DORA compliance
DORA has become part of your daily work. We make it lighter.
Maintaining the register of information, reporting incidents on time, keeping third parties in view: you know exactly what needs to be done. What is often missing is a system that holds it all together. The SwissGRC® Platform brings your DORA topics together in one place: structured, connected and ready to answer at any time.
DORA in 2026
From preparation to supervision in practice
DORA is no longer a future topic. Supervisors are examining, the register of information is submitted annually, and critical ICT third-party providers are under direct European oversight. Anyone still working with spreadsheets is falling behind.
DORA enters into force
Regulation (EU) 2022/2554 enters into force on 16 January 2023. Financial entities and ICT providers get two years to align governance, processes and contracts with the five pillars of digital resilience. In parallel, the ESAs flesh out the requirements in regulatory and implementing technical standards (RTS and ITS).
DORA applies: reporting duties and the register of information become reality
DORA has applied since 17 January 2025. Financial entities report major ICT incidents within tight deadlines and submit their register of information covering all contractual arrangements with ICT third-party providers for the first time. Supervisors identify recurring errors as early as the first submission round: incomplete registers, missing exit strategies and contracts not yet aligned with the RTS minimum content.
ESAs designate 19 critical ICT third-party providers
On 18 November 2025, EBA, ESMA and EIOPA publish the first list of critical ICT third-party providers (CTPPs), including major cloud platforms, network and data centre operators and specialised financial data providers. These providers now come under direct European oversight. Importantly, operational responsibility for third-party risk remains entirely with the financial entity.
Operational oversight begins
The ESAs set up Joint Examination Teams and appoint a Lead Overseer for each critical ICT third-party provider, with far-reaching information, control and inspection powers. At the same time, the second submission round of the register of information is under way, and the register is now transmitted to the ESAs every year. National authorities such as BaFin run workshops so the errors of the first round are not repeated.
Deeper supervision and a growing scope
Supervisory practice deepens: extended examinations, annually updated CTPP lists and a growing focus on threat-led penetration testing (TLPT) for significant institutions. In Germany, the FinmadiG additionally widens the scope. Organisations that treat DORA as a continuous process rather than a project hold the advantage.
The five pillars of DORA
Five pillars, one platform
DORA spreads its requirements across five fields of action. The SwissGRC® Platform connects them in one integrated data model: risks, incidents, tests and third parties interlock instead of sitting in separate silos. Pick a pillar and see what implementation looks like in practice.
Pillar 1 · Foundation
ICT risk management
Financial entities must run a sound, documented ICT risk management framework: inventory systems and assets, identify, assess, treat and continuously monitor risks, with clear accountability at the level of the management body.
How you implement it with the SwissGRC® Platform
- Connected ICT inventory: capture protected assets, systems and processes and link them to risks, controls and providers.
- Integrated ISMS: information security and ICT risk in one data model, including measure tracking.
- Reporting for the management body: dashboards and reports that serve supervisory requirements and board expectations alike.
Pillar 2 · Responsiveness
Managing and reporting ICT-related incidents
Incidents must be detected and classified, and major cases reported to the competent authority within tight deadlines: initial notification, intermediate report and final report, consistent and traceable.
How you implement it with the SwissGRC® Platform
- End-to-end incident management: from capture through classification to root cause analysis in a single workflow.
- Deadlines under control: structured reporting processes with clear responsibilities, so the initial notification goes out on time.
- Linked to risk management: every incident feeds the cause, event and impact chain and sharpens your risk view.
Pillar 3 · Resilience
Testing digital operational resilience
Regular testing, from vulnerability assessments to threat-led penetration testing (TLPT) for significant institutions, makes sure protection, detection and recovery capabilities work in practice.
How you implement it with the SwissGRC® Platform
- Test planning and follow-up: document test types, cycles and results centrally and manage findings as measures.
- BCM built in: create and test contingency plans and feed the lessons straight back into risks and controls.
- Audit-ready evidence: a complete history of all tests and measures for audit and supervision.
Pillar 4 · Supervisory focus 2026
Managing ICT third-party risk
The register of information covering all contractual arrangements with ICT third-party providers is transmitted to supervisors every year. Add due diligence, minimum contract content, concentration risk and exit strategies for critical functions. With ESA oversight of CTPPs, this pillar takes centre stage in 2026.
How you implement it with the SwissGRC® Platform
- Register of information under DORA: capture it in a structured way, keep it current and keep it ready for submission.
- Third-party risk management: assess and monitor providers and make concentration risk visible, including CTPP dependencies.
- Exit strategies documented: record exit plans for critical services and keep them up to date.
Pillar 5 · Collective defence
Sharing cyber threat information
DORA encourages the voluntary exchange of threat intelligence between financial entities, within trusted communities and in line with data protection. Those who share and receive spot attack patterns earlier.
How you implement it with the SwissGRC® Platform
- Document the threat picture: capture external intelligence in a structured way and link it to your own risks and scenarios.
- Knowledge becomes action: alerts turn into trackable tasks instead of forgotten emails.
- One picture for everyone: threats, incidents and risks in one consistent view for specialists and leadership.
The solution
DORA compliance with the SwissGRC® Platform
Six capabilities, one integrated data model. Every DORA requirement has a clear home in the SwissGRC® Platform, and every home is connected to the others. That cuts duplicate work, and when supervisors ask, the answer is already there.
DORA Compliance Check
Track the implementation of every requirement of Regulation (EU) 2022/2554, including the associated RTS and ITS. Gaps become visible, measures are assigned, and progress stays transparent for the management body.
ICT risk management & ISMS
Inventory and interlink your entire IT ecosystem. Identify, assess and monitor ICT risks in an integrated ISMS and take well-founded decisions to improve your security posture.
Register of information under DORA
Build and maintain the register of all contractual arrangements with ICT third-party providers: structured capture, regular updates and complete traceability, ready for the annual submission.
Incident management
Detect, classify and report incidents in line with DORA. Seamlessly integrated with risk management, covering the full cause, event and impact chain through to the final report.
Business continuity management
Plan and test contingency measures so your organisation keeps operating even in a crisis. Test results feed straight back into risks and measures and strengthen your resilience over time.
Third-party risk management
Take a data-centred approach to all ICT third-party risk: due diligence, ongoing monitoring, concentration risk and exit strategies, including your dependencies on critical providers under ESA oversight.
Interactive · 2 minutes
How DORA-ready is your organisation?
Six questions along the supervisory examination priorities. You get an assessment right away, anonymous and with no sign-up.
How do you maintain your register of information on ICT third-party providers?
Could you report a major ICT incident to your supervisor within four hours of classification?
Do you know your dependencies on the 19 critical ICT third-party providers under ESA oversight?
How closely are your ICT inventory, risks and controls linked to each other?
How systematically do you test your digital operational resilience?
Does your management body receive reliable reports on DORA implementation on a regular basis?
The readiness check is a non-binding self-assessment and does not replace regulatory advice. No answers are stored or transmitted.
Frequently asked questions
Understanding DORA, as of 2026
The key questions on the Digital Operational Resilience Act, updated with the latest developments: from CTPP oversight to the annual submission of the register of information.
What is the Digital Operational Resilience Act (DORA)?
DORA is Regulation (EU) 2022/2554. It entered into force on 16 January 2023 and has applied since 17 January 2025. It harmonises digital operational resilience requirements for around 20 types of financial entities in the EU, from banks and insurers to payment institutions and crypto-asset service providers, and brings ICT third-party providers directly into scope.
The goal: the European financial sector should be able to detect, manage and recover from severe digital disruption without putting the stability of the financial system at risk.
What are the five pillars of DORA?
- ICT risk management: a documented framework to identify, assess, manage and monitor ICT risk.
- Incident management and reporting: major ICT incidents are classified and reported to the competent authority within the deadlines.
- Digital resilience testing: regular testing, up to threat-led penetration testing (TLPT) for significant institutions.
- ICT third-party risk management: including the register of information, minimum contract content, concentration risk and exit strategies.
- Information sharing: voluntary exchange of cyber threat intelligence between financial entities.
What changed with the CTPP list of November 2025?
On 18 November 2025, the European supervisory authorities EBA, ESMA and EIOPA designated 19 ICT third-party providers as critical (CTPPs) for the first time, from hyperscalers and network and data centre operators to specialised providers of financial data and services. Since 2026, these providers have been under direct ESA oversight with Lead Overseers and Joint Examination Teams.
Important for financial entities: operational responsibility stays with you. If you use a CTPP, that dependency needs to be reflected in your own register and your concentration risk assessment, and the insights from ESA oversight need to flow into your own ICT risk management. If a critical provider fails to act on supervisory recommendations, national authorities can, as a last resort, require financial entities to suspend or terminate use of its services.
What is the register of information and what applies from 2026?
The register of information documents all contractual arrangements with ICT third-party providers, specifically flagging services that support critical or important functions. It is transmitted to the ESAs every year via the national supervisor.
From the first submission round, supervisors flagged typical weaknesses: incomplete registers (think shadow IT), missing exit plans, and contracts still lagging behind the minimum content of the technical standards. For the ongoing rounds, data quality is the deciding factor. A tool-supported register linked to contracts, risks and functions cuts errors and effort considerably.
What are the reporting deadlines for major ICT incidents?
Once an incident is classified as major, the initial notification is due within four hours, and no later than 24 hours after detection. It is followed by an intermediate report no later than 72 hours after the initial notification and a final report, including root cause analysis, no later than one month after the last intermediate report. The deadlines are tight, which is why a rehearsed, tool-supported reporting process with clear roles is decisive. Practice confirms it: since DORA took effect, several hundred major ICT incidents have been reported in Germany alone, a large share of them linked to external providers.
Does DORA also affect Swiss companies?
DORA is an EU regulation, but its effects reach beyond the EU. Swiss financial companies with subsidiaries or business activity in the EU are affected, and so are Swiss ICT providers serving EU financial entities: their clients demand DORA-compliant contracts, the ability to provide evidence, and cooperation on the register of information. Swiss supervisory practice is also increasingly aligning with comparable operational resilience principles. Whoever implements the DORA logic today is well positioned in both markets.
How do DORA and NIS2 differ?
NIS2 is a directive with a broad, cross-sector scope covering essential and important entities. DORA is a regulation that applies specifically and directly to the financial sector. For financial entities, DORA takes precedence over NIS2 as the sector-specific regime. Many organisations still need to keep both frameworks in view, for example in groups with financial and non-financial companies. The SwissGRC® Platform maps both frameworks in one platform, so evidence only has to be produced once.
How does Swiss GRC support DORA compliance?
The SwissGRC® Platform covers the DORA requirements as one coherent whole: a DORA compliance check with measure tracking, ICT risk management and ISMS, the register of information under DORA, end-to-end incident management with a reporting process, business continuity management, and third-party risk management including exit strategies and CTPP dependencies.
As a scalable solution it grows with you: start with the DORA core topics and extend your GRC processes step by step to further areas. Optionally with data residency in Switzerland, and supported by our team, which knows the regulated DACH market from years of hands-on work.
SwissGRC® Platform
Supervisors ask. You deliver.
See how you manage your register of information, incident reporting and third-party risk with the SwissGRC® Platform.
DE