Agentic compliance for DORA

DORA, from the ICT risk framework to a complete register of information.

DORA, Regulation (EU) 2022/2554, has applied to EU financial entities since 17 January 2025. It covers ICT risk management, incident reporting, resilience testing and third-party risk. Teddy's agents map the requirements onto your controls, check every ICT contract against Art. 30 and keep the register of information current.

Art. 30Required clauses checked in every IT contract
One registerAll IT providers, built from your contracts
4 hoursFirst report on major incidents, prepared
What DORA asks for

Six obligations.
Each one has a home in Teddy.

DORA is an EU regulation and applies directly, without national transposition. It covers banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and other financial entities, with proportionate rules for smaller ones. Here is what it asks for and where it lives in Teddy.

Art. 5 to 16ICT risk management framework

Strategies, policies and tools to protect ICT systems, detect anomalies, respond, recover and learn. Some smaller entities can apply a simplified framework under Art. 16.

In TeddyMapped onto your existing ISMS controls
Art. 5(2) and 5(4)Management body

The management body defines, approves and oversees the ICT risk framework, bears ultimate responsibility and keeps its knowledge current through regular training.

In TeddyDecisions and training records for management
Art. 17 to 23Incident classification and reporting

Classify ICT-related incidents with the EU criteria. For major incidents: an initial notification within 4 hours of classification and no later than 24 hours after becoming aware, then an intermediate and a final report.

In TeddyClassification checklist and report templates
Art. 24 to 27Resilience testing

A testing programme in which systems that support critical or important functions are tested at least yearly. Entities identified by the authority also run threat-led penetration testing at least every three years.

In TeddyTest plan and results linked to controls
Art. 28 and 30ICT third-party risk and contracts

A third-party risk strategy and ICT contracts with the provisions of Art. 30, with stricter ones where a service supports critical or important functions.

In TeddyContract Agent checks every ICT contract
Art. 28(3)Register of information

A register of all contractual arrangements for ICT services, at entity and group level, in the EU templates and available to the competent authority on request.

In TeddyBuilt from your contracts and kept current
At least yearlyFramework reviewICT risk management framework
Per major incidentReportingInitial, intermediate, final
At least yearlyTestingSystems for critical or important functions
Every three yearsThreat-led testingFor identified entities
The problem

Hundreds of ICT contracts.
One register the supervisor can ask for.

DORA turned supplier management into a regulatory duty. Every ICT contract needs specific provisions, and the register of information has to be complete and current.

01Older IT contracts

The Contract Agent lists missing clauses and suggests wording.

02The register of IT providers

Teddy fills it in the official EU format from your contracts and supplier list.

03Is this a major incident

Clear criteria and owners decide quickly whether an incident must be reported.

04400 contracts, a register in Excel and a supervisor asking. Still no answer.

Legal holds the contracts, procurement holds the supplier list, and the register lives in a workbook with broken links. ChatGPT can explain Art. 30, but it cannot read your 400 contracts against it. Teddy's Contract Agent reads every ICT contract, flags missing provisions and fills the register from the source.

How it works

From scattered contracts to a program you can show the supervisor

Teddy's agents map the requirements, read the contracts and keep the register current. Legal and management decide, and a compliance engineer is there when the supervisor asks.

01 Gap Audit Agent

Scope and proportionality per entity

Teddy works out which DORA rules apply to each entity in your group and whether the simplified framework under Art. 16 is an option.

DORA scope · Acme GroupDraft
Acme Payments · payment institutionIn scope
Simplified framework (Art. 16)Not applicable
Threat-led testing (Art. 26)Not identified
Teddy: The competent authority decides on threat-led testing. I will flag it if that changes.
02 Gap Audit Agent

ICT risk framework on your existing controls

Requirements from Art. 5 to 16 are mapped onto the controls you already run for ISO 27001 or NIS2. You see what is covered and what DORA adds.

Chapter IIICT risk management
Requirements covered by existing controls78%
Art. 11 · Response and recovery plansPartial
Art. 12 · Backup and restorationCovered
03 Contract Agent

Every ICT contract against Art. 30

The Contract Agent reads each contract, marks whether the service supports a critical or important function and checks the provisions that apply.

Granite Data ServicesPayment gateway
Supports a critical functionYes
Data locations · Art. 30(2)(b)Stated
Exit strategy · Art. 30(3)(f)Missing
Teddy: I drafted an exit clause from your template. Legal decides what goes to Granite.
04 Contract Agent

A register that stays current

The register of information is filled from the contracts themselves. New or changed contracts update the draft, and nothing is final before you approve it.

Register of informationEU templates
Contractual arrangements412
Linked to functionsComplete
Fields still missing23
Teddy: A new contract was signed yesterday. I added it to the register draft for your approval.
05 Policy Agent

Incident classification and reporting

The Policy Agent drafts the classification checklist and the report templates, linked to your incident response, so the clock never surprises you.

Major incident reportingArt. 19
Classification checklistApproved
Initial notification · 4 hoursTemplate ready
Intermediate report · 72 hoursTemplate ready
Final report · one monthTemplate ready
Never stuck

Ask Teddy whether a contract meets Art. 30, before you sign it.

Ask in plain language whether an incident is major or a contract is complete. Teddy answers from your live program. For supervisory requests, our compliance engineers are at your side.

1

Ask TeddyIs this incident major? Which contracts support critical functions? Teddy knows DORA and your setup.

2

Agents do the workContract checks, register entries, report templates and gap analysis, each with its source.

3

Our team backs you upCompliance engineers help with supervisory requests, register submissions and audits.

TeddyAcme Group · DORA
Is last night's payment outage a major incident?
Possibly. It is major if it affects a critical service and either involves malicious unauthorised access with possible data loss or meets at least two materiality thresholds.
  • Critical service affectedYes
  • Clients affectedThreshold met
  • Reputational impactTo assess
If you classify it as major, the initial notification is due within 4 hours. Shall I prepare it?
Prepare notificationAsk our team
CEYour compliance engineer helps with supervisory requests and audits.
FAQ

Questions about DORA

Does DORA apply to ICT providers too?

DORA applies directly to financial entities. ICT providers feel it through their contracts, because financial entities must include the Art. 30 provisions. Providers designated as critical are also overseen directly by the European Supervisory Authorities.

We have ISO 27001. How much counts?

Much of the ICT risk management framework. DORA adds incident classification and reporting deadlines, resilience testing, specific contract provisions and the register of information.

What is the difference between Art. 30(2) and 30(3)?

Art. 30(2) lists provisions every ICT contract needs, such as data locations, service levels and termination rights. Art. 30(3) adds stricter ones for services that support critical or important functions, such as exit strategies and full audit rights.

Do we need threat-led penetration testing?

Only if your competent authority identifies you for it. Every entity needs a testing programme, and systems that support critical or important functions are tested at least yearly.

Your DORA program, built from your contracts and your controls.

Start with an Art. 30 check of your ICT contracts.

Reviewed by Sven Moritz, former CISO · October 2026

What to expect

How long DORA takes, and how Teddy closes the gaps in weeks

TypicalTwo years, and counting

Institutions had a two-year window, and many still did not finish. Before the deadline, fewer than half were confident they would make it, and over a third planned full compliance only for 2026.

With TeddyWithin weeks

Register of information built from your contracts, every ICT contract checked against Art. 30 and the gaps listed with owners. After that, Teddy keeps the register current all year.

  • Register of information: submitted every year in March. In Germany, the 2026 window ran from 9 to 30 March.
  • What BaFin saw in year one: more than 600 major ICT incidents reported. Most institutions using critical providers said those services would be hard to bring back in-house.
  • Supervisory focus 2026: ICT third-party risk management and incident reporting, the part of DORA practitioners rate as hardest.
SMSven MoritzCo-founder of Teddy, former CISOLast reviewed: October 2026
From the audit room

Where DORA programs fall short

  1. The contracts are older than DORA.

    Many existing ICT contracts still lack the Art. 30 minimum clauses, and many agreements have no exit plan at all.

  2. The exit plan exists on paper only.

    Supervisors ask for credible, tested exit strategies for critical or important functions. With critical cloud providers that is hard, and most institutions know it.

  3. The register is filled once a year, in March.

    It has to reflect every contract signed or ended during the year, including tools teams bought on their own. Treat it as a living inventory, not an annual form.