Licensed by the Estonian FIU · FIU000117Operating since 2014Punane 6, Tallinn

info@micaconsult.com+372 5089565

LexorCorp Global

Guide

DORA: ICT risk framework and register of information

The five pillars of DORA and how a smaller financial entity meets them.

LexorCorp Global OÜ · published 27 September 2026

The Digital Operational Resilience Act — Regulation (EU) 2022/2554, DORA — applies from 17 January 2025 to almost every regulated financial entity in the EU: credit institutions, payment and e-money institutions, crypto-asset service providers, investment firms, fund managers, creditors under several regimes and more. It sets one standard for ICT risk management and one register of ICT third-party arrangements. This guide explains what DORA requires, how proportionality works for smaller firms, and what our DORA services deliver.

The guide is general information, not legal advice.

The five pillars of DORA

  1. ICT risk management framework (Articles 5–16) — governance by the management body, a documented framework, identification and protection of ICT assets, detection, response and recovery, backup policies, learning and communication. A simplified framework applies to certain small entities (Article 16).
  2. ICT-related incident management and reporting (Articles 17–23) — classification of incidents and major incident reporting to the competent authority on fixed deadlines.
  3. Digital operational resilience testing (Articles 24–27) — a testing programme proportionate to the entity; threat-led penetration testing only for entities designated by the authority.
  4. ICT third-party risk (Articles 28–30) — a strategy, due diligence before contracting, mandatory contract clauses, exit plans, and the register of information on all ICT third-party arrangements (Article 28(3)), submitted to the authority annually.
  5. Information sharing (Article 45) — voluntary arrangements on cyber threat intelligence.

Proportionality

DORA applies to large and small firms, but the depth of the framework follows the entity's size, risk profile and the nature of its services (Article 4). A small payment institution does not need the tooling of a bank — but it needs every required document, an owner for each process and evidence that it works.

Our DORA services

DORA-aligned ICT documents are also part of a MiCA application and of payment and e-money institution applications; ordering DORA together with the licence avoids writing the same documents twice. See also compliance audits.

What you receive

  • a DORA framework proportionate to your firm, with owners and evidence;
  • the register of information in the required format;
  • where ordered, the annual update of the register.

Prices are starting prices confirmed in a written quote and exclude VAT. All communication takes place by email.

Ready to start? Choose the DORA framework or the annual register update. Open the quote form.

Frequently asked questions

Does DORA apply to small payment institutions and crypto firms?

Yes. DORA applies from 17 January 2025 to payment and e-money institutions, crypto-asset service providers, fund managers and most other regulated financial entities. The depth of the framework follows the entity's size and risk profile (proportionality), but the required elements apply to all.

Related guides

More on this topic: Compliance services.

Request a quote

Choose the DORA framework or the annual register update.

Open the quote form Compliance services