DORA has applied since 17 January 2025, unifying digital operational resilience rules across the EU financial sector. Policies alone aren't enough. You must prove you manage, test and report ICT risk. Kybit delivers the operational half.
Five pillars, one goal: an ICT outage or attack must not take you down. Verify exact requirements against the RTS/ITS and your regulator.
Regulation (EU) 2022/2554 has been directly applicable since 17 January 2025 across all EU member states.
Banks, insurers, investment and payment firms, crypto-asset providers and other financial entities, plus their critical ICT providers.
A management-owned ICT risk-management framework: identify, protect, detect, respond and recover.
Classify and report major ICT-related incidents to the competent authority within the set deadlines.
Regular testing, and for entities identified by their competent authority, threat-led penetration testing (TLPT) aligned with TIBER-EU, at least every 3 years.
Manage ICT third-party risk and a register of contracts; critical ICT providers are overseen by the European Supervisory Authorities (ESAs).
Operationally, from resilience testing to detection and incident reporting.
Threat-led penetration testing aligned with TIBER-EU and red-team operations that evidence resilience against real scenarios.
24/7 SOC/MDR, classification of major incidents and evidence for regulator reporting within DORA's deadlines.
Threat intelligence, hunting and risk analysis feeding a management-owned ICT risk-management framework.
Hardening, backups, resilient Infrastructure as Code and recovery plans to ensure operational continuity.
Framework and policy design and ICT third-party-risk management across the supply chain.
DORA rarely arrives alone. We help you handle them all.
Straight answers to what clients ask us most.
DORA (Regulation (EU) 2022/2554) has been directly applicable since 17 January 2025 across all EU member states. As a regulation it needs no transposition and applies directly.
Financial entities: banks, insurers, investment and payment firms, crypto-asset providers and more. It also covers the critical ICT service providers serving them. Kybit can act both as an ICT service provider and as your compliance partner.
Threat-led penetration testing is advanced, threat-intelligence-driven testing aligned with the TIBER-EU framework. It is required for financial entities individually identified by their competent authority, at least every three years (microenterprises and simplified-regime entities are excluded). Kybit performs TLPT and follow-on red-team operations.
For the financial sector DORA is lex specialis: it takes precedence over the general NIS2 rules where they overlap. Many organisations still face both; we align the obligations so the work isn't done twice.
We'll review your ICT risk framework, testing plan and incident-reporting process, then put them into operation.