Skip to main content

Mergen named ServiceNow Elite Partner and Center of Excellence of the Year

DORA (Digital Operational Resilience Act) is now in force across the EU. The early audits have begun. Many financial-services organizations are discovering that what they thought was DORA-compliant isn’t.

The three patterns we see

1. ICT third-party register is incomplete. DORA requires a complete register of ICT third-party providers, classified by criticality. Most banks have a procurement record but not a control-risk-classified register.

2. Operational-resilience testing is theoretical. DORA requires regular testing of operational-resilience scenarios. Tabletop exercises don’t qualify; you need actual recovery validation.

3. Incident reporting timing is misunderstood. DORA timing requirements are aggressive. Most organizations’ incident-reporting workflows weren’t designed for sub-4-hour reporting.

The 90-day plan

Build the register first (most foundational). Run an actual recovery test (will surface real gaps). Tighten incident-reporting workflows (operational change, not technical).

Ready to talk
about your next initiative?

Connect with a Mergen architect to scope an outcome-led engagement.

💬

Talk to an Expert

Connect with a certified architect and explore how Mergen can accelerate your transformation.

📋

Get a Free Assessment

Receive a comprehensive platform health check and a prioritized roadmap.

📖

View Success Stories

See how organizations like yours achieved measurable results.

🚀

Start a Project

Ready to go? Tell us about your initiative and we'll scope an engagement in 48 hours.

Contact Book Demo