DORA — Digital operational resilience.
EU Regulation 2022/2554.
In force since January 17, 2025. Applies to 22,000+ European financial entities and their critical ICT providers. Aitamit covers ICT risk management, incident management, and resilience testing pillars with signed evidence for national supervisory authorities.
Who does DORA apply to?
Financial entities: banks, savings banks, EMI/PI, insurers and reinsurers, asset managers (UCITS, AIFM), investment firms, market infrastructures (CCP, CSD), crypto-asset providers (CASPs), payment service providers (PSPs), rating agencies, pension funds, alternative managers, PEPP providers.
And particularly important: critical ICT providers serving financial entities (cloud, data centers, MSPs, regulated software). If your company provides IT services to banking/finance, DORA may apply to you directly.
Fines: up to €10M or 5% of worldwide annual revenue, whichever is greater. For serious infringements, possible exclusion from authorized ICT providers registry → provider bankruptcy.
What Aitamit covers
Pillar 1: ICT risk management (Art. 5-15)
Aitamit provides complete ICT asset inventory (Art. 8), critical function identification, continuous risk analysis via measured posture (Art. 9), protection and prevention (encryption, patches, AV — Art. 9), continuous detection (Art. 10), continuity management (Art. 11), data-driven learning and evolution.
Pillar 2: ICT incident management (Art. 17-23)
Hash-chain immutable audit as incident evidence. Automatic severity classification. Initial notification 4h after detection, intermediate 72h, final 1 month — Aitamit provides verifiable technical timeline. SIEM integration for authority reports.
Pillar 3: Resilience testing (Art. 24-27)
Annual basic tests (vulnerability assessment, scenario testing). For significant entities: TLPT (Threat-Led Penetration Testing) every 3 years. Aitamit provides inventory and data to define testing scope and verify subsequent remediation.
Pillar 4: Third-party ICT risk (Art. 28-44)
Information register on all contractual agreements with ICT providers. Aitamit is an ICT provider: we deliver standard DORA-ready contractual documentation (Art. 30 clauses, exit strategy, audit rights, sub-contracting).
Pillar 5: Information sharing (Art. 45)
Optional capabilities for threat intelligence sharing with other entities. Aitamit exposes API + webhooks for integration with sharing platforms (FS-ISAC, EU-FSF).
EDS as DORA-ready ICT provider
For financial customers: specific contracts compliant with Art. 30: critical functions description, EU processing location, on-site audit rights, quantitative service levels (SLA), orderly exit with assisted migration, pre-approved sub-contractors.
DORA questions
Who supervises DORA compliance?
When am I declared a critical ICT provider?
Is European Digital Stores SL a DORA critical ICT provider?
How long does DORA compliance take?
Financial sector subject to DORA
Enterprise demo with real banking/insurance case + access to DORA-ready contracts.