Five pillars. One register. Zero spreadsheets.
STORM GRC gives banks, insurers, payment institutions, investment firms and the ICT third-party providers DORA Compliance, by serving them a single workspace for the five DORA pillars — ICT risk management, incident reporting, resilience testing, third-party risk, and the Art. 28(3) register of information.
DORA has moved from a guideline to a regulation — already in force since January 2025.
Five pillars, hundreds of pages of Regulatory Technical Standards from the ESAs, and a register of information that has to be ready for the competent authority on request. Most financial entities discover they have the pieces — just not in one place auditors can read.
ICT risk management
A documented ICT risk-management framework approved by the management body, with protection, detection, response and recovery controls running continuously.
Incident reporting
Classification of ICT-related incidents, major-incident reporting to the competent authority within tightly bounded timelines, and significant cyber-threat reporting.
Resilience testing
An annual digital operational resilience testing programme — vulnerability assessments, scenario-based tests and tabletop exercises (TTX) structured around your critical ICT functions.
Third-party risk & the register
Every ICT third-party arrangement classified, contracted under Art. 30, and listed in the Art. 28(3) Register of Information — submitted to the competent authority on demand.
Two sides of the same regulation. One data model.
DORA reaches across the boundary between the financial entity and the ICT third party. STORM is built for both — and lets them work against the same control set.
Financial entities
Banks, insurance and reinsurance undertakings, investment firms, payment institutions, electronic money institutions, crypto-asset service providers, CCPs, CSDs, trading venues, credit rating agencies — about 22,000 entities across the EU.
- ICT risk-management framework documented, approved and reviewed
- Major-incident classification and reporting submitted to the competent authority
- Annual testing programme structured around critical ICT functions
- Register of Information for every ICT third-party arrangement
- Proportionality same rules, scaled to size and complexity
ICT third-party providers
The cloud, SaaS, telco and data providers that financial entities depend on. Critical ICT Third-Party Providers (CTPPs) — designated by the European Supervisory Authorities — fall under direct oversight from a lead overseer.
- Sub-contractor chain documented and contractually controlled
- Concentration risk evidence for financial-entity customers
- Exit and substitutability plans documented and tested
- Lead overseer cooperation where designated as a CTPP
- Operational resilience controls aligned with financial customer expectations
The articles your competent authority will quote.
STORM’s DORA configuration is pre-mapped to the DORA regulation, the Commission Delegated Regulations and the ESA Regulatory Technical Standards (RTSs). You don’t translate generic ISO 27001 into DORA — STORM does it.
Initial, intermediate, final. One workflow.
From the moment your team classifies an ICT-related incident as major under the ESA criteria, the clock starts. STORM builds Article 19 into the incident module — so the initial notification, the intermediate report and the final report are produced from the same record without re-keying.
To the competent authority
An initial notification to the competent authority as soon as possible — and no later than 4 hours after the incident is classified as major per the Commission Delegated Regulation.
What changed, what’s contained
An intermediate report updating the initial notification with a current view of severity, impact, mitigation in progress, and any cross-border implications.
Root cause & mitigation
A final report covering root cause, the full mitigation set applied, lessons learned, and the changes to controls and processes that follow from the incident.
What your Head of Operational Risk actually opens on Monday.
The same STORM platform, configured for DORA — five pillars cross-mapped to your existing ISO 27001 and operational-risk frameworks, Article 19 reporting wired into the incident module, supplier register feeding the Art. 28(3) register of information.
Register of Information
Every ICT third-party arrangement in the ESA template — contract, criticality, sub-processor chain, exit plan — exported to the format the competent authority asks for.
Five-pillar gap analysis
Each pillar scored on the 5-level maturity scale, with drill-down to controls, evidence and remediation tasks assigned with deadlines.
Major-incident workflow
ESA classification criteria built into the incident form — the initial, intermediate and final reports all generated from one record, with management-body sign-off recorded.
Audit-ready DORA compliance in 90 days.
A typical mid-size financial entity (250–2000 staff) hits DORA audit-ready posture within one quarter. Larger institutions with multiple subsidiaries or significant-entity status run a longer programme, but the first 30 days look the same.
Framework & baseline
- ICT risk-management framework documented (Art. 5)
- Asset and service inventory complete
- Existing ISO 27001 / op-risk controls mapped to DORA
- Competent authority and ESA contact established
Register & third parties
- Art. 28(3) Register of Information populated
- Critical-function contracts reviewed against Art. 30
- Major-incident classification & reporting tested
- Testing programme defined; scenario-based tests and TTX scheduled
Audit-ready
- Internal audit completed and reported
- Management body approval recorded
- Incident-reporting workflow tested end-to-end
- Competent-authority documentation pack ready
From fragmented supplier records to a submission-ready Register of Information
DORA requires financial entities to maintain a complete view of ICT third-party arrangements, critical services, contractual provisions and exit arrangements. STORM brings those records into one workspace, so the register, evidence and internal review process are ready when the competent authority asks.
Operation snapshot
Questions Heads of Op Risk and CISOs actually ask.
If your question isn’t here, the answer is a 30-minute call — usually faster than email.
Are we in scope for DORA?
We have ISO 27001 already. Does DORA need a new programme?
What goes into the Art. 28(3) Register of Information?
How does DORA interact with NIS 2 if we are caught by both?
What about our existing third-party contracts? Do we need to renegotiate everything?
How quickly do major incidents have to be reported?
Can the platform be deployed on-premise?
See STORM GRC working against your DORA obligations — in 30 minutes.
A focused demo with someone who knows the regulation. We walk through how STORM GRC maps to the five DORA pillars and show you exactly how it fits your organisation — no commitment required.
EU-based team. No sales pressure.


