EU financial services

Operational resilience for financial services and their ICT ecosystem.

The Digital Operational Resilience Act sets a common EU framework for ICT risk management, incident handling, resilience testing, and ICT third-party risk in the financial sector. We help firms move from policy to repeatable operations and evidence.

Our implementation focus

Make the requirements operational.

  1. 01

    Assess ICT risk management maturity

  2. 02

    Design incident classification and reporting processes

  3. 03

    Strengthen resilience testing and exercises

  4. 04

    Build ICT third-party oversight and registers

  5. 05

    Align governance and management reporting

Independent assessment

DORA has applied since 17 January 2025. Specific obligations depend on the entity and regulatory role.

Questions we hear

Get the distinctions right.

Does DORA apply to every technology provider serving a bank?

No. Direct duties depend on the entity’s role and the regulation. Financial customers may also place contractual requirements on ICT providers. Confirm the relevant position before designing the program.

Can an ISO/IEC 27001 certificate establish DORA compliance?

No. Security management can support DORA controls, but incident, testing, supplier, governance, and reporting duties require their own analysis and evidence.

Work with Normstone

Build a defensible path to readiness.

Tell us the outcome you need and the markets involved. We’ll help define the work.

Start a conversation