WHY DORA IS BECOMING RELEVANT NOW
New Obligations for the Financial Sector
The Digital Operational Resilience Act (DORA) requires financial institutions and their critical ICT service providers to adhere to uniform standards for IT risk management, security incident reporting, and the monitoring of third-party providers. Unlike NIS2, which applies across all industries, DORA specifically targets the financial sector and also includes ICT service providers (information and communication technology service providers) such as cloud providers.
Those who fail to meet the requirements risk not only fines but also the loss of business relationships—since regulated financial firms, in turn, must require proof of compliance from their service providers.
An early assessment of how DORA affects your organization provides planning certainty for all parties involved in the value chain.
Our Approach
How We Support You
GRASS-MERKUR does not view DORA compliance as an isolated audit requirement, but rather as a structured consulting process aligned with the five pillars of DORA. Together, we assess your ICT risk management, third-party management, and security incident reporting processes.
Based on this, we develop a prioritized action plan that meets the requirements of European supervisory authorities and fits into your existing governance structure.
Your Benefits
- Clarity regarding your DORA compliance status as a financial institution or ICT provider
- Assessment of your outsourcing register and third-party risks
- Preparation for resilience testing and TLPT requirements
- Establishment of timely reporting processes for ICT incidents
- Practical implementation rather than merely preparing expert reports
Our Framework Model
The Five Pillars of Our DORA Consulting
These include:
- ICT risk management
We assess your existing processes for managing IT and cyber risks against the DORA requirements. - Reporting of security incidents
We support you in setting up timely reporting processes for major ICT incidents to the supervisory authorities. - Resilience testing
We prepare you for threat-led penetration testing (TLPT) and further resilience assessments. - ICT third-party management
We assess your outsourcing register and the concentration risks among critical IT service providers. - Information sharing
We support you in building structured processes for exchanging threat intelligence with other market participants.
Contact
Request a Consultation on DORA
Tell us about your project — we will get back to you with a concrete assessment.
Direct Line
GRASS-MERKUR GmbH & Co. KG
Rothwiese 5
30559 Hannover