Digital operational resilience for finance — automated end-to-end.
DORA expects EU financial entities to prove ICT risk management, incident reporting, resilience testing, and third-party oversight on demand. Lojycal turns each pillar into a live, signed evidence stream — so the next supervisory dialogue with your competent authority is a five-minute export, not a six-week project.
What DORA actually demands
Regulation (EU) 2022/2554 has applied since 17 January 2025. Five pillars, all enforceable, all auditable by the ECB, EBA, ESMA, EIOPA, or your national authority.
ICT risk management framework
A documented, board-approved framework covering identification, protection, detection, response, recovery, learning and communication.
ICT-related incident reporting
Major incidents classified per RTS, with initial, intermediate, and final reports inside the supervisory deadlines.
Digital operational resilience testing
Risk-based testing programme, advanced TLPT (Threat-Led Penetration Testing) for significant entities every three years.
ICT third-party risk
A register of information on contractual arrangements with ICT third-party service providers — kept current, reportable to the authority.
The Lojycal DORA engine
Four connected workspaces produce every artefact your competent authority — or your ICT third-party — will ask for.
ICT risk register
Risk inventory aligned to the DORA RTS taxonomy: ICT assets, dependencies, criticality, treatment, residual risk — signed by the management body.
Trust Center
Incident classifier & report builder
Detected events flow into the incident ledger. Classification against the DORA criteria (clients affected, duration, geographical spread, data losses, economic impact) is automated.
SIEM + Incident Ledger
TPP register
Register of information on third-party providers, generated in the exact RTS template — critical-or-important function tagging, sub-outsourcing, exit strategy.
Vendor Governance
Resilience testing ledger
Test inventory: vulnerability scans, performance tests, source-code reviews, scenario-based tests, TLPT. Each result tied to remediation tickets and re-test evidence.
Trust Center → Pentest & Hardening
DORA pillars → Lojycal controls
Lojycal automatically produces evidence for the majority of DORA Title II–V obligations. A sampled view:
| DORA area | Example obligation | Lojycal source |
|---|---|---|
| Title II — ICT risk | Art. 6 — ICT risk management framework | Trust Center → Risk + Posture |
| Title II — ICT risk | Art. 9 — Protection & prevention (cryptography, access) | KMS + RBAC + AAL2 |
| Title II — ICT risk | Art. 12 — Backup, restoration & recovery | Asset Lifecycle + Backup Evidence |
| Title III — Incident | Art. 17 — ICT-related incident management process | SIEM + Incident Ledger |
| Title III — Incident | Art. 19 — Reporting to authorities (initial/intermediate/final) | Incident Ledger → Report Builder |
| Title IV — Testing | Art. 24 — Resilience testing programme | Trust Center → Pentest & Reviews |
| Title V — Third-party | Art. 28 — Register of information on contractual arrangements | Vendor Governance → TPP Register |
| Title V — Third-party | Art. 30 — Key contractual provisions & exit strategy | Vendor Governance → Contract Ledger |
Sampled — not exhaustive. Coverage depends on which Lojycal modules and connectors you have enabled.
Supervisors expect machine-readable evidence
DORA gives competent authorities and the Lead Overseer for critical ICT providers (CTPPs) far-reaching information rights. The register of information has a strict RTS template — and they will compare yours with thousands of others.
Lojycal writes every workflow run, every dual-control decision, every contract change to a WORM (write-once, read-many) audit log. The Trust Center bundles selected windows into a signed Evidence Pack — JSON, CSV and PDF, with a detached HMAC signature using a per-organisation key — and the TPP register exports in the exact ESA RTS layout, ready for supervisory submission.
From gap analysis to supervisory-ready — a 90-day path
Most financial entities still treat DORA as a documentation exercise. Lojycal collapses it into a single quarter because evidence and the TPP register generate themselves.
- Days 0–30
Phase 1 — Framework & scope
Confirm scope (credit institution, payment institution, insurer, etc.). Map the DORA framework to existing ICT controls. Lojycal pre-fills the risk register and identifies critical-or-important functions.
- Days 31–60
Phase 2 — Incident & TPP register
Wire SIEM/EDR egress to the incident classifier. Populate the TPP register from contract data and vendor inventory. Tag critical-or-important arrangements.
- Days 61–90
Phase 3 — Testing & supervisory rehearsal
Run the first resilience testing cycle. Generate a signed Evidence Pack and a TPP register export. Rehearse the initial/intermediate/final notification flow against a major-incident scenario.
DORA automation — common questions
What is DORA automation?
DORA automation is the practice of producing ICT risk register entries, incident reports, the register of information on ICT third-party arrangements, and resilience-test evidence directly from live operational systems — instead of building them manually before each supervisory dialogue. Lojycal automates all four pillars end-to-end.
Does DORA apply to my entity?
DORA applies to a wide range of EU financial entities: credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, central securities depositories, central counterparties, trading venues, insurance and reinsurance undertakings, IORPs, and others listed in Article 2. It also applies to critical ICT third-party providers (CTPPs) designated by the Lead Overseer.
How does Lojycal handle the register of information on ICT third-party arrangements?
Lojycal's Vendor Governance module produces the register in the exact ESA RTS template format — every contractual arrangement, with criticality tag (critical-or-important function or not), sub-outsourcing chain, geographical location of data processing, and exit strategy. The register is regenerated daily and exportable on demand.
What about TLPT (Threat-Led Penetration Testing)?
Significant entities must run TLPT at least every three years, performed by independent testers. Lojycal doesn't perform the TLPT itself but ingests its outputs — scope, threat scenarios, findings, remediation — into the Trust Center's pentest module, where each finding is tied to a remediation ticket, a re-test, and a signed closure record.
How are major incidents classified and reported?
Detected events flow from SIEM, EDR and SaaS connectors into the incident ledger. Lojycal applies the DORA RTS classification criteria (clients/financial counterparties affected, reputational impact, duration, geographical spread, data losses, economic impact) and surfaces incidents that cross the major-incident threshold. The initial, intermediate and final reports are pre-populated in the official template.
How does DORA differ from NIS2 in what Lojycal automates?
DORA is lex specialis for the EU financial sector — its ICT incident reporting and TPP rules override NIS2 for in-scope entities. The underlying evidence (incident timeline, vendor register, controls) is largely shared in Lojycal, but DORA outputs follow the strict ESA RTS templates and report into different supervisory channels (ECB / EBA / ESMA / EIOPA / national authority).
Make supervisory dialogue an export, not a project.
Every ICT risk. Every major incident. Every third-party arrangement. One signed source of truth.
