DORA · Regulation (EU) 2022/2554
DORA compliance, proved article by article.
If you sell software to a bank, insurer or payment firm in the EU, DORA is now your problem too. Evidero matches your existing policies, contracts and test reports against each DORA requirement, and cites the exact sentence the answer came from.
What DORA requires
Four pillars. Every one needs evidence.
The regulation asks what you do and how you can show it. The second half is where weeks disappear.
ICT risk management
A documented framework covering identification, protection, detection, response and recovery — reviewed at least yearly and after every major incident.
Evidero maps each article to the sentence in your own ICT risk policy that answers it, and flags the articles nothing in your documents covers.
Incident reporting
Classification of ICT-related incidents and initial, intermediate and final reports to the competent authority within fixed deadlines.
Your incident process and classification thresholds are matched line by line against the reporting duties, so gaps show up before an auditor finds them.
Digital operational resilience testing
A risk-based testing programme, run at least annually, with findings tracked to closure. Threat-led penetration testing for significant entities.
Test reports, scope statements and remediation records become dated evidence attached to the requirement they satisfy.
Third-party risk and contracts
Contractual clauses on data location, access and audit rights, subcontracting, exit strategies, and a register of information on all ICT arrangements.
As a supplier you get asked for these clauses constantly. Evidero answers each one with a citation to the contract or policy paragraph it came from.
How the gap analysis works
Upload the documents you already have. Evidero reads them against every DORA article, shows what is covered, and marks the rest no source found.
Nothing is invented. If a requirement has no matching sentence in your policies, the answer stays empty and lands in the risk register with what it means and what to do about it. Your data stays in Frankfurt and is never retained for model training.
DORA rarely arrives alone — see the full framework coverage for GDPR, NIS2 and the EU AI Act, or read how we handle security and data residency.
Questions we get asked
Does DORA apply to my SaaS company?
Directly, if you are an EU financial entity. Indirectly, and in practice just as hard, if you supply ICT services to one — banks, insurers, payment firms and investment firms must push DORA obligations into their supplier contracts, which means the questionnaires land on you.
When did DORA start applying?
Regulation (EU) 2022/2554 has applied since 17 January 2025. There is no phase-in for the core obligations.
What does a financial customer actually ask for?
Register-of-information data, subcontracting chains, data location, exit and continuity plans, incident notification timelines, and evidence that resilience testing happened. Almost every item must be backed by a document, not a claim.
How is this different from a policy generator?
A generator writes the policy. Evidero shows the exact sentence in your existing documents that answers a requirement, and says 'no source found' when nothing does.
Pilot
Send us your DORA questionnaire. We'll show you the answers with sources.
Direct line to the founder. Onboarded in 48 hours. No contract, no credit card.
Request pilot access