SECaaS.IT

DORA

DORA: your ICT risk management framework on one platform instead of spreadsheets.

Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) has applied directly since 17 January 2025 — without national implementing legislation. Banks, insurers, investment firms, payment service providers and their critical ICT third-party providers are affected. PRISM builds your ICT risk management framework on the same control and evidence foundation that 200+ organisations already use for ISO 27001 and BSI C5.

Why now

  • • Received a supervisory or BaFin enquiry about your ICT risk management?
  • • Customer requires inclusion in the register of information?
  • • As a critical ICT service provider requested by a financial entity to provide DORA proof?

DORA has applied since 17.01.2025 as an EU regulation — unlike NIS 2, without national implementing legislation. The register of contractual arrangements with ICT third-party providers (Register of Information) is subject to reporting; supervision of critical ICT third-party providers is being rolled out.

What PRISM brings to your DORA framework

A standalone DORA control catalogue is not available pre-packaged — the underlying crosswalk and gap analysis engine is. New catalogues can typically be built on request within around two weeks.

ICT Risk Management

DORA compliance structured — ICT risks documented and audit-proof.

DORA requires a formal ICT risk framework, incident reporting, TLPT and third-party risk management. PRISM ISO maps the Pillar 1 to 5 requirements as executable measures — audit-proof for regulators and auditors.

DORA Pillar 1–5 ICT Risk Framework Incident Reporting
PRISM ISO — DORA ICT Risk Framework

Who is this for?

Yes, if

  • Bank, insurer, investment firm or payment service provider under Art. 2 DORA
  • Critical ICT third-party provider for financial entities (cloud, SaaS, data centre, software)
  • Already have ISO 27001 or BSI C5 in house — DORA builds on existing controls
  • Goal: maintain controls once, demonstrate to supervisors and customers jointly

Not suitable

  • Large institutions with their own GRC stack and dedicated ICT incident reporting tool
  • Pure consulting relationship without software use

Many DORA requirements on ICT risk management overlap with BSI C5 and ISO/IEC 27001 — with the C5 crosswalk and the ISO 27001 foundation you maintain controls once and reuse them.

Frequently asked questions about DORA

What is DORA?
The Digital Operational Resilience Act (DORA) is an EU regulation that has applied to financial entities and their IT service providers since January 2025. It sets out requirements for ICT risk management, incident reporting, resilience testing (TLPT) and third-party risk management (TPRM).
Who does DORA apply to?
DORA applies to banks, insurers, investment firms, payment service providers, crypto-asset service providers, credit rating agencies and critical ICT third-party providers. Companies that supply IT services to regulated financial institutions also fall under the requirements as critical DORA third-party providers.
What do I need to implement in practice?
DORA structures requirements across five pillars: ICT risk management (Pillar 1), incident reporting and classification (Pillar 2), digital operational resilience testing including TLPT (Pillar 3), third-party risk management (Pillar 4) and information sharing (Pillar 5). PRISM ISO maps all five pillars as controls.
From when does DORA apply?
DORA has been mandatory since January 2025. Additional transition periods for registration with the Lead Overseer are running for critical ICT third-party providers. Organisations that are not yet compliant should start with a gap analysis now.
How does PRISM ISO help with DORA?
PRISM ISO structures DORA requirements as executable controls with owners, deadlines and audit-proof evidence. The multi-framework crosswalk automatically transfers controls you have already fulfilled for ISO 27001 or NIS 2 to DORA — eliminating significant duplication of effort.

Software alone — or with consultant and auditor?

Three tiers, one goal: your DORA proof. From a licence to a fixed-price package with auditor included.

Compare packages →

So geht PRISM vor

Von der Lücke bis zum laufenden Betrieb.

Vier Phasen, eine Plattform — kein Wechsel zwischen Tools, keine Lücken zwischen Phasen.

Wo stehen Sie heute?
Was muss sich ändern?
Was können Sie dem Auditor zeigen?
Was passiert nach dem Audit?

Wo stehen Sie heute?

PRISM bewertet Ihre bestehenden Dokumente, Prozesse und Kontrollen gegen alle Anforderungen der DORA. Jede Lücke kommt mit Begründung und direktem Link zur Maßnahme — kein manuelles Zusammensuchen.

Was muss sich ändern?

Aus der Analyse entstehen priorisierte Maßnahmen mit Verantwortlichen, Fristen und Fortschrittsanzeige. Was kritisch ist, steht oben. Verantwortlichkeiten sind klar zugewiesen — kein Aufgaben-Ping-Pong.

Was können Sie dem Auditor zeigen?

Richtlinien, Kontrollen und Evidenz werden norm-konform verwaltet und auf Audit-Bereitschaft geprüft. Das Evidenz-Paket entsteht auf Knopfdruck — mit revisionssicherer Änderungshistorie.

Was passiert nach dem Audit?

PRISM läuft nicht bis zum Zertifikat — danach erst richtig. Wiederkehrende Aufgaben, Monitoring, Vorfallmanagement und DORA-Überwachungsaudits bleiben in der Plattform. Das ISMS bleibt lebendig.

Was unsere Kunden sagen

„Der Security Health Check war sehr effizient und zielführend und half uns, Transparenz zu schaffen."

Johannes Beier

IT-Leiter · B2B Medical

Security Health Check

Alle Fallstudien lesen →

Trusted by

  • Logo GIZ
  • Logo varisano Kliniken
  • Logo Kath. St. Paulus Gesellschaft
  • Logo Planfox
  • Logo iS2
  • Logo CareSocial
  • Logo EuroTax Consulting
  • Logo nubedian
  • Logo Ypsilon
  • Logo BFMT
  • Logo Haub + Partner
  • Logo DYNAMED
  • Logo B2B Medical

Let's build your ICT risk management framework for DORA.

In the initial call we clarify how the crosswalk engine fits your DORA requirements.