Digital operational resilience, scoped honestly
ICT risk management, incident reporting, resilience testing and third-party oversight for institutions with EU entities, EU clients or EU-scoped ICT — built alongside E-21 rather than twice.
Book a briefingIf any part of you is in EU scope, DORA applies.
The Digital Operational Resilience Act has applied since January 17, 2025. It reaches Canadian and UK institutions more often than they expect: an EU subsidiary or branch, EU clients served from elsewhere, or an ICT provider designated as critical can all pull operations into scope.
DORA covers five areas — ICT risk management, incident classification and reporting, digital operational resilience testing, third-party risk with prescribed contractual terms, and information sharing. It overlaps heavily with E-21, which is the opening for institutions running both.
What is required.
ICT risk management
A documented framework with board accountability, asset and dependency mapping, and protection, detection, response and recovery arrangements.
Incident management
Classification against defined criteria and reporting of major incidents inside the regulatory clock, which is short.
Resilience testing
A regular testing programme, with threat-led penetration testing for entities that meet the significance criteria.
Third-party risk
A register of information on all ICT arrangements plus contractual clauses that many existing vendor agreements do not contain.
Information sharing
Voluntary arrangements for exchanging cyber threat intelligence, with the governance to participate safely.
The E-21 overlap
Dependency mapping, tolerances and testing serve both regimes. We build to the stricter of the two and map the evidence across.
What an engagement produces.
- A scope determination showing exactly which entities, services and providers are captured, with the reasoning
- Gap assessment across all five pillars against your current framework
- The register of information on ICT third-party arrangements, in the required structure
- Contract remediation plan identifying which vendor agreements need which clauses
- Incident classification and reporting procedures tested against the regulatory timelines
- A testing programme aligned with E-21 so one exercise satisfies both supervisors
Common questions.
- We are Canadian with a small EU presence. Are we really in scope?
- Usually the EU-established entity is, and the group functions it depends on get pulled in behind it. The scope determination is the first deliverable precisely because getting it wrong in either direction is expensive.
- Can we treat DORA and E-21 as one programme?
- Largely yes, and you should. The dependency mapping, tolerances and testing are substantially the same work; the differences sit in incident reporting timelines and the contractual requirements for ICT providers.
- What is the most common gap?
- The register of information and the contract clauses. Both are administratively heavy, both depend on vendors who are slow to respond, and both are the easiest things for a supervisor to check.
Book a 30-minute briefing
A short conversation is usually enough to tell you whether this is the right first move — and what it would cost.
Book a briefing