DORA
DORA: your ICT risk management framework on one platform instead of spreadsheets.
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA) has applied directly since 17 January 2025 — without national implementing legislation. Banks, insurers, investment firms, payment service providers and their critical ICT third-party providers are affected. PRISM builds your ICT risk management framework on the same control and evidence foundation that 200+ organisations already use for ISO 27001 and BSI C5.
Why now
- • Received a supervisory or BaFin enquiry about your ICT risk management?
- • Customer requires inclusion in the register of information?
- • As a critical ICT service provider requested by a financial entity to provide DORA proof?
DORA has applied since 17.01.2025 as an EU regulation — unlike NIS 2, without national implementing legislation. The register of contractual arrangements with ICT third-party providers (Register of Information) is subject to reporting; supervision of critical ICT third-party providers is being rolled out.
What PRISM brings to your DORA framework
A standalone DORA control catalogue is not available pre-packaged — the underlying crosswalk and gap analysis engine is. New catalogues can typically be built on request within around two weeks.
- ICS module as the basis for your ICT risk management framework (DORA Art. 5–16)
- Multi-framework crosswalk: fulfil ISO 27001 and C5 controls once, apply to DORA requirements
- Risk management with AI reassessment — for ICT risks and third-party risks
- Asset register for critical ICT service providers — contracts, dependencies and controls in one place
- Incident management with file upload as basis for reporting documentation of major ICT incidents
- Hosting and AI processing exclusively in Germany, auditor directly bookable (PRISM Certified)
ICT Risk Management
DORA compliance structured — ICT risks documented and audit-proof.
DORA requires a formal ICT risk framework, incident reporting, TLPT and third-party risk management. PRISM ISO maps the Pillar 1 to 5 requirements as executable measures — audit-proof for regulators and auditors.
Who is this for?
Yes, if
- Bank, insurer, investment firm or payment service provider under Art. 2 DORA
- Critical ICT third-party provider for financial entities (cloud, SaaS, data centre, software)
- Already have ISO 27001 or BSI C5 in house — DORA builds on existing controls
- Goal: maintain controls once, demonstrate to supervisors and customers jointly
Not suitable
- Large institutions with their own GRC stack and dedicated ICT incident reporting tool
- Pure consulting relationship without software use
Many DORA requirements on ICT risk management overlap with BSI C5 and ISO/IEC 27001 — with the C5 crosswalk and the ISO 27001 foundation you maintain controls once and reuse them.
Frequently asked questions about DORA
- What is DORA?
- The Digital Operational Resilience Act (DORA) is an EU regulation that has applied to financial entities and their IT service providers since January 2025. It sets out requirements for ICT risk management, incident reporting, resilience testing (TLPT) and third-party risk management (TPRM).
- Who does DORA apply to?
- DORA applies to banks, insurers, investment firms, payment service providers, crypto-asset service providers, credit rating agencies and critical ICT third-party providers. Companies that supply IT services to regulated financial institutions also fall under the requirements as critical DORA third-party providers.
- What do I need to implement in practice?
- DORA structures requirements across five pillars: ICT risk management (Pillar 1), incident reporting and classification (Pillar 2), digital operational resilience testing including TLPT (Pillar 3), third-party risk management (Pillar 4) and information sharing (Pillar 5). PRISM ISO maps all five pillars as controls.
- From when does DORA apply?
- DORA has been mandatory since January 2025. Additional transition periods for registration with the Lead Overseer are running for critical ICT third-party providers. Organisations that are not yet compliant should start with a gap analysis now.
- How does PRISM ISO help with DORA?
- PRISM ISO structures DORA requirements as executable controls with owners, deadlines and audit-proof evidence. The multi-framework crosswalk automatically transfers controls you have already fulfilled for ISO 27001 or NIS 2 to DORA — eliminating significant duplication of effort.
Software alone — or with consultant and auditor?
Three tiers, one goal: your DORA proof. From a licence to a fixed-price package with auditor included.
So geht PRISM vor
Von der Lücke bis zum laufenden Betrieb.
Vier Phasen, eine Plattform — kein Wechsel zwischen Tools, keine Lücken zwischen Phasen.
Wo stehen Sie heute?
PRISM bewertet Ihre bestehenden Dokumente, Prozesse und Kontrollen gegen alle Anforderungen der DORA. Jede Lücke kommt mit Begründung und direktem Link zur Maßnahme — kein manuelles Zusammensuchen.
Was unsere Kunden sagen
„Der Security Health Check war sehr effizient und zielführend und half uns, Transparenz zu schaffen."
Johannes Beier
IT-Leiter · B2B Medical
Security Health CheckTrusted by
Let's build your ICT risk management framework for DORA.
In the initial call we clarify how the crosswalk engine fits your DORA requirements.