DORA
Readiness
DORA made ICT resilience a supervised obligation for EU financial entities, with an ICT risk framework, incident classification and reporting, resilience testing, and a third-party register that regulators can ask for. We run readiness so all five pillars exist and hold together.
Who this is for
Readiness earns its cost when something is waiting on the other side of it. These are the situations where it pays for itself.
EU financial entities in scope - banks, insurers, investment firms, payment institutions, crypto-asset service providers and more
ICT third-party providers serving those entities and receiving DORA obligations contractually
Companies who need the register of information ready for a competent authority
Entities expected to run threat-led penetration testing and unsure what that commits them to
What the engagement does
Your Lorikeet team runs the assessment, collects and vets the evidence, and keeps control status current. You are not handed a spreadsheet and wished well.
- Assess your ICT risk management framework against Articles 5 to 16 and record the gaps
- Establish management body ownership, which DORA makes explicit and non-delegable
- Build incident classification and the reporting path for major ICT-related incidents
- Set up the digital operational resilience testing programme, including where TLPT applies
- Build the ICT third-party register and bring contracts up to the Article 30 requirements
- Prepare the evidence a competent authority would request
What you walk away with
An ICT risk framework with named ownership, an incident classification and reporting process that meets the deadlines, a testing programme covering critical systems, and a third-party register with contracts that carry the mandatory provisions. The register in particular is a common late discovery, and it takes longer to assemble than anyone expects.
How it runs
Four phases. You always know which one you are in and what is outstanding.
Scoping call
We establish what is in scope, which assessment path applies, and what you already have. It costs nothing, and it ends with a straight answer about whether readiness is the right spend right now.
Assessment
We walk the control set and record where you actually stand, control by control. The gap list lands early so your team can start on the long items while the rest of the assessment continues.
Remediate and evidence
We work the gap list down with your team and collect what each control needs, filed against the control it belongs to with an owner and an expiry date rather than dumped in a folder.
Hand off to your assessor
You go in with a package that maps requirement to control to evidence, and we stay available through the assessment itself.
What the assessment covers
The control areas we walk for DORA. Each breaks down into individual controls carrying status, owner and evidence in Talon.
DORA is supervised by national competent authorities and the European Supervisory Authorities. There is no certificate. Readiness prepares you for supervision and for the diligence your financial-sector customers will run on you.
It runs in Talon, not in a spreadsheet
Every control, its status, its owner and its evidence sit in the portal your team already uses, so the readiness picture you see is the one your Lorikeet team is maintaining rather than a copy that went stale a fortnight ago.
- Control-by-control status, kept current by the people doing the work
- Evidence filed against the control it satisfies, with expiry dates tracked
- The auditor request list, so nothing is chased over email
- A readiness view that shows what an assessor would see
Tools like Vanta monitor controls continuously once they exist and work. Readiness is the part before that: deciding the boundary, designing the controls, and closing the gaps a monitoring tool would otherwise report as permanently red. We work alongside them, and we are a Vanta MSP partner.
Our partnersAsked on almost every DORA call
Not directly unless you are designated critical, but the obligations reach you through contract. Financial entities must impose Article 30 provisions on their ICT providers, so the requirements arrive whether or not you are in scope.
TLPT is an advanced, intelligence-led test against live production systems, required periodically for entities identified for it. Not every entity is in scope for TLPT, and establishing whether you are is part of readiness.
A structured record of all contractual arrangements for ICT services, reportable to your competent authority. It is more detailed than most vendor inventories and is one of the more common reasons DORA programmes run late.
DORA is sector-specific for financial entities and takes precedence where both could apply. The control substance overlaps heavily, so work done for one carries into the other.
Rarely run alone
Controls overlap heavily between frameworks, and evidence collected once counts everywhere it applies. A second framework costs a fraction of the first.
DORA readiness, on your timeline
A scoping call costs nothing and ends with a straight answer: what the work involves, what it costs, and whether you need it yet.