matomo

Implementing DORA: What IT Has to Deliver | FHC+P
Practical guide · Financial sector

Implementing DORA

What IT concretely has to deliver, beyond the paperwork

The Digital Operational Resilience Act has applied since January 2025 to banks, insurers, and other financial entities, along with their ICT service providers. Many institutions have written the frameworks, but the IT-side implementation lags: incomplete inventories, tests that would not hold, outdated third-party registers. Here are the building blocks IT actually has to deliver, from FHC+P's project practice in the financial sector. The supervisory assessment belongs to compliance and legal counsel.

1 · Foundation

ICT risk management with a real inventory

2 · Incidents

Classify incidents and report on time

3 · Testing resilience

Test what has to hold in an emergency

4 · Third parties

Third parties under control

Move DORA from paperwork into operations?

We implement the IT building blocks: inventories, processes, tests, registers. More about our work for the sector: IT services for banking and financial services.

Questions & Answers

FAQ

Have further questions? Feel free to contact us directly via our contact form or by e-mail.

Who does DORA apply to? +

To a broad spectrum of financial entities in the EU, from banks through insurers and investment firms to payment service providers, and indirectly to their ICT service providers. DORA has applied since 17 January 2025 and is enforced by the financial supervisors.

Where does DORA implementation most often fail in practice? +

At the gap between paperwork and operations: frameworks and policies exist, but the asset inventory is incomplete, the information register outdated, restore tests are missing, and incident classification is not built into the ticket system. Exactly these operational building blocks are what we implement.

Does FHC+P also do the supervisory assessment? +

No, we deliver the technical and process implementation: inventories, reporting and testing processes, third-party registers, exit plans, and their anchoring in operations. The supervisory assessment and communication with the supervisor lies with your compliance function, with whom we work closely.