EU regulations

DORA: EU regulation for financial sector

The Digital Operational Resilience Act (DORA) is a comprehensive EU regulation

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

It harmonises cybersecurity and operational resilience requirements for financial institutions and their ICT service providers, aiming to minimise risks and ensure continuity in the face of cyber threats.

TIBER-EU TLPT and DORA compliance

TIBER-EU Threat-Led Penetration Testing (TLPT) is a critical component of DORA compliance, helping financial institutions and critical entities validate their resilience against sophisticated, threat-led attacks in line with European regulatory expectations.

  1. Threat-led scenarios

    Threat-led scenarios based on real-world adversary TTPs and intelligence.

  2. Realistic attack drills

    Realistic, goal-oriented exercises that simulate targeted attacks on critical systems and processes.

  3. Regulatory collaboration

    Close collaboration with regulators, internal teams, and external partners to ensure alignment with TIBER-EU methodology and objectives.

  4. Reporting and remediation

    Detailed reporting and remediation guidance to strengthen detection, response, and overall cyber resilience.

How Thales supports DORA compliance

ICT risk management and governance: our frameworks and solutions help manage cybersecurity risks and ensure operational resilience, including advanced threat detection and response. 

Incident reporting: our incident response services ensure rapid reporting and forensics, meeting DORA strict timelines for incident notification and investigation. Digital operational resilience testing: we conduct regular resilience testing, including penetration testing, adversary simulation, and purple teaming, to validate preparedness against cyber threats. Third-party ICT risk management: we support due diligence and risk assessment for third-party ICT providers, ensuring compliance with DORA stringent requirements. Data encryption & cryptographic key management solutions integration and management: our solutions, including Hardware Security Modules (HSMs), key management platforms, ensure compliance with DORA data protection. 

How Thales supports DORA compliance

© 123RF

TIBER-EU TLPT ensures that organisations can demonstrate compliance, improve incident response maturity, and build confidence in their ability to withstand advanced cyber threats, directly supporting DORA requirements for digital operational resilience testing.

What is DORA?

Threat-led penetration testing and TIBER-EU

Threat-led penetration testing (TLPT) services for TIBER-EU and DORA-compliant cyber resilience.

  • White paper | how to comply with DORA, the EU’s Digital Operational Resilience Act?

Related solutions

SOCI Act for Critical Infrastructure Resilience

Critical infrastructure resilience - SOCI compliance

Practical approaches to achieving strategic and operational outcomes through strong risk, resilience and compliance management that goes beyond compliance for critical infrastructure operators

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance
PCI DSS compliance services

PCI DSS compliance services

Achieve cardholder data security with PCI DSS certification support.

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance
ISO27001 certification

ISO 27001 certification

ISO 27001 takes a risk-based approach to compliance

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance
NIS2 Directive: European cyber regulation

NIS2 directive: European cyber regulation

Understand NIS2 obligations, EU country enforcement and how Thales supports compliant, resilient critical infrastructure operators.

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance
SWIFT CSCF Independent Assessment

SWIFT CSCF Independent Assessment

Certified independent assessments for SWIFT CSCF compliance and annual KYC Security Attestation

  • Cybersecurity
  • Cybersecurity services
  • Cyber governance & compliance

Contact us for more information about our solutions