Skip to content
Tenant Excellence

Applies toEuropean Union · financial sector

DORA

ICT risk-management requirements of Regulation (EU) 2022/2554 for financial entities, evaluated from Microsoft 365 and Azure configuration.

From Complete

Scope as evaluated

  • Identity, access and authentication controls
  • Logging, detection and ICT operations settings
  • Data protection and cloud configuration

Read from the tenant

  • Entra ID access policies and privileged roles
  • Audit and alert configuration in Microsoft 365 and Azure
  • Encryption, sharing and Defender settings

Sample controls

  • Art. 9 Protection and prevention
  • Art. 10 Detection
  • Art. 11 Response and recovery
Results are configuration indications drawn from your tenant. They are not an audit opinion or a certification.

In depth

Give the auditor a link, not a folder

Every covered control shows the data Microsoft Graph returned and the endpoint it came from. One click creates a read-only snapshot for one framework; it needs no account and expires after 24 hours.

  • Structured proof per control, with its Graph or ARM source
  • Scoped to one framework, read-only, no sign-in for the auditor
  • Expires after 24 hours; creation is written to the audit log
Learn more

Questions

Questions about DORA

Does this replace the DORA register of information?

No. It evaluates configuration controls; the register and third-party risk remain your programme’s work.

Can we show a DORA snapshot to our supervisor?

The auditor link is a read-only, 24-hour snapshot scoped to DORA. Sharing it is your decision.

Which package includes DORA?

Complete and Premium.

Request a demo

Which frameworks do you report against?

Tell us in the demo request and we will show the matching controls on a demo tenant.

0 / 2,000