DORA · Regulation (EU) 2022/2554
DORA compliance, mapped to the actual articles
The Digital Operational Resilience Act asks for specifics: contractual provisions, a Register of Information, critical-function declarations and resilience testing. ResiliencePilot is built around exactly those requirements.

What DORA requires, and how we deliver it
Mapped article by article
Each DORA obligation has a home in the platform, with a full audit trail and recorded approvals.
Article 30 contract provisions
Track the mandatory contractual provisions for ICT third-party arrangements (standard for important suppliers, enhanced for critical ones), with status and evidence per supplier.
Critical-function declarations
Declare functions supporting critical or important services, link them to suppliers and dependencies, and keep the rationale on record with its supporting evidence.
Register of Information
Maintain the DORA Register of Information across your ICT third-party arrangements, ready to export for the supervisory authority.
ICT resilience testing
Plan and evidence your digital operational resilience testing programme, mapped to the functions it protects. Part of the full business continuity capability.
Article 11: ICT business continuity policy
A BC policy with BIA-driven RTO/RPO, recovery strategies and tested plans for critical or important functions, wired into the continuity work that backs it up.
Article 12: Backup & restoration
Track backup and recovery arrangements and evidence restoration testing against your recovery objectives.
Incident reporting
rAIley drafts major-incident reports mapped to DORA's classification and timelines, citing the linked records. Your team reviews and submits. Not sure an incident is reportable? Use the indicative calculator.
Third-party risk management
Tier ICT third parties by criticality, run due-diligence questionnaires with AI-assisted review, track assurance and certifications, and evidence Article 30 obligations. Part of Risk Intelligence, linked to your risk register.
Where rAIley helps with DORA
DORA generates a lot of paperwork, and rAIley drafts the bulk of it: major-incident reports aligned to the classification and timelines, supplier-review summaries and resilience-testing write-ups, each grounded in your own records and fully audit-logged. The drafting speeds up; the accountability stays with your team, which reviews and signs off every submission.
Frequently asked questions
- Yes. You maintain the DORA Register of Information across your ICT third-party arrangements and export it for the supervisory authority.
- Each ICT supplier arrangement tracks the mandatory provisions (the standard set for important suppliers and the enhanced set for critical ones), with status and supporting evidence.
- rAIley drafts major-incident reports aligned to DORA's classification criteria and reporting timelines, citing the linked incident records. Your team reviews and submits; nothing is auto-filed.
- In the EU, on Microsoft Azure (Sweden Central), relevant for DORA's data residency and oversight expectations. If you have specific residency requirements, talk to us.
- Yes. ResiliencePilot supports DORA, NIS2, ISO 27001, ISO 22301, SOC 2 and Cyber Essentials on one platform, so overlapping controls are shared across all of them.
Does ResiliencePilot cover the Register of Information?
How does it handle Article 30 contract provisions?
Can rAIley help with DORA incident reporting?
Where is our data hosted?
Does it also cover NIS2 and ISO 27001?
Take on DORA with ResiliencePilot
See it on your own data and frameworks, with your security and data-residency questions answered.