DORA Compliance
ICT resilience evidence chain for EU finance.
Same primitive as S5, specialised for DORA Article 18 (ICT incident reporting) and Article 19 (operational resilience testing). HATP-attested logging of every automated decision in the ICT stack.
- Who buys this
- EU banks, insurers, payment firms, asset managers. Smaller volume than NIS2 but higher per-customer revenue.
- Why now
- DORA has been in force since 2025-01-17. Enforcement is intensifying. Financial institutions need provable audit trails for ICT decisions affecting operational resilience.
- Status
- Q2 2027
- Regulations satisfied
- DORA Articles 18, 19, 28, 30
How it works
Article 18 incident
Structured reporting bundles with HATP-signed event chains.
Article 19 resilience
Attested artefacts from operational-resilience exercises.
TPM evidence
Third-party ICT risk: receipts include upstream provider identity.
ECB-ready
Output aligns with ECB ICT incident reporting schemas.
Pricing
Pricing is being finalised.
Per-tier rates for DORA Compliance will be published once the pricing review completes. EU customers are billed in EUR with EU VAT; non-EU on request. Talk to us for a quote in the meantime.
Talk to usReady to evaluate?
Get a sandbox token, walk a real HATP receipt chain, and read the EU DPA before you decide.