Skip to main content
← All answers
Frameworks

What does DORA require for ICT risk management?

More context

DORA applies to banks, insurers, investment firms, payment institutions, crypto-asset service providers, and other EU financial entities, and extends to critical ICT third-party providers. The regulation has been fully applicable since January 17, 2025, and supervisors expect the ICT risk framework to be demonstrable, not aspirational.

The configuration-heavy obligations sit in Articles 9 to 11: protection and prevention require systems to be securely configured and kept that way; detection requires the ability to spot anomalous changes. Continuous CIS benchmark scanning satisfies both halves, producing a running record that configurations remained hardened and that deviations were detected and remediated.

Related questions

More questions on Frameworks?

Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.

Request Executive Briefing →