Audnexa
SecurityModulesPricingFAQ
plPolski enEnglish daDansk
Book a security walkthrough
SecurityModulesPricingFAQ For audit firms +48 12 200 27 10 Book a security walkthrough

← All articles

DORA audit — ICT requirements, third-party risk and how to prepare

Author: Adam Wojak · Managing Director, Virtline (ISO/IEC 27001) · Updated: 2026-06-25

In short: DORA (Regulation (EU) 2022/2554) is directly applicable law for EU financial entities that harmonizes digital operational resilience. It applies since 17 Jan 2025. A DORA audit covers ICT risk management, incident reporting, resilience testing, ICT third-party risk (register of information) and information sharing.

What DORA is and who it covers

DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) is directly applicable EU law harmonizing digital operational resilience for the financial sector. It applies since 17 January 2025.

It covers a broad range of financial entities (banks, insurers, investment firms, payment institutions and others) and — indirectly — critical ICT third-party providers.

The five DORA pillars

  • ICT risk management (framework, roles, policies),
  • major ICT incident reporting,
  • digital operational resilience testing (including advanced / TLPT),
  • ICT third-party risk management (register of information, contractual clauses),
  • cyber-threat information sharing.

Register of information (ICT third parties)

A concrete obligation is maintaining a register of information about ICT third-party contracts, with criticality classification — a key element of third-party-risk audits.

How to prepare for a DORA audit

  • inventory the ICT risk-management framework and evidence,
  • build the register of information and criticality classification,
  • document incident reporting and resilience testing,
  • review vendor contractual clauses (audit rights, exit plan),
  • prepare a review-ready gap report for the risk committee.

How Audnexa supports DORA audits

Audnexa supports preparing auditable report and gap-analysis drafts for DORA — with references to evidence and a full audit trail. In offline mode (Bank Mode), material stays in the customer’s infrastructure and a human approves every report.

A mature tool, battle-tested over years in Virtline’s audit practice (ISO/IEC 27001). It does not replace an auditor’s or lawyer’s opinion.

Frequently asked questions

When does DORA apply?

DORA applies since 17 January 2025 as a directly applicable EU regulation — no national transposition is required.

How does DORA differ from NIS2?

DORA is a regulation focused on the financial sector’s digital operational resilience (lex specialis). NIS2 is a broader-scope directive. For financial entities, DORA generally takes precedence on ICT matters.

Which tool should you choose for a DORA audit?

Assess data control (offline/on-premise), audit trail, human approval, ICT vendor register support and maturity. Audnexa meets these criteria (Bank Mode, ISO/IEC 27001, years of Virtline practice).

Sources

  • EUR-Lex — DORA Regulation (EU) 2022/2554
  • EBA — Digital Operational Resilience

Book a security walkthrough

Related articles

  • NIS2 audit — who is covered, what the obligations are, and how to prepare
  • Which tools support NIS2, DORA and banking compliance audits? Selection criteria
  • GDPR audit — security of processing (Art. 32), DPIA, RoPA and the 72-hour breach

This content is informational and does not constitute a legal opinion, an auditor’s opinion or a formal compliance decision.

← All articles

Audnexa

Auditable AI workspace for IT security and compliance reporting at regulated institutions.

Audnexa is a product of Virtline Sp. z o.o.

Product

Security Deployment Modules Pricing Trust Center

Company

Knowledge For audit firms Contact LinkedIn +48 12 200 27 10 biuro@virtline.com

Legal

Privacy policy DPA Terms security@virtline.com

Audnexa supports the work of auditors and compliance teams. It does not constitute a legal opinion, an auditor’s opinion, or a formal compliance decision.

© 2026 Virtline Sp. z o.o. All rights reserved. ul. Wadowicka 8A, 30-415 Kraków · NIP 6751499701

We use cookies for traffic analytics (GA4). Statistics load only after your consent. Privacy policy