Digital operational
resilience, handled.
How 01GRC maps to the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554) — across ICT risk management, incident management, resilience testing and ICT third-party risk.
Built around how DORA is structured.
DORA organises operational resilience into four pillars. Here is the article-by-article mapping of what each one asks for and what 01GRC delivers against it.
ICT risk management
Governance, identification, protection, detection, response and continuous learning — the management framework at the heart of DORA (Arts. 5–13).
Incident management
A managed lifecycle for ICT-related incidents and the classification that drives reporting (Arts. 17–18).
Resilience testing
A programme of digital operational resilience testing, evidenced against your recovery targets (Arts. 24–25).
ICT third-party risk
Third-party risk principles, contract management, and the Register of Information your regulator asks for (Arts. 28–30).
01GRC provides the tooling and audit evidence that support these DORA requirements. It is one component of an organisation's broader operational-resilience programme.
One platform, every standard you answer to.
DORA is one of several frameworks built in — and you can add your own. More framework guides are on the way.
- ISO/IEC 27001:2022
- ISO/IEC 27701
- DORA
- GDPR
- NIS2
- CIS Controls v8.1
- Add your own
See your DORA programme
the way it should look.
Book a personalised walkthrough — we'll demo ICT risk, incident management, resilience testing and the Register of Information on data shaped like yours.