Skip to main content

Getting Started with DORA

The Digital Operational Resilience Act (DORA) has been enforceable since January 17, 2025. It applies to EU financial entities (over 20 categories listed in Article 2) and their ICT third-party service providers. Providers designated as critical by the ESAs are additionally subject to direct oversight. Once you activate DORA in Matproof, you’ll see approximately 70 controls across five pillars. This guide walks you through exactly what to do — in order — so you make real progress from day one.
If you haven’t activated DORA yet, go to Settings → Frameworks → DORA and click Activate. Your controls will be pre-populated automatically.

What DORA Requires at a Glance


Am I in Scope?

DORA applies to you if your organization is any of the following:
  • Credit institution, payment institution, or e-money institution
  • Investment firm or crypto-asset service provider
  • Insurance or reinsurance undertaking
  • Central counterparty or trade repository
  • ICT third-party service providers — all are indirectly affected through contractual requirements (Articles 28-30); those designated as critical by an ESA are additionally subject to direct oversight (Articles 31-44)
This is a non-exhaustive list. Article 2(1) covers 21 categories of financial entities. Consult the full list in the Regulation if your entity type is not shown above.
ICT providers that serve in-scope financial entities may be directly supervised under DORA even if they are not themselves financial institutions. Check with your legal counsel if you are unsure.
DORA applies proportionally based on entity size, risk profile, and complexity (Article 4). Microenterprises may apply a simplified ICT risk management framework under Article 16.

The 5 DORA Pillars in Matproof

ICT Risk Management

Policies + ControlsDocument your ICT risk strategy, define risk tolerance, and complete the governance controls in Pillar 1. Start here before anything else.

Incident Reporting

Incidents ModuleSet up your 4-hour initial reporting workflow. Configure incident classification thresholds that match your regulator’s criteria.

Resilience Testing

Cloud TestsSchedule and document your TLPT cycles. Matproof tracks test scope, results, and remediation actions.

Third-Party Risk

Vendor RiskBuild your ICT third-party register and classify each vendor by DORA criticality. Send risk assessments directly from the platform.

Information Sharing

Voluntary (Article 45)Financial entities may voluntarily participate in threat intelligence sharing arrangements. This pillar is encouraged but not mandatory.

Follow this sequence. Skipping ahead — especially past vendor mapping — is the most common reason DORA audits go poorly.

The Three Things Teams Get Wrong

1. Not prioritizing controls

With ~70 controls across five pillars, trying to do everything at once leads to nothing getting done. Filter by Priority: High and work pillar by pillar in the order above.

2. Missing the 4-hour incident notification window

Most teams only discover this requirement after a real incident. Set up the Incidents module before you need it. Define what constitutes a “major incident” internally, document it, and run at least one tabletop exercise.

3. Skipping vendor criticality classification

DORA’s third-party risk rules (Articles 28-44) are among the most operationally complex. Without classifying vendors, you cannot determine which ones need enhanced contractual clauses, sub-outsourcing controls, or exit plans. This is also the area regulators scrutinize most.

Control Prioritization Reference


What Good Looks Like

By the end of week 8, a complete DORA implementation in Matproof should have:
  • All three foundational policies Approved with assigned owners
  • Every ICT vendor in the register with a DORA Criticality classification
  • All Critical and Important vendors with a completed assessment on file
  • The Incidents module configured with classification criteria and a live notification workflow
  • A TLPT schedule documented in Cloud Tests
  • At least 85% of controls in Completed or In Review status
Use Dashboard → DORA Overview to see your pillar-by-pillar completion percentage at a glance. This is the view your auditor will want to see.

Next Steps