Regulation
EU DORA
EU DORA — Digital Operational Resilience Act
6 requirements · 5 connected unified controls
Open EU DORA in the mapRequirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
EU DORA (Digital Operational Resilience Act)
| Requirement | Unified control and mapping |
|---|---|
| DORA-Ch2ICT risk management framework (Art 5-16) | UC-BCDR-02 — Establish and govern an ICT operational resilience frameworkPartial Remaining requirement: detailed protection, backup, and recovery capabilities implemented via companion controls |
| DORA-Art17-23ICT-related incident management, classification and reporting | UC-BCDR-06 — Resolve operational incidents and eliminate root causesPartial Remaining requirement: major-incident report clocks: initial 24h, intermediate 72h, final 1 month |
| DORA-Art24-27Digital operational resilience testing (incl. threat-led penetration testing) | UC-BCDR-10 — Test recovery capabilities and train contingency personnelPartial Remaining requirement: vulnerability assessments and the Art 25 security-testing catalogue satisfied by companion controls; TLPT regime specifics - three-yearly cadence, authority-approved scope, independent/certified testers (Arts 26-27), and tester independence (Art 24(4)) - require dedicated controls |
| DORA-Art28-44Managing of ICT third-party risk | UC-TPRM-01 — Operate a third-party security risk management programPartial Remaining requirement: DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program |
| DORA-Art45Information and intelligence sharing arrangements | |
| DORA-Art5Governance and organisation (management body responsibility) |