Skip to content

    Articles tagged: DORA

    6 articles on DORA from the Top Floor insights library.

    • 2026-08-25

      How Long Does DORA Readiness Take?

      There is no grace period to plan against: DORA has applied since January 2025 and provides no transitional period. The honest timeline is set by the regulation's recurring clocks and by the workstreams with external lead times, and it differs for a new entrant, a laggard, a vendor and a group.

    • 2026-08-23

      Does DORA Require Threat-Led Penetration Testing?

      Only if your competent authority tells you so. No financial entity opts into TLPT, and no vendor can tell you that you are in scope. What the designation actually turns on, and what to do while you wait to hear.

    • 2026-08-23

      What the DORA Register of Information Requires

      Fourteen linked tables, machine-validated, with the LEI as the only identifier that works. In the ESAs' dry run, 6.5% of registers passed every data quality check and 86.4% of the failures were an empty mandatory field.

    • 2026-08-16

      Does DORA Apply to US Companies?

      Almost certainly not directly, and almost certainly yes in practice. DORA binds EU financial entities, not their overseas vendors, but Articles 28 to 30 mean it arrives at your door as a contract addendum with a signature deadline attached.

    • 2026-08-16

      What a DORA Addendum Actually Asks You to Sign

      Nine baseline terms under Article 30(2), six more under Article 30(3) when your service supports a critical or important function. A clause-by-clause read of the addendum European financial customers are sending their technology vendors.

    • 2026-08-16

      DORA Incident Reporting: The 4, 24, and 72 Hour Clocks

      Three reports on three clocks, set by Commission Delegated Regulation (EU) 2025/301. The four-hour one is the surprise, because it starts at classification rather than at containment.