EDIH, EEN, Interreg: the platform for European programmes.Find out more

DORA Maturity · Digital Operational Resilience for Financial Services

Your digital operational resilience, measured article by article and turned into a costed action plan.

10 themes, 108 questions, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

DORA Maturity · Digital Operational Resilience for Financial Services

Governance and accountability of the management bodyN1 → N5
ICT risk management frameworkN1 → N5
Mapping of assets and critical functionsN1 → N5
Protection and preventionN1 → N5

10 themes, 108 questions, 5-level scale.

Nordhavn Industries

53 / 100

Governance and accountability of the management body6484
ICT risk management framework5379
Mapping of assets and critical functions6182
Protection and prevention3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • Cetim
  • Aerospace Valley
  • Pôle SCS
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One Regulation (EU) 2022/2554 (DORA), applicable since 17 January 2025 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

It is this mechanism, a level, a level above, and the action linking the two, that turns a finding into a trajectory.

Are exit strategies for ICT providers supporting critical or important functions defined and tested?

  1. N1

    No exit strategy is formalised. The question would only arise once a provider actually stopped delivering the service.

  2. N2

    Reversibility clauses appear in some contracts, with no associated exit plan or identified switchover scenario.

  3. N3

    An exit strategy is documented for each provider supporting a critical function: replacement solution, data to be retrieved, estimated transition time.

  4. N4

    Exit strategies are reviewed at each contract renewal and linked to the register of information. Switchover timeframes are verified with the business concerned.

  5. N5

    Exit scenarios are tested during exercises, including unplanned termination cases, and lessons learnt feed into the review of contracts and the ICT risk management framework.

Action to move from L2 to L3

For each ICT provider supporting a critical or important function identified in the register of information, draw up an exit sheet setting out the replacement solution, the data and formats to be retrieved and the estimated transition time, then have it validated by the owning business unit at the quarterly ICT risk committee.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon DORA.

What this framework covers

DORA, Regulation (EU) 2022/2554 on digital operational resilience for the financial sector, has applied since 17 January 2025. It covers a broad scope: credit institutions, investment firms, insurers, asset managers, crypto-asset service providers, market infrastructures, and third-party ICT providers designated as critical. Five pillars structure the text: an ICT risk management framework under the responsibility of the management body, major incident management and reporting, digital resilience testing, third-party ICT risk management, and information sharing on cyber threats.

The difficulty is not understanding the text, it is knowing where you actually stand. Is the register of information on contractual arrangements kept up to date as amendments occur, or rebuilt once a year for the submission deadline? Are the notification deadlines for a major incident achievable on a Friday evening, with the people actually on call? Are exit strategies for critical providers documented and tested, or do they exist only as a contractual clause? These questions cannot be settled by a binary compliance status.

A common confusion is worth clearing up: DORA is a regulation, not a directive, and it is not something you get certified against. There is no DORA label. Oversight is carried out by national and European competent authorities, through the submission of the register of information, incident notification and, for designated entities, threat-led penetration testing (TLPT). Another point worth clarifying: DORA takes precedence over NIS 2 for the financial entities it covers, but the underlying governance and risk management arrangements remain largely shared.

A compliance audit concludes with a gap or compliance finding on a given requirement. A maturity assessment answers a different question: what level of control does the practice actually reach, and what specific action moves it up to the next level. On DORA, this distinction matters, because most organisations hold the expected documents without having the repeatability, traceability and steering that the regulator will look for during a review or after a real incident.

In Datamensio, the DORA framework is ready to use and adaptable. The AI adjusts themes, questions and levels to your regulatory status and size, applying the proportionality principle set out in the text, or builds a version from your own documents: ICT risk management policy, register of information, continuity plans.

Reference standard: Regulation (EU) 2022/2554 (DORA), applicable since 17 January 2025

The themes assessed

  • Governance and accountability of the management body

    Approval and review of the ICT risk management framework, roles and responsibilities, budget allocation, training for leaders, alignment with control functions.

  • ICT risk management framework

    Documented policies and procedures, tolerance for digital disruption risk, annual review, incorporation of lessons from incidents and tests.

  • Mapping of assets and critical functions

    ICT asset inventory, identification of critical or important functions, internal and external dependencies, information classification, upkeep.

  • Protection and prevention

    Identity and access management, encryption, network security, change and patch management, secure development.

  • Detection and monitoring

    Mechanisms for detecting anomalous activity, alert thresholds, monitoring coverage, dedicated resources, review of detection performance.

  • Continuity, recovery and backups

    ICT business continuity policy, recovery time and point objectives, backup sites, backup and restoration policy, documented exercises.

  • Incident management and reporting

    Detection and classification process, criteria for major incidents, initial, intermediate and final notification deadlines, channels to the competent authority, client communication.

  • Digital operational resilience testing

    Annual testing programme, vulnerability assessments, compatibility and performance testing, threat-led penetration testing (TLPT), handling of findings.

  • Third-party ICT risk management

    Policy on ICT providers, pre-contractual due diligence, mandatory contractual clauses, concentration, chain subcontracting, audit and access rights.

  • Register of information and regulatory submission

    Completeness of the register of contractual arrangements, data quality, update process, preparation for submissions and authority requests.

A short version of the framework, with 40 questions, is available for the online self-assessment. The full version covers 10 themes and 108 questions.

Frequently asked questions

Can you be certified against DORA?

No. DORA is a directly applicable European regulation, there is no associated certification. Oversight rests with the competent authorities, through the register of information, incident notifications and, for the entities concerned, threat-led testing. The maturity assessment measures your practices and prepares for these milestones, it does not issue any attestation.

What is the difference between this assessment and a DORA compliance audit?

An audit checks whether a requirement is met and concludes with a gap or compliance finding. The assessment places each practice on a five-level maturity scale and points to the action that moves it up to the next level. The two complement each other: the assessment builds the trajectory, the audit validates the level reached.

How long does the assessment take?

The short version takes 20 to 30 minutes to complete. The full version, run collaboratively, involves several contributors: security, procurement, continuity, compliance. Most of the time goes into gathering input from these teams rather than into data entry.

Is the framework adaptable to our status and size?

Yes. DORA applies a proportionality principle, and the framework follows the same logic: you can edit the questions, levels and themes, or let the AI produce a version tailored to your regulatory status from your own documents. You keep full control of the framework.

How does DORA fit with NIS 2 and ISO 27001?

DORA takes precedence over NIS 2 for the financial entities it covers, but the governance, risk management and incident handling requirements rest on principles that converge with ISO 27001 and ISO 27005. Datamensio’s cross-framework roadmaps consolidate several assessments and group common actions together rather than duplicating them.

Does the assessment cover our IT providers?

The pillar dedicated to third parties evaluates your own practices: pre-contractual due diligence, contractual clauses, concentration monitoring, exit strategies, upkeep of the register of information. You can also roll out the framework to your providers, individually or at scale, and compare their results on a common basis.

How do you get from the assessment to the action plan?

The gap between the score achieved and the target set automatically generates the corresponding actions. The AI groups them into a prioritised roadmap, and the service catalogue matches a solution to each item, with its cost, timeframe and expected impact on the score.

Where is the data hosted?

In France, at OVH, with backup at Scaleway. No transfer outside the European Union. The AI models used can be selected, including from European providers.

Take your first measurementon DORA.