DORA compliance software for UK firms with EU exposure
DORA — the EU's Digital Operational Resilience Act — has applied since 17 January 2025. It does not bind UK-only firms directly, but it reaches UK financial entities with EU subsidiaries or branches, UK firms serving EU-regulated clients, and UK ICT providers to EU financial entities. STREAM® by Acuity helps in-scope firms evidence DORA's ICT risk, third-party oversight and incident obligations — including the Register of Information that every supervisory review examines first.
Does DORA apply to a UK firm?
Not automatically. DORA is an EU regulation — a purely domestic UK firm with no EU nexus is regulated instead by the FCA and PRA operational-resilience regime (PS6/21 and SS1/21), not by DORA. But three things pull a UK firm into DORA's scope:
An EU subsidiary or branch
You have an EU subsidiary or branch that is itself a regulated financial entity.
EU-regulated clients
You provide services to EU-regulated financial entities — an EU client base brings obligations with it.
ICT provider to EU entities
You act as an ICT third-party provider to EU financial entities — including an intra-group UK IT function serving an EU subsidiary.
If any of those is true, DORA follows you home. If none is, your obligations sit with the FCA/PRA regime — and STREAM® supports that too.
What is DORA, and when did it take effect?
DORA (Regulation (EU) 2022/2554) creates one binding standard for how EU financial entities manage ICT risk. It entered into force on 16 January 2023 and has applied since 17 January 2025, following a two-year transition. It rests on five pillars: ICT risk management, incident reporting, resilience testing, ICT third-party risk, and information sharing.
The Register of Information: DORA's hardest requirement
Under Article 28(3), every in-scope financial entity must maintain a Register of Information — a complete, structured record of every contractual arrangement with every ICT third-party provider, held at entity, sub-consolidated and consolidated levels, built to the ESAs' data model. It is the first document a supervisor examines, and the first place teams come unstuck.
How STREAM® helps you evidence DORA
STREAM® by Acuity gives in-scope firms one place to build and maintain the evidence DORA demands — rather than a spreadsheet per obligation.
Register of Information
Structure every ICT third-party arrangement to the ESAs' data model, with subcontractor chains and criticality classification, so the Register survives a data-quality check.
ICT third-party risk
Assess and continuously monitor cyber risk across your ICT vendor population, with tiering and control evidence — via the Vendor Management Hub.
Incident readiness
Assess incident thresholds and assemble the evidence a major-incident report requires, ready for your team to submit.
Control monitoring
Map controls once and evidence them against DORA and your other frameworks together, so continuous compliance replaces the annual scramble.
What's at stake
DORA gives supervisors real teeth. For a financial entity, penalties can reach up to 2% of total annual worldwide turnover. Beyond the fine, the exposure is board-level: DORA places ICT and third-party resilience squarely within management-body accountability, and a failed Register is a documented, dated finding. STREAM® exists to make that accountability defensible — evidence a supervisor accepts, produced continuously rather than reconstructed under deadline.
See how STREAM® evidences DORA
Book a walkthrough with our team and see the Register of Information, ICT third-party risk and incident evidence in one platform.
Book a walkthroughRelated solution
Third-Party Risk Management
How STREAM® and the Vendor Management Hub help you assess and continuously monitor cyber risk across your ICT vendor population.
Explore third-party risk management →Frequently asked questions about DORA
Common questions on DORA scope, the Register of Information, and how STREAM® helps.