DORA

Frequently Asked Questions

What Is DORA?

The Digital Operations Resilience Act (DORA) is a piece of EU legislation relating to the cyber security and digital of financial institutions...

Read more

Which Organisations Does DORA Apply to?

DORA is applicable to a wide range of organisations in the financial sector, including banks, insurance companies...

Read more

‍How does DORA differ from ISO 27001?

If your organisation is already certified to ISO 27001, this will provide a strong starting point for compliance with DORA, as the two cover...

Read more

How is DORA structured?

DORA is structured around five core ‘pillars’ that relate to ICT and cyber security, which aim to provide a comprehensive digital resiliency framework for financial organisations...

Read more

What are the regulatory technical standards (RTS) and implementing technical standards (ITS)?

In addition to DORA itself, the European Supervisory Authorities (ESAs) have produced a number of regulatory technical standards (RTS)...

Read more

How is DORA enforced?

DORA is enforced by designated regulators in each EU member state, known as competent authorities.  These competent authorities can request that financial organisations implement...

Read more

DORA - The Digital Operations Resilience Act

Published on
5 Jun
2025

URM’s blog discusses the EU’s Digital Operation’s Resilience Act (DORA), explaining who it will apply to, its requirements, how it will be enforced, and more.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
10/3/2026
ISO 27001: How Certification Works

URM’s blog breaks down the ISO 27001 certification process, the roles of certification bodies and UKAS, what auditors look for during assessments, and more.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
9/3/2026
Implementing and Auditing ‘People Controls’ from ISO 27001:2022

URM’s blog explains why ‘people’ warrants its own control theme in ISO 27001 and how to prepare for a people controls audit, offering advice for each control.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
18/12/2025
ISO 27001:2022 - A.5 Organisational Controls (Access Management)

URM’s blog explores why the access controls in ISO 27001 matter, and how to implement each control in full conformance with both the Standard and best practice.

Read more
"
Our consultant was very thorough and knowledgeable when delivering the ISO 27001 pre-stage-2 internal audit.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.