Skip to main content

DORA and DNB guidelines for financial services

One platform for DORA, ISO 27001 and your accountability towards DNB and the AFM. From the register of information to incident records, with evidence that comes from your own systems.

  • DORA and ISO 27001 on one set of controls
  • A register of ICT third parties
  • Built and hosted in the EU
The Tidal Control dashboard showing progress on DORA

What financial services firms achieve with Tidal

35+
Frameworks on one set of controls, including DORA and ISO 27001
1 register
Every ICT third party in one place instead of buried in contracts
300+
Automated tests on your cloud and tooling

Why DORA stalls at fintechs

The regulation is broad, and the work is spread across teams.

  • A register in a spreadsheet

    The register of ICT third parties lives in a file nobody dares to change.

  • Legal text instead of tasks

    The five pillars stay abstract until they are turned into controls with an owner.

  • Incidents without an overview

    During a disruption it is not immediately clear whether it must be reported and which deadline applies.

  • Duplicate work next to ISO 27001

    Set up DORA apart from ISO 27001 and you record the same controls twice.

How financial services firms use Tidal

From the five pillars to the report that has to go out within four hours.

DORA broken into work you can tick off

DORA consists of five pillars: ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. In Tidal they are worked out as concrete controls with an owner and a status. Not legal text, but a task list.

More on DORA
The controls overview in Tidal Control, with status, progress and framework per control

The register of information DORA requires

DORA obliges you to keep a register of all your ICT service providers, with classification of critical functions, contractual arrangements and an exit strategy. Tidal keeps that register current and shows where an arrangement or exit plan is missing.

More on vendor management
Vendors in Tidal Control with risk rating and assessment status

Classify and report inside the deadline

For a major ICT incident the deadlines run in hours, not weeks. Tidal helps you classify on impact, duration and services affected, and builds the initial report, the intermediate update and the final report from your incident record.

More on issue management
Issues in Tidal Control, including incidents with priority

One dossier for DNB, the AFM and internal audit

Your risk framework, register, incidents and test plans build themselves from your live data. If the regulator asks how you manage dependence on a critical provider, the answer is ready, including who decided what, and when.

More on controls and reporting

Supervisory dossier

PDF

  • Register of ICT third partiesCurrent
  • ICT risk management frameworkCurrent
  • Incident registerCurrent
  • Resilience test planCurrent

Manual or with Tidal

  • Register of ICT third parties

    Manual

    A spreadsheet

    With Tidal

    A current register with classification

  • DORA pillars

    Manual

    Legal text

    With Tidal

    A task list with owners

  • Recording incidents

    Manual

    By email and chat

    With Tidal

    In one register, linked to risks

  • Evidence current

    Manual

    Not included

    With Tidal

    Continuous tests through your integrations

  • DORA and ISO 27001

    Manual

    Two projects

    With Tidal

    One set of controls

From baseline assessment to demonstrably in control

DORA is ongoing supervision. You set it up once and then keep it current in the same system.

  1. Stage 1

    Baseline assessment

    We test your ICT risk management, your outsourcing and your incident process against DORA. You see per pillar where you stand and what has to happen first.

  2. Stage 2

    Setup

    Policy, risk framework and the register of information go into Tidal, with templates written for financial services firms under DNB or AFM supervision.

  3. Stage 3

    Demonstrable

    Your evidence is ready and keeps collecting itself through your integrations. The regulator and your internal audit get one dossier instead of separate documents per pillar.

  4. After that

    Keeping it current

    DORA is ongoing supervision, not a project. New outsourcing, incidents and resilience tests are handled in the same system.

Connect the tools you already use

  • AWS
  • Azure
  • Entra ID
  • Google Cloud
  • GitHub
  • Jira
  • Datadog
  • Microsoft Sentinel
  • Cloudflare
  • Aikido
  • Google Workspace
  • All integrations

“Their support has been invaluable in our compliance journey.”

Joris Arts

Head of Compliance, Floryn

Frequently asked questions

DORA applies to virtually every financial entity in the EU: banks, insurers, payment institutions, investment firms, crypto service providers and pension funds. Critical ICT service providers to those parties also come under direct supervision.

ISO 27001 is a standard you can be certified against; DORA is legislation and therefore mandatory. A well-implemented ISO 27001 management system covers a large part of the first DORA pillar, but DORA explicitly adds the register of information, reporting deadlines and resilience testing.

Yes. DORA obliges you to keep a register of all contractual arrangements with ICT service providers, including which critical or important functions they support. That register has to be current and available to the regulator on request.

For a major ICT incident there is an initial report within a few hours, an intermediate report within 72 hours and a final report within a month. Tidal helps you classify and tracks the deadlines from the moment you record the incident.

You remain responsible for the chains you depend on. That means contractual arrangements about audits, incident reporting and exit, plus a reasoned picture of what happens if a critical provider fails.

Yes, and it is usually the smartest route. In Tidal you set up one set of controls; evidence you assign counts for both. That way you build towards the certificate and towards your DORA accountability at the same time.