Edge Register
Standards ยท DORA

DORA (Regulation (EU) 2022/2554)

Rendered when the buyer ticks "DORA financial entity". The register cites 2 of its 26 clauses, behind 2 findings: intermittent or no link, and no backup stated, financial entity site with no recovery objective, and on the duty rows of every site it reaches.

Requirement text drawn from the compliance.theartofservice.com corpus, read against the held text of each standard: the corpus statement of each clause, not the instrument verbatim. Source framework: DORA (Regulation (EU) 2022/2554). What it attaches to a site: the DORA regime page.

Clauses cited

2 of 26
DORA Art. 11 Response and recovery

Financial entities shall put in place an ICT business continuity policy and ICT response and recovery plans (including measures, procedures and arrangements) to ensure continuity of critical or important functions, quickly contain damage, resume activities and recover, subject to regular testing.

Evidence an auditor accepts: ICT business continuity policy + response/recovery plans; Records of plan testing
Common gap: No ICT continuity/response/recovery plans
Source framework: DORA (Regulation (EU) 2022/2554)
DORA Art. 12 Backup policies and procedures, restoration and recovery

Financial entities shall develop and document backup policies and procedures, and restoration and recovery procedures and methods, ensuring backups can be restored with minimal disruption, with backup systems physically and logically segregated from the source system.

Evidence an auditor accepts: Backup and restoration policies/procedures; Evidence of segregated backups and restoration tests
Common gap: No tested backups
Source framework: DORA (Regulation (EU) 2022/2554)

See which clauses your list engages

Paste the list and every site names the clauses behind it, filtered to the regimes that apply to you. Eight sites free, no account.

Build my edge register