testing and TLPT, and staff training. We deliver policies, registers, playbooks, test reports and training records aligned with DORA and ISO 27001, ready for management approval.

DORA compliance documents in a white folder with a shield and network symbol and the MAXCORP logo
  • A gap assessment of ICT governance, continuity and provider contracts, with a prioritised roadmap

  • The full DORA policy set and registers, tailored to how your company actually operates

  • Incident playbooks and reporting procedures aligned with DORA classification and deadlines

  • Third-party oversight: a provider register, due diligence, contract clauses and exit plans

  • Scenario testing, and TLPT scoping where supervisors require it, with the evidence kept on file

  • Training for staff and management, with attendance records you can show in an inspection

Regulators expect more than policies on paper: they ask for tested procedures, evidence and effective oversight of ICT providers. Building this internally takes time and scarce skills, which is why fintechs source their DORA work from us. We start with a gap assessment, then deliver policies, registers, playbooks and test evidence aligned with DORA and ISO 27001. You get a programme that works day to day and stands up to inspection.

Approach

Our three-pillar approach to DORA

A structured method in three pillars. Each step produces documentation and evidence you can show a supervisor, while the framework stays proportionate and workable for daily operations.

1. Readiness and gap assessment

Governance review

ICT governance, risk registers and incident handling assessed.

Continuity and outsourcing

BCP/DR arrangements and provider agreements reviewed.

Remediation roadmap

Prioritised findings with owners, milestones and timelines.

Management baseline

A summary suitable for supervisory discussions.

2. Implementation

Policies and registers

The full DORA set, tailored to your operations.

Governance alignment

Roles, escalation chains and accountability.

Playbooks and controls

Incident, continuity and oversight procedures.

Contract addenda

Audit rights, provider duties and exit strategies.

3. Testing and ongoing compliance

Testing

ICT scenario testing, and TLPT scoping where applicable.

Remediation tracking

Evidence that gaps have been closed.

Training

Staff and management sessions, with attendance records.

Ongoing monitoring

Review cycles and metrics that keep the framework current.

Services

Key services for DORA compliance and ICT risk management

We support every stage of the DORA journey. Each area comes with registers, evidence and reporting, so compliance can be demonstrated and maintained.

ICT risk frameworks and governance

DORA requires a structured ICT risk management framework that shows accountability and proportionality. We design and document it: risk registers that categorise ICT threats, control mappings that link risks to mitigation, and escalation procedures so incidents are reported and handled in time.

Governance is aligned so ICT risks are part of management oversight and board reporting, and you can show that risks are actively monitored, proportionately mitigated and regularly reviewed.

Incident management and continuity planning

You must be able to detect, escalate and recover from ICT disruption within defined timeframes. Two key measures are the Recovery Time Objective (RTO), the maximum time a service may be unavailable, and the Recovery Point Objective (RPO), the maximum tolerable data loss measured in time.

We design incident playbooks, escalation workflows and BCP/DR arrangements covering internal processes and third-party dependencies, run business impact assessments, set measurable recovery objectives and organise exercises that test the plans in practice.

Third-party oversight and testing

DORA puts strong emphasis on ICT providers and outsourcing: a register of providers, due diligence and ongoing assessment, and contracts with audit rights, continuity obligations and exit strategies.

We set up oversight that classifies providers by risk, assesses their continuity arrangements and documents exit plans. Where required, we coordinate digital operational resilience testing, including threat-led penetration testing (TLPT) for entities in scope, and prepare the evidence.

Policy and documentation development

An effective framework needs a maintained and consistent set of policies, procedures and evidence logs covering ICT risk management, incident response, third-party oversight and testing, each mapped to the regulation.

We prepare and adapt the full set, referencing the relevant DORA articles and fitting it into your governance, so staff have clear guidance and audits find fewer ambiguities.

Incident reporting and registers

You must detect ICT incidents, escalate them internally, notify the authority when thresholds are met and keep verifiable records of incidents and remediation.

We implement procedures aligned with DORA's incident classification and notification standards: escalation protocols, incident registers and templates for the initial, intermediate and final reports, plus logs of remediation and test results. For ongoing filing, see Regulatory reporting.

Staff and management training

Staff, management and the board must understand their roles in ICT risk management. Regulators expect structured training, attendance logs and awareness activities.

We run sessions for senior management, compliance teams and operational staff on ICT risk, incident response, third-party oversight and reporting, tailored to your business model and kept up to date as the rules evolve.

Ongoing monitoring and advisory

DORA is a continuous obligation. Frameworks, continuity arrangements and provider oversight must stay current as systems, providers and threats change.

We set up monitoring routines and review schedules: policy reviews, periodic continuity and recovery tests, provider re-assessments and risk register updates, with evidence logs for every review and remediation step. For an outsourced ICT/DORA role, see Compliance officer outsourcing; for an independent check, see Audits & assessments.

FAQ

DORA compliance: frequently asked questions

Which companies face the strictest DORA duties?

DORA applies to all financial entities in scope, but larger institutions and those providing critical services, such as major EMIs, PIs and CASPs, face closer scrutiny. They may be selected for advanced requirements such as threat-led penetration testing (TLPT).

What are the core DORA obligations?

ICT risk management, incident detection and reporting, business continuity and disaster recovery (BCP/DR), third-party oversight, digital operational resilience testing and training. All of it must be documented, tested and demonstrable to the regulator.

When is TLPT required?

TLPT applies to entities that supervisors identify as critical based on their size, systemic importance and risk exposure. For entities selected, it is carried out at least every three years, or more often if the supervisor requires.

How does DORA incident reporting work?

Incidents are classified by severity, and a major ICT incident is reported to the authority in three stages: an initial notification, an intermediate report and a final report, each on a short deadline. The deadlines and how we file them are on Regulatory reporting.

How does DORA relate to GDPR and NIS2?

For financial entities in scope, DORA replaces the cybersecurity and incident-reporting duties of NIS2 (it applies as the more specific law). It does not replace GDPR: one incident can trigger both a DORA report and a GDPR personal data breach notification, so the two procedures should be aligned.

What does DORA expect from ICT providers?

A register of providers, risk assessments and contracts with audit rights, continuity clauses and exit strategies. Providers must be monitored continuously, not only checked once at onboarding.

What evidence do inspectors ask for?

ICT risk registers, incident logs, continuity and recovery test results, third-party oversight records, training logs and management reports. The evidence must show that policies are tested and effective in practice, not only that they exist.

How long does implementation take?

Typically several months, depending on your size, risk profile and ICT maturity. Legacy systems, many third-party providers or advanced testing such as TLPT can extend the timeline. MAXCORP usually starts a gap assessment within 1 to 2 weeks once the scope is agreed.

Contact

Plan your DORA programme

After a short discovery call we send a step-by-step plan and a documentation checklist mapped to your DORA obligations.

What can we help with?

We reply within 1 business day.

By submitting this form you agree to our Privacy Policy. We use your details to reply to your enquiry.

Send an enquiry

Tell us about your project. We reply with next steps and a budget.

By sending this form, you agree to our Privacy Policy.We use your details to reply to your enquiry.

Book a free call

Open in a new tab

Loading the calendar…

Cookie settings

Choose which cookies we may use. Necessary cookies are always on, because the website cannot work securely without them. Cookie Policy