Selling to EU financial institutions, or a financial entity yourself? Folksoft implements the ICT risk-management framework DORA requires, sets up incident reporting and resilience testing, and manages third-party ICT risk — so you meet the regulation without a resilience team.
From the moment you connect your stack to the day a regulator or financial customer asks for evidence, Folksoft runs the programme for you.
We stand up the governance, policies, and controls DORA's ICT risk pillar requires — owned by your board, not a binder.
Classification and reporting workflows for major ICT-related incidents, ready for the competent authority's deadlines.
We set up the digital operational resilience testing programme — and support advanced (TLPT) scoping where it applies.
Register of information, contractual requirements, and monitoring for your critical ICT providers — or for your own posture as an ICT provider to financial entities.
Folksoft watches your AWS, Azure, GCP, GitHub, GitLab, and Okta environments around the clock — so drift is surfaced the moment it appears.
DORA reaches you down one of two paths. Which one decides your scope, your deadlines, and who you answer to.
Banks, payment and e-money firms, investment firms, insurers, crypto-asset service providers, and more. The full DORA framework applies to you directly — all five pillars, with your competent authority supervising.
Tech vendors serving financial entities — cloud, data, security, and core platforms. DORA reaches you through contractual requirements your financial customers must impose, and if you are designated critical, through direct EU oversight.
In short: either you're a financial entity subject to DORA directly, or an ICT provider whose financial customers push DORA obligations onto you. Folksoft determines which and gets you ready.
If any of these sound like you, DORA is likely on your critical path.
Payments, lending, investment, insurance, and crypto firms operating in the EU and subject to DORA directly.
Cloud, data, security, and core platform vendors serving EU financial institutions.
Companies finding DORA contractual requirements arriving in renewals from financial customers.
Any company that must demonstrate operational resilience to EU financial regulators or partners.
Everything founders ask us before starting their DORA programme.
Still have questions?If you're an EU financial entity, it applies directly. If you're an ICT provider to financial entities, it reaches you through contracts — and possibly direct oversight if you're designated critical. Folksoft confirms your status.
DORA has applied since January 2025, so obligations and reporting are already live.
It depends on your role — financial entity or ICT provider — and on the scope of your environment, so there's no one-size-fits-all number. Contact us and we'll give you a tailored quote for your situation.
Yes. That's exactly what Folksoft is built for. Folksoft runs the programme and pairs you with a real human GRC analyst who guides you through every step — so you don't need an in-house resilience team to meet DORA.
Book a demo and we'll confirm whether DORA reaches you as a financial entity or an ICT provider — then map your fastest path to meeting it.