About doratesting
doratesting explains the digital operational resilience testing requirements of the EU DORA regulation – what financial entities must test, how often, and what threat-led testing adds. Guidance about a regulation is only as good as its provenance, so this page sets ours out.
Who publishes it
SEQ SIA, registration No. 40203410806, Lastādijas iela 12 k-3, Riga, LV-1050, Latvia, trading as OffSeq. The company provides resilience and penetration testing to organisations in the EU. Contact: support@offseq.com.
This site is independent of the European Commission, the European Supervisory Authorities and every national competent authority. It reflects our reading of the published texts, not an official interpretation.
Who writes it
Articles are prepared and reviewed by OffSeq testers and consultants who work on DORA and NIS2 engagements. They are published under the editorial responsibility of SEQ SIA rather than an individual byline; a named author, where credited, appears under the headline with a link to their profile.
How regulatory claims are handled
- Requirements are cited to the instrument – Regulation (EU) 2022/2554 and the associated regulatory technical standards – with a link to the consolidated text on EUR-Lex.
- Where a requirement depends on proportionality or on supervisory discretion, we say so rather than presenting a single answer.
- The applicability tool on this site is an orientation aid. It is not a legal determination of scope.
- The “Updated” date moves only with the text, enforced by an automated content-hash ledger – which matters here, because the underlying rules keep evolving.
Conflict of interest
We sell DORA-related testing. A site explaining a testing obligation is therefore also lead generation, and you should weigh our recommendations accordingly.
- OffSeq links are our own service links.
- Nobody pays to appear on this site; there is no advertising, sponsorship or affiliate income.
- Much of what DORA requires – an inventory, a testing plan, evidence of remediation – is internal work no external provider can do for you, and the guides say that.
Not legal advice
Nothing here determines whether DORA applies to your entity or what your supervisor will accept. Take a legal or compliance opinion for that.
Corrections
Write to support@offseq.com with corrections. Substantive fixes are made and visibly re-dated.