DORA compliance – preparing the ICT environment

As a general contractor for IT systems, we prepare the infrastructure, integrations and technical documentation so that your organisation can demonstrate compliance with the requirements of the DORA Regulation.

Contact us!

The DORA Regulation (EU 2022/2554) has been fully applicable since 17 January 2025 and requires financial entities and their ICT providers to ensure digital operational resilience.

We help your company demonstrate compliance with the requirements set out by DORA – from an audit of the environment, through the implementation of security measures, to post-implementation support.

GOTOMA GENERAL supports the technical and implementation side of compliance. We do not provide legal advice, nor do we act as a regulatory auditor – we work with the client’s compliance team or law firm, delivering the ICT layer that meets the requirements of the regulation.

In the area of cybersecurity, we also work with partners who support us with their expertise and experience in the delivery of technical projects.

The five pillars of DORA – the scope of our support

We provide specific technical input for each of the five areas of the regulation.

ICT risk management
Security architecture, backups, recovery, access policies.
ICT incident reporting
Monitoring, event classification and procedures for reporting to the supervisory authority.
Digital resilience testing
Preparing the environment for testing, including advanced TLPT.
ICT third-party risk
Register of services, integrations compliant with DORA contractual clauses.
Information sharing on threats
Tools for collecting and sharing cyber threat information.

Who is it for?

Banks and investment firms
Payment institutions
Insurers
ICT service providers for the sector

Time to get down to business, let's talk about the project.

Describe your needs and we will come back with a proposal tailored to your business.

Contact us