DORA

Frequently Asked Questions

What Is DORA?

The Digital Operations Resilience Act (DORA) is a piece of EU legislation relating to the cyber security and digital of financial institutions...

Read more

Which Organisations Does DORA Apply to?

DORA is applicable to a wide range of organisations in the financial sector, including banks, insurance companies...

Read more

‍How does DORA differ from ISO 27001?

If your organisation is already certified to ISO 27001, this will provide a strong starting point for compliance with DORA, as the two cover...

Read more

How is DORA structured?

DORA is structured around five core ‘pillars’ that relate to ICT and cyber security, which aim to provide a comprehensive digital resiliency framework for financial organisations...

Read more

What are the regulatory technical standards (RTS) and implementing technical standards (ITS)?

In addition to DORA itself, the European Supervisory Authorities (ESAs) have produced a number of regulatory technical standards (RTS)...

Read more

How is DORA enforced?

DORA is enforced by designated regulators in each EU member state, known as competent authorities.  These competent authorities can request that financial organisations implement...

Read more

DORA - The Digital Operations Resilience Act

Published on
5 Jun
2025

URM’s blog discusses the EU’s Digital Operation’s Resilience Act (DORA), explaining who it will apply to, its requirements, how it will be enforced, and more.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
7/8/2026
The Fundamentals of Risk Management in ISO 27001

URM’s blog explains the risk management requirements in ISO 27001, including identifying ISMS risk, risk assessment and treatment, documentation and more

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
4/8/2026
ISO 27001 Clause 10.2: Nonconformity and corrective action

URM’s blog explains how to meet ISO 27001 Clause 10.2, including finding nonconformities, performing root cause analysis, implementing corrective actions & more

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
30/7/2026
ISO 27001 Clause 7.4: Communication

URM’s blog explains ISO 27001 communications requirements, their links to interested parties, & how both can be addressed through a single framework.

Read more
"
URM have carried out our PCI DSS assessments for nearly 10 years. During that time they have shown expertise and commitment in helping us reach our goals. Last year we decided to go for Cyber Essentials Plus and had no hesitation in getting URM to assess us for that.
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.