DORA and DNB guidelines for financial services
One platform for DORA, ISO 27001 and your accountability towards DNB and the AFM. From the register of information to incident records, with evidence that comes from your own systems.
- DORA and ISO 27001 on one set of controls
- A register of ICT third parties
- Built and hosted in the EU

What financial services firms achieve with Tidal
- 35+
- Frameworks on one set of controls, including DORA and ISO 27001
- 1 register
- Every ICT third party in one place instead of buried in contracts
- 300+
- Automated tests on your cloud and tooling
Why DORA stalls at fintechs
The regulation is broad, and the work is spread across teams.
A register in a spreadsheet
The register of ICT third parties lives in a file nobody dares to change.
Legal text instead of tasks
The five pillars stay abstract until they are turned into controls with an owner.
Incidents without an overview
During a disruption it is not immediately clear whether it must be reported and which deadline applies.
Duplicate work next to ISO 27001
Set up DORA apart from ISO 27001 and you record the same controls twice.
How financial services firms use Tidal
From the five pillars to the report that has to go out within four hours.
DORA broken into work you can tick off
DORA consists of five pillars: ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. In Tidal they are worked out as concrete controls with an owner and a status. Not legal text, but a task list.
More on DORA
The register of information DORA requires
DORA obliges you to keep a register of all your ICT service providers, with classification of critical functions, contractual arrangements and an exit strategy. Tidal keeps that register current and shows where an arrangement or exit plan is missing.
More on vendor management
Classify and report inside the deadline
For a major ICT incident the deadlines run in hours, not weeks. Tidal helps you classify on impact, duration and services affected, and builds the initial report, the intermediate update and the final report from your incident record.
More on issue management
One dossier for DNB, the AFM and internal audit
Your risk framework, register, incidents and test plans build themselves from your live data. If the regulator asks how you manage dependence on a critical provider, the answer is ready, including who decided what, and when.
More on controls and reportingSupervisory dossier
- Register of ICT third partiesCurrent
- ICT risk management frameworkCurrent
- Incident registerCurrent
- Resilience test planCurrent
Manual or with Tidal
Register of ICT third parties
Manual
A spreadsheet
With Tidal
A current register with classification
DORA pillars
Manual
Legal text
With Tidal
A task list with owners
Recording incidents
Manual
By email and chat
With Tidal
In one register, linked to risks
Evidence current
Manual
Not included
With Tidal
Continuous tests through your integrations
DORA and ISO 27001
Manual
Two projects
With Tidal
One set of controls
From baseline assessment to demonstrably in control
DORA is ongoing supervision. You set it up once and then keep it current in the same system.
Stage 1
Baseline assessment
We test your ICT risk management, your outsourcing and your incident process against DORA. You see per pillar where you stand and what has to happen first.
Stage 2
Setup
Policy, risk framework and the register of information go into Tidal, with templates written for financial services firms under DNB or AFM supervision.
Stage 3
Demonstrable
Your evidence is ready and keeps collecting itself through your integrations. The regulator and your internal audit get one dossier instead of separate documents per pillar.
After that
Keeping it current
DORA is ongoing supervision, not a project. New outsourcing, incidents and resilience tests are handled in the same system.
Connect the tools you already use
AWS
Azure
Entra ID
Google Cloud
GitHub
Jira
Datadog
Microsoft Sentinel
Cloudflare
Aikido
Google Workspace- All integrations
“Their support has been invaluable in our compliance journey.”

Joris Arts
Head of Compliance, Floryn
In financial services the regulator is watching
Four frameworks that shape your accountability.
Frequently asked questions
DORA applies to virtually every financial entity in the EU: banks, insurers, payment institutions, investment firms, crypto service providers and pension funds. Critical ICT service providers to those parties also come under direct supervision.
ISO 27001 is a standard you can be certified against; DORA is legislation and therefore mandatory. A well-implemented ISO 27001 management system covers a large part of the first DORA pillar, but DORA explicitly adds the register of information, reporting deadlines and resilience testing.
Yes. DORA obliges you to keep a register of all contractual arrangements with ICT service providers, including which critical or important functions they support. That register has to be current and available to the regulator on request.
For a major ICT incident there is an initial report within a few hours, an intermediate report within 72 hours and a final report within a month. Tidal helps you classify and tracks the deadlines from the moment you record the incident.
You remain responsible for the chains you depend on. That means contractual arrangements about audits, incident reporting and exit, plus a reasoned picture of what happens if a critical provider fails.
Yes, and it is usually the smartest route. In Tidal you set up one set of controls; evidence you assign counts for both. That way you build towards the certificate and towards your DORA accountability at the same time.