Skip to content
DORA · Digital Operational Resilience Act

DORA compliance software for UK firms with EU exposure

DORA — the EU's Digital Operational Resilience Act — has applied since 17 January 2025. It does not bind UK-only firms directly, but it reaches UK financial entities with EU subsidiaries or branches, UK firms serving EU-regulated clients, and UK ICT providers to EU financial entities. STREAM® by Acuity helps in-scope firms evidence DORA's ICT risk, third-party oversight and incident obligations — including the Register of Information that every supervisory review examines first.

Does DORA apply to a UK firm?

Not automatically. DORA is an EU regulation — a purely domestic UK firm with no EU nexus is regulated instead by the FCA and PRA operational-resilience regime (PS6/21 and SS1/21), not by DORA. But three things pull a UK firm into DORA's scope:

An EU subsidiary or branch

You have an EU subsidiary or branch that is itself a regulated financial entity.

EU-regulated clients

You provide services to EU-regulated financial entities — an EU client base brings obligations with it.

ICT provider to EU entities

You act as an ICT third-party provider to EU financial entities — including an intra-group UK IT function serving an EU subsidiary.

If any of those is true, DORA follows you home. If none is, your obligations sit with the FCA/PRA regime — and STREAM® supports that too.

What is DORA, and when did it take effect?

DORA (Regulation (EU) 2022/2554) creates one binding standard for how EU financial entities manage ICT risk. It entered into force on 16 January 2023 and has applied since 17 January 2025, following a two-year transition. It rests on five pillars: ICT risk management, incident reporting, resilience testing, ICT third-party risk, and information sharing.

Article 28(3)

The Register of Information: DORA's hardest requirement

Under Article 28(3), every in-scope financial entity must maintain a Register of Information — a complete, structured record of every contractual arrangement with every ICT third-party provider, held at entity, sub-consolidated and consolidated levels, built to the ESAs' data model. It is the first document a supervisor examines, and the first place teams come unstuck.

~6.5%of nearly 1,000 firms passed all data-quality checks in the ESAs' 2024 voluntary dry run. The common failures were incomplete contract data, missing subcontractor information and misclassification — not effort, but structure.

How STREAM® helps you evidence DORA

STREAM® by Acuity gives in-scope firms one place to build and maintain the evidence DORA demands — rather than a spreadsheet per obligation.

Register of Information

Structure every ICT third-party arrangement to the ESAs' data model, with subcontractor chains and criticality classification, so the Register survives a data-quality check.

ICT third-party risk

Assess and continuously monitor cyber risk across your ICT vendor population, with tiering and control evidence — via the Vendor Management Hub.

Incident readiness

Assess incident thresholds and assemble the evidence a major-incident report requires, ready for your team to submit.

Control monitoring

Map controls once and evidence them against DORA and your other frameworks together, so continuous compliance replaces the annual scramble.

For the board

What's at stake

DORA gives supervisors real teeth. For a financial entity, penalties can reach up to 2% of total annual worldwide turnover. Beyond the fine, the exposure is board-level: DORA places ICT and third-party resilience squarely within management-body accountability, and a failed Register is a documented, dated finding. STREAM® exists to make that accountability defensible — evidence a supervisor accepts, produced continuously rather than reconstructed under deadline.

See how STREAM® evidences DORA

Book a walkthrough with our team and see the Register of Information, ICT third-party risk and incident evidence in one platform.

Book a walkthrough

Related solution

Third-Party Risk Management

How STREAM® and the Vendor Management Hub help you assess and continuously monitor cyber risk across your ICT vendor population.

Explore third-party risk management →

Frequently asked questions about DORA

Common questions on DORA scope, the Register of Information, and how STREAM® helps.