Skip to content
DORA · EU financial entities

Stop scrambling for your DORA evidence the week before your auditor asks.

DORA has been in force across EU finance since 17 January 2025. Your competent authority can ask for the evidence pack on any day. Secruna keeps it ready.

What you get

Three outcomes for a DORA assessment.

The DORA evidence pack

One ready-to-ship PDF and CSV covering every pillar your competent authority walks through.

The incident clock

The 4-hour, 72-hour and 1-month notification windows surfaced against the moment your team classifies the incident.

The third-party register

The Article 28 ICT third-party register populated from your connector inventory. No more spreadsheet.

How it works

Connect. Map. Ship.

1. Connect

Read-only OAuth into your cloud and SaaS.

2. Map

Each system mapped to a DORA pillar. Two reviewers sign off.

3. Ship

One-click DORA evidence pack — PDF, CSV, signed audit trail.

Who it’s for

EU banks, payment firms, insurers, crypto-asset providers.

Any financial entity directly applicable under DORA — and the ICT third-party providers they rely on.

Deep detail

The five DORA pillars, in our docs.

Pillar-by-pillar walkthrough — ICT risk management, incident handling, resilience testing, ICT third-party risk and information sharing — lives on docs.secruna.com.

Want to see your DORA gap?
Talk to us for 30 minutes.

A 30-minute call tells you where your DORA evidence pack is empty today.