About Us Solutions How We Work Contact Blog
Book a Demo
DORA — EU Regulation 2022/2554

DORA Compliance for Fintech Startups — Done For You.

Selling to EU financial institutions, or a financial entity yourself? Folksoft implements the ICT risk-management framework DORA requires, sets up incident reporting and resilience testing, and manages third-party ICT risk — so you meet the regulation without a resilience team.

DORA-ready in weeks — no resilience team needed.
Applicable since 2025 Incident reporting 5 DORA pillars Continuous
2022/2554
The EU regulation, covered
Jan 2025
Applicable — and enforced
5
Pillars implemented, end to end
30-day
Money-back guarantee
The platform

What Folksoft does for your DORA programme

From the moment you connect your stack to the day a regulator or financial customer asks for evidence, Folksoft runs the programme for you.

ICT risk-management framework

We stand up the governance, policies, and controls DORA's ICT risk pillar requires — owned by your board, not a binder.

Incident management & reporting

Classification and reporting workflows for major ICT-related incidents, ready for the competent authority's deadlines.

Resilience testing programme

We set up the digital operational resilience testing programme — and support advanced (TLPT) scoping where it applies.

Tested and evidenced
No ad-hoc pentestsNo spreadsheets

Third-party ICT risk

Register of information, contractual requirements, and monitoring for your critical ICT providers — or for your own posture as an ICT provider to financial entities.

Register Contract clauses Ongoing monitoring

Continuous monitoring of your stack

Folksoft watches your AWS, Azure, GCP, GitHub, GitLab, and Okta environments around the clock — so drift is surfaced the moment it appears.

Financial entity vs ICT provider

Which one are you?

DORA reaches you down one of two paths. Which one decides your scope, your deadlines, and who you answer to.

Financial entity

Directly subject to DORA

Banks, payment and e-money firms, investment firms, insurers, crypto-asset service providers, and more. The full DORA framework applies to you directly — all five pillars, with your competent authority supervising.

ObligationDirect
All five pillars apply — supervised by your competent authority
Start here if you hold an EU financial licence
ICT third-party provider

Pulled in through your customers

Tech vendors serving financial entities — cloud, data, security, and core platforms. DORA reaches you through contractual requirements your financial customers must impose, and if you are designated critical, through direct EU oversight.

ContractOversight
Contract clauses now — direct EU oversight if designated critical
Start here if DORA clauses are landing in your contracts

In short: either you're a financial entity subject to DORA directly, or an ICT provider whose financial customers push DORA obligations onto you. Folksoft determines which and gets you ready.

Who needs it

Who needs DORA?

If any of these sound like you, DORA is likely on your critical path.

Fintechs and financial entities in the EU

Payments, lending, investment, insurance, and crypto firms operating in the EU and subject to DORA directly.

ICT and SaaS providers to EU finance

Cloud, data, security, and core platform vendors serving EU financial institutions.

Vendors receiving DORA flow-down clauses

Companies finding DORA contractual requirements arriving in renewals from financial customers.

Teams proving operational resilience

Any company that must demonstrate operational resilience to EU financial regulators or partners.

FAQ

DORA questions, answered

Everything founders ask us before starting their DORA programme.

Still have questions?

01 Does DORA apply to my startup?

If you're an EU financial entity, it applies directly. If you're an ICT provider to financial entities, it reaches you through contracts — and possibly direct oversight if you're designated critical. Folksoft confirms your status.

02 When did DORA start applying?

DORA has applied since January 2025, so obligations and reporting are already live.

03 How much does DORA compliance cost?

It depends on your role — financial entity or ICT provider — and on the scope of your environment, so there's no one-size-fits-all number. Contact us and we'll give you a tailored quote for your situation.

04 Can I do this without a resilience or security team?

Yes. That's exactly what Folksoft is built for. Folksoft runs the programme and pairs you with a real human GRC analyst who guides you through every step — so you don't need an in-house resilience team to meet DORA.

Get started

Get DORA ready in weeks.

Book a demo and we'll confirm whether DORA reaches you as a financial entity or an ICT provider — then map your fastest path to meeting it.

30-day money back guarantee. No resilience hires needed.