Detecting…
LoginAssess your organisation’s compliance with the EU Digital Operational Resilience Act, identify critical ICT and third-party risk gaps, and develop a practical roadmap for achieving and maintaining DORA compliance.
The Digital Operational Resilience Act (DORA) is an EU regulation designed to strengthen the digital operational resilience of the financial sector. It requires regulated financial organisations to demonstrate that they can prevent, withstand, respond to and recover from cyberattacks, technology failures and other Information and Communication Technology (ICT) disruptions. DORA has applied since 17 January 2025 and covers a wide range of organisations, including banks, insurance companies, investment firms, payment institutions, pension providers, crypto-asset service providers and certain ICT third-party service providers.
A DORA gap analysis helps your organisation assess its current ICT risk management, cybersecurity and operational resilience arrangements against the requirements of the Digital Operational Resilience Ac
The assessment identifies where existing policies, processes, contracts, technologies and controls meet DORA requirements and where compliance gaps, weaknesses or missing evidence remain. It provides a structured understanding of your organisation’s current level of DORA readiness.

Without a structured gap analysis, organisations may overlook critical compliance obligations, weaknesses in ICT governance or dependencies on technology suppliers. These gaps can increase exposure to operational disruption, regulatory scrutiny, financial loss and reputational damage.
Kelmac Group’s DORA Gap Analysis and Readiness Assessment helps financial entities understand their compliance position, identify priority risks and establish a clear roadmap towards sustainable DORA compliance and enhanced digital operational resilience.
DORA applies to a broad range of EU financial entities, including:

The precise obligations may vary depending on the organisation’s type, size, risk profile and role within the financial services ecosystem. A DORA applicability assessment can help establish which regulatory requirements apply to your organisation.

Kelmac Group conducts an independent and structured assessment of your organisation’s existing ICT governance, cybersecurity, operational resilience and third-party risk management arrangements against applicable DORA requirements. Our consultants review both documented controls and their practical implementation to determine whether your organisation can demonstrate effective and sustainable compliance.
KelmacGroup methodology is aligned with regulatory expectations and industry’s best practices.

Kelmac Group combines information security, risk management, regulatory compliance, auditing and management-system expertise to provide a practical approach to digital operational resilience. Our approach is:
● H3: Risk-based: Findings are prioritised according to operational and regulatory significance.
● Evidence-focused: We assess whether controls are implemented and supported by demonstrable evidence.
● H3: Business-aligned: Recommendations consider your organisation’s size, complexity and critical services.
● H3: Implementation-oriented: We provide practical actions rather than simply identifying weaknesses.
● H3: Framework-integrated: Existing ISO 27001, business continuity, cybersecurity and supplier-risk controls are considered.
● H3: Management-focused: Reporting is designed to support informed decisions, accountability and regulatory assurance.
DORA has applied since 17 January 2025 to financial entities and other organisations that fall within its scope. Applicable organisations must be able to demonstrate that the required governance, risk management, testing, incident reporting and ICT third-party controls are operating effectively.
No. ISO 27001 can provide a strong foundation, but organisations must assess and address DORA-specific obligations.
The duration depends on the organisation’s size, complexity, number of legal entities, ICT environment and availability of evidence. Kelmac Group should provide a tailored scope after an initial consultation.
Evidence may include policies, ICT risk registers, asset inventories, incident records, testing reports, supplier contracts, continuity plans, recovery tests, governance minutes and registers of information.
Certain ICT providers may be directly affected by DORA’s oversight framework, while other suppliers will face contractual, assurance and information requirements from regulated financial-sector customers.
Yes. We provide end-to-end support, from gap analysis through to full compliance and operational resilience maturity.