Services
Services
SOC & Attestations
SOC & Attestations
Payment Card Assessments
Payment Card Assessments
ISO Certifications
ISO Certifications
Privacy Assessments
Privacy Assessments
Federal Assessments
Federal Assessments
Healthcare Assessments
Healthcare Assessments
Penetration Testing
Penetration Testing
Cybersecurity Assessments
Cybersecurity Assessments
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
ESG & Sustainability
ESG & Sustainability
AI Services
AI Services
Industry Solutions
Industry Solutions
Cloud Computing & Data Centers
Cloud Computing & Data Centers
Financial Services & Fintech
Financial Services & Fintech
Healthcare
Healthcare
Payment Card Processing
Payment Card Processing
US Government
US Government
Higher Education & Research Laboratories
Higher Education & Research Laboratories
About Us
About Us
Leadership Team
Leadership Team
Careers
Careers
Corporate Social Responsibility
Corporate Social Responsibility
Strategic Partnerships
Strategic Partnerships

Financial Services and Fintech

The Digital Operational Resilience Act (DORA)

Strengthen your operational resilience against cyber threats and information and communication technology (ICT) disruptions as an organization doing business in the financial sector.  

Contact a Specialist Build Your Compliance Roadmap

Why DORA?

With cyber threats on the rise, DORA mandates comprehensive risk management, ensuring that organizations in the financial sector can withstand, respond to, and recover from all types of ICT-related disruptions and threats. Compliance with DORA is not just a regulatory requirement but a strategic imperative to safeguard your organization's integrity and reputation.

DORA will apply to over 20 different types of financial entities and ICT third-party service providers. If DORA is applicable to you, compliance is mandatory and an assessment against the requirements may help ensure that you are adequately meeting those requirements. 

Complete Timeline of Milestones

Though DORA was originally released on January 16, 2023, its effective date is not scheduled until January 17, 2025, and there are several intermediary milestones planned in between

January 16, 2024

Publication
DORA becomes part of EU regulation with an aim to establish a universal framework for managing and mitigating ICT risk in the financial sector

January 17, 2024

Technical Standards 
(Part 1)
The ESAs publish the first RTS and ITS to help ensure consistent application of the principles and objectives set out in DORA

July 17, 2024

Technical Standards 
(Part 2)
Delivery of the second round of RTS and ITS.

January 17, 2025

Effective
DORA becomes effective and oversight activities begin for the ESAs

Demonstrate Your Dedication to DORA

Partnering with Schellman for your DORA compliance needs brings numerous benefits:
  • Comprehensive Assessments In-depth evaluations of your current cybersecurity posture.
  • Customized Solutions Tailored strategies to meet DORA requirements effectively.
  • Expert Guidance Continuous support from initial assessment through to full compliance.
  • Cutting-Edge Tools Advanced technologies and methodologies to safeguard your operations.

Why Schellman as Your Trusted Partner?

Schellman specializes in cybersecurity assessments tailored to the financial sector's unique challenges. Our team of seasoned experts understands the intricacies of DORA and provides a seamless path to compliance.
Choose us for our proven track record, client-centric approach, and unwavering commitment to excellence in cybersecurity.
  • Comprehensive Assessments In-depth evaluations of your current cybersecurity posture.
  • Customized Solutions Tailored strategies to meet DORA requirements effectively.
  • Expert Guidance Continuous support from initial assessment through to full compliance.
  • Cutting-Edge Tools Advanced technologies and methodologies to safeguard your operations.

Our DORA Process

We begin each project with your end goals in mind and to provide preparation for future key project activities. Effective communication and timely coordination of project planning activities are central to our methodology with our clients.

Image

Planning

After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the Client are fully aware of the what, who, when, why, and how prior to the beginning of testing.

Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.

Image

Understanding and Kickoff

The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the client with any questions.

By including communication prior to starting, Schellman ensures that no last-minute changes to the project or team have occurred and the Client has the plan prior to the testing and on-site visit.

Image

Testing and Gathering

Testing and gathering is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of gathering the evidence needed for the objectives discussed.

Schellman has a no surprise policy and has daily contact with the stakeholders during the testing and gathering activities. Furthermore, Schellman will begin documentation of the draft deliverable to be able to provide it to the Client efficiently after this phase. The Client will have confidence the Schellman team has completed this phase timely and completely.

Image

Reporting

Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.

Schellman’s report takes into account the entire process and customizes a report for each Client. The draft report will be provided within 2 weeks of the last day of testing and gathering phase, and a final report will be provided within 30 days. This timing is unsurpassed by the industry.

Your DORA Specialist, Chris Smith

Chris Smith is a Director with Schellman based in Raleigh, NC. Chris has over 12 years of audit and compliance experience and maintains multiple CPA licenses, along with CISSP, CISA, ISO 27001 Lead Auditor, and CIPP/US certifications. Chris’ primary focus areas consist of SOC examinations and cybersecurity assessments.