DORA
DORA compliance support for UK financial firms and ICT suppliers serving the EU. Gap analysis, remediation and the evidence your EU regulators and clients expect.
Service Details
DORA compliance means proving your firm can withstand, respond to and recover from ICT disruption, to the standard EU regulators and your EU clients expect. Falx gives you a clear gap analysis against the Digital Operational Resilience Act (DORA), a prioritised remediation plan and the evidence to show you meet it.
DORA covers ICT risk management, incident reporting, resilience testing and third-party oversight across banks, insurers, payment institutions, crypto-asset service providers and their technology suppliers. It is one of the frameworks we run within our governance services.
INFO
DORA is EU law, not UK law. UK firms are mainly affected through EU operations, EU clients, or as ICT suppliers to EU financial entities.
Why DORA matters to UK financial firms
DORA exists so that a cyber attack or ICT failure at one firm does not cascade through the financial sector. That means reporting incidents within strict timelines, proving you can recover and overseeing every critical supplier.
For UK firms, the commercial pressure usually arrives before the regulatory kind. EU clients must evidence their supply chain resilience, so they write DORA terms into your contract. Showing DORA alignment helps you win and keep EU business.

Who DORA applies to
Firms operating in the EU financial market, and the technology suppliers that serve them
ICT providers and suppliers
Firms providing technology services to EU financial entities, including cloud, data analytics and critical software vendors
Financial entities
Including banks, insurers, investment firms, payment institutions, e-money institutions, clearing houses and crypto-asset service providers
An ICT supplier is drawn in through its EU clients' contracts, regardless of where its own operations are based.
What DORA requires
DORA groups its requirements into five pillars. In plain English:
- ICT risk management — A documented framework for identifying, protecting against and recovering from ICT risk, with your management body accountable for it.
- Incident management and reporting — A process to classify ICT incidents and report major ones to your regulator within set deadlines.
- Resilience testing — A regular testing programme, from vulnerability scans to scenario tests. Larger, designated firms must also run threat-led penetration testing (TLPT) at least every three years.
- Third-party risk management — A register of your ICT supplier contracts, required contract terms, and exit plans for critical services.
- Information sharing — Voluntary arrangements to share threat intelligence with other financial firms.
Comparing regimes? Our NIS2 vs NIST vs CIS vs DORA guide explains which apply to financial firms.
Resilience you can run, not just a compliance file
The firms that cope with DORA treat it as an operational resilience programme, with regulatory evidence as the output. We bring over a decade of financial-sector security experience, close the gaps that matter and leave you with testing and reporting routines your team can keep up.
How we help you comply
From first assessment to evidence you can keep current:
Gap analysis
We assess your operations against all five DORA pillars, map overlaps with FCA and PRA resilience rules, and extend the review across your suppliers.
Remediation
We fix the gaps in priority order, from incident reporting workflows that meet DORA deadlines to supplier contract terms and exit plans.
Resilience testing
We support scenario development, attack-tree creation and testing proportionate to your risk profile, including preparation for threat-led testing.
Evidence and ongoing support
We keep your ICT risk framework, supplier register and test results current, so you can answer regulators and client questionnaires quickly.
One programme for every regime you answer to
DORA is rarely the only regime you answer to. FCA resilience rules, PCI DSS, ISO 27001 and client audits stack up fast.
We map them into one programme, so a single control produces evidence for several frameworks and your team is not running the same exercise four times.

Related frameworks and services
DORA overlaps most with the EU’s NIS2 directive and the UK FCA requirements. Many financial firms also hold ISO 27001, process card payments under PCI DSS, and use NIST or CIS as their control framework. Personal data in scope also falls under GDPR.
For the work behind the evidence, see compliance support, risk management, security posture reviews, penetration testing and identity and access. Our end-to-end compliance programme brings these together.
We apply DORA most often for clients in financial services, insurance and private equity.
Frequently asked questions
Find out where you stand on DORA
Tell us about your EU business and the clients asking questions. You get a clear view of which DORA requirements apply to you and what to fix first.