Research DORA
with trusted AI.

Cite the Regulation, RTS, and ITS to the article. ICT risk, incident reporting, resilience testing, and third-party oversight in one search. Applicable since 17 January 2025.

European Union Austria Belgium Bulgaria Croatia Cyprus Czech Republic Denmark Estonia Finland France Germany Greece Hungary Ireland Italy Latvia Lithuania Luxembourg Malta Netherlands Poland Portugal Romania Slovakia Slovenia Spain Sweden United Kingdom Norway Switzerland Iceland Liechtenstein

Built for DORA. Ready for supervisory scrutiny.

A modern glass tower against the sky
17 Jan 2025 DORA applies in full
A legal library overlooking a European cathedral
64 articles + RTS & ITS indexed
A modern glass tower at dusk
5 pillars risk, incidents, testing, 3rd-party, sharing
A private boardroom overlooking a European city
4 hours initial major-incident notification
A boardroom overlooking a European cityscape
24 languages every EU official language
A modern legal office
Daily ESA guidelines & technical standards
DORA coverage
Regulation text · RTS · ITS · EBA guidelines · ESMA & EIOPA guidelines · National transposition
How it works

From your documents to a full ICT risk file.

Upload

Drop your ICT risk register, third-party contracts, incident playbooks, or draft TLPT scope straight into the chat. Documents persist across the whole conversation.

Ask

Scope the ICT risk-management framework (Art. 5-16), classify ICT-related incidents, map critical third-party contractual clauses, or check your TLPT obligations, cross-referenced to the Regulation, every RTS and ITS, and ESA guidelines.

Export

A citation-backed report with paragraph-level gaps, obligation by obligation, ready to drop into your ICT risk file or board-level resilience briefing.

What are the ICT third-party risk requirements under DORA?

Chapter V: ICT third-party risk

Under Articles 28-30 of Regulation (EU) 2022/2554 (DORA), financial entities must manage ICT third-party risk as an integral part of their ICT risk-management framework, and maintain a register of information on all contractual arrangements (Art. 28(3)).

Key obligations

  • Pre-contractual due diligence and concentration-risk assessment (Art. 28(4)-(8))
  • Mandatory contractual provisions for all ICT services (Art. 30(2))
  • Enhanced terms for services supporting critical or important functions (Art. 30(3))
  • Exit strategies and audit/access rights for the entity and authorities

Critical-provider oversight

ICT providers designated critical under Article 31 fall under the Union Oversight Framework (Art. 31-44), led by a Lead Overseer (EBA, ESMA, or EIOPA). DORA has applied since 17 January 2025.

Trusted by legal and AI-governance teams across Europe.

"

The best AI for any research related to EU law and regulations. It always comes up with the best answer.

"

eulaw.ai is the only tool I trust for EU regulation. It has cut our compliance research time by at least 30%.

"

eulaw.ai enables us to take on clients from industries and jurisdictions we previously would have had to decline.

"

A single fabricated case citation can lead to professional sanctions. eulaw.ai is built so there is no fabricated legislation or case law: every reference traces back to a source in your results.

Your DORA work stays inside the EU.

EU Data Residency

Your documentation, queries, and chat history are stored and processed only within the EU.

Built for GDPR

Engineered for full GDPR compliance, so DORA research never works against your data-protection duties.

No Model Training

Your ICT risk files never train AI models. Model providers never receive or store your content.

Encryption

All customer data is encrypted at rest and in transit using modern protocols including TLS 1.3.

ISO 27001:2022 & SOC 2

Run from ISO 27001:2022 and SOC 2 certified data centres.

Audits & Vulnerability

Regular external security reviews, with continuous vulnerability scanning.

Your first DORA citation in 30 seconds.

Free trial · no credit card · cancel anytime.