DORA compliance
Operational resilience readiness for financial entities and their ICT providers. Hackerbane audits your ICT risk management, incident reporting, resilience testing, and third-party controls against the Digital Operational Resilience Act, then helps you close the gaps before your supervisor asks.
What DORA is
The Digital Operational Resilience Act is a European Union regulation that sets one rulebook for how financial entities manage the risk in their technology. It has applied since January 2025 and covers five areas: ICT risk management, reporting of major ICT incidents, digital operational resilience testing, management of ICT third-party risk, and information sharing on threats.
DORA is a regulation, not a directive, so it applies directly in every member state without local transposition. National competent authorities supervise it, and the European Supervisory Authorities publish the technical standards that spell out what good looks like.
Who it applies to
- Banks, payment institutions, e-money institutions, and investment firms.
- Crypto-asset service providers and issuers authorised under MiCA.
- Trading venues, central counterparties, fund managers, insurers, and other regulated financial entities.
- ICT third-party providers that serve those entities, including cloud, custody technology, and data providers. Critical providers face direct oversight.
What Hackerbane does
- Gap assessment: we map your current controls to each of the five DORA areas and the technical standards beneath them, and tell you what is missing, weak, or undocumented.
- Controls audit: we test the ICT risk-management framework as it runs, not as the policy describes it. Access control, change management, backup and recovery, logging, and key management are checked against the systems that hold assets.
- Resilience testing: penetration testing and security review of the in-scope smart contracts, custody and signing infrastructure, node and bridge software, and any AI components that can move money or change a rule, scoped to the DORA testing requirement.
- Third-party risk: we review your register of ICT providers, the contractual clauses DORA requires, and how you monitor concentration risk.
- Incident reporting: we test your classification, escalation, and reporting playbook against the deadlines in the regulation.
- Remediation and audit support: fixes are retested, evidence is assembled, and we walk your supervisor, internal audit, or board through what was done.
What you get
- A gap report mapped requirement by requirement, with an owner and a priority for each gap.
- Technical findings with severity, proof of exploitability for the serious ones, and a fix your engineers can ship against.
- An evidence pack: test reports, control walkthroughs, and remediation records your supervisor can read.
- Verified remediation and an updated report once the fixes land.
Who signs off
DORA has no certificate. Your national competent authority supervises compliance and can ask for evidence at any time. Hackerbane prepares that evidence and the fixes behind it; the supervisor decides whether you meet the regulation.
Questions
- Does DORA apply to crypto firms?
- Yes. Crypto-asset service providers and issuers authorised under MiCA are financial entities under DORA, and the ICT providers that serve them are in scope through them. If you run an exchange, a custodian, or a token issuer in the EU, DORA applies to the systems that hold assets.
- Is a Hackerbane audit the same as DORA threat-led penetration testing?
- Threat-led penetration testing is required only for entities that your authority designates, and it follows a framework the authority sets. Hackerbane runs the resilience and penetration testing that every in-scope entity needs, and can act as the external tester inside a threat-led programme where the framework allows it.
- How long does DORA readiness take?
- It depends on how many systems are in scope and how far your controls are from the standard. We start with the gap assessment so you know the size of the work before you commit to it, then agree a timeline for the audit and remediation.
Next step
Request an audit
Tell us which DORA requirements your supervisor has raised, which systems are in scope, and your reporting deadline. We will propose a gap assessment and audit plan with an estimate.