Skip to content
Cyber Horizon
All frameworks

// Financial

Digital Operational Resilience Act Compliance Software

EU regulation on digital operational resilience for the financial sector.

Framework at a glance

Short name

DORA

Version

2025

Category

Financial

Controls

118

What DORA covers

118 controls across 5 domains — every one tracked, owned and evidenced in Cyber Horizon.

ICT Risk Management

78 controls
  • 1.1.1 Governance and control framework
  • 1.1.2 ICT Risk Management implementation
  • 1.1.3 Management responsibilities
  • 1.1.4 CIAA considerations and implementation
  • 1.1.5 Roles and responsibilities

ICT-related incident management, classification and reporting

10 controls
  • 2.1.79 ICT-related incident management process
  • 2.1.80 ICT-related incident management process: content
  • 2.2.81 Classification of incidents
  • 2.2.82 Classification of cyber threats
  • 2.3.83 Reporting of major ICT-related incidents

Digital Operational Resilience testing

17 controls
  • 3.1.89 Digital Operational Resilience testing
  • 3.1.90 DOR testing risks considerations
  • 3.1.91 Independent tester
  • 3.1.92 Testing finding prioritization, classification and remedy
  • 3.1.93 Yearly testing

Managing of ICT Third-party risk

12 controls
  • 4.1.106 ICT third-party risks basis
  • 4.1.107 ICT third-party risks strategy
  • 4.1.108 ICT third-party contractual arrangements: register of information
  • 4.1.109 ICT third-party assessment
  • 4.1.110 ICT third-party InfoSec requirements

Information-sharing arrangements

1 controls
  • 5.1.118 Information-sharing arrangements on cyber threat information and intelligence

How Cyber Horizon automates DORA

Every DORA control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is Digital Operational Resilience Act?

EU regulation on digital operational resilience for the financial sector.

How many controls does Digital Operational Resilience Act have?

Digital Operational Resilience Act (2025) has 118 controls in Cyber Horizon's catalogue, organised across 5 domains.

How does Cyber Horizon help with Digital Operational Resilience Act?

Cyber Horizon maps Digital Operational Resilience Act into a shared control library alongside every other framework you run, so evidence collected once counts towards DORA and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See DORA mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of DORA in Cyber Horizon.