Compliance & Certification · DORA

DORA compliance: digital operational resilience.

Support your DORA compliance and strengthen the digital operational resilience of your IT against ICT risks, from penetration testing through to regulatory reporting.

Our approach — a continuous cycle
1 · Assess 2 · Protect 3 · Comply 4 · Monitor 5 · Evolve Our approach
Certifications & accreditations
What it is

Withstand digital shocks.

The DORA regulation (Digital Operational Resilience Act) harmonises digital operational resilience requirements for the financial sector across the EU. It targets an entity's ability to withstand, respond to and recover from ICT-related incidents.

Intervalle supports you from ICT risk to resilience testing, from gap analysis to lasting compliance.

  • Scope of application: financial entities and ICT providers
  • ICT risk management and the associated governance
  • Resilience testing and major incident reporting
  • Gap analysis and a prioritised remediation plan
The pillars of DORA

Structured resilience.

We address every pillar of the regulation, from risk management to oversight.

ICT risk management

A governance framework for the continuous control of information-system risk.

Major incident reporting

Detection, classification and reporting of ICT-related incidents within the regulatory deadlines.

Resilience testing (TLPT)

A testing programme up to threat-led penetration testing (TLPT).

ICT third-party risk management

Control of critical providers and dependencies on ICT third parties.

Threat information sharing

Exchange of cyber-threat intelligence within the financial community.

Governance & oversight

Accountability of the management body and steering of operational resilience.

Our method

From gap to lasting compliance.

A complete approach, from the initial analysis to maintaining compliance.

  1. 1

    Audit

    Gap analysis against the requirements of the DORA regulation.

  2. 2

    Remediate

    A prioritised remediation plan with operational support.

  3. 3

    Comply

    Bringing ICT risk, resilience testing and governance into compliance.

  4. 4

    Post-compliance

    Regulatory watch, reviews and maintaining compliance over time.

Compliance & Certification

Other frameworks.

Cybersecurity, payments and national security — we cover them all.

Ready to aim for DORA compliance?

A gap analysis and a roadmap through to compliance. Leave us your details and an expert will get back to you.