DORA · Regulation (EU) 2022/2554
DORA makes financial entities responsible for ICT resilience — and for the records that prove it: incident reports, resilience tests, the register of ICT third parties. A log you keep yourself is easy to doubt. LedgerProof turns each of those records into a tamper-evident, independently verifiable, cryptographically anchored receipt — evidence a supervisor can check without trusting you or any vendor.
What DORA is. The Digital Operational Resilience Act — Regulation (EU) 2022/2554 — is the EU's single rulebook for the financial sector's resilience to ICT (technology) disruption. Adopted on 14 December 2022, it entered into force on 16 January 2023 and has applied since 17 January 2025. It reaches a broad range of financial entities — from banks, payment and e-money institutions to investment firms, insurers, trading venues and crypto-asset service providers — and, through an EU oversight framework run by the three European Supervisory Authorities, their critical ICT third-party providers. A companion directive, Directive (EU) 2022/2556, aligns the older financial-sector directives with it.
Why evidence is the hard part. DORA does not just ask you to do the right things — it expects you to be able to show them to a competent authority, often under time pressure. The weak point is almost always the record: an internal log your organisation wrote itself can be edited after the fact, so it proves little to a third party. Verifiable evidence has to be independently checkable and tamper-evident — anyone can confirm a record existed in exactly that form at that time, without trusting you. That is precisely what LedgerProof produces.
DORA is built on five areas. Each one leaves a paper trail a supervisor may later scrutinise — and each is a place a cryptographically anchored receipt makes that trail provable.
DORA asks for: A documented ICT risk-management framework, with policies, and records of ICT assets and logs, as part of the firm's overall risk management.
LedgerProof: Anchor each version of your framework and key policies, so you can prove which version was in force on any given date.
DORA asks for: Detect and classify ICT-related incidents, and report a major one to your competent authority in three stages: an initial notification, an intermediate report, and a final report.
LedgerProof: Anchor the incident record and each report the moment it is filed — timestamped — so what you reported, and when, is provable later.
DORA asks for: A testing programme, and — for identified entities — threat-led penetration testing (TLPT) at least every three years.
LedgerProof: Anchor test scopes, results and remediation records as fixed, independently checkable artifacts an assessor can trust.
DORA asks for: Maintain a register of information on every contractual arrangement for ICT services, kept updated and reported to authorities at least yearly.
LedgerProof: Anchor a dated snapshot of each register submission, so the exact version you reported is fixed and verifiable after the fact.
DORA asks for: Voluntary arrangements to exchange cyber-threat information and intelligence among financial entities.
LedgerProof: Anchor the provenance of shared intelligence, so recipients can independently verify its origin and that it has not been altered.
Time limits for a major ICT-related incident — Commission Delegated Regulation (EU) 2025/301.
A LedgerProof receipt fixes the exact content and time of each report as you file it. “We reported on time” stops being something you assert and becomes something you can prove.
The authoritative material, ranked by how cleanly it can be fingerprinted and cryptographically anchored. Every URL was verified.
A Anchor directly — a stable Official-Journal PDF at a permanent URL. B Anchor a snapshot — a living regulator page that changes over time.
DORA — Regulation (EU) 2022/2554 — entered into force on 16 January 2023 and has applied since 17 January 2025. Its evidence expectations are live now, not upcoming.
No tool can. LedgerProof produces independently verifiable evidence that a record — an incident report, a test result, a register submission — existed, unaltered, at a specific time. Whether that satisfies a DORA obligation is a determination your auditor, competent authority, or counsel makes.
The ones a supervisor may later scrutinise: major-incident reports and their timing, resilience-test and TLPT results, the versions of your ICT risk-management framework, and each submission of the register of information.
No. LedgerProof is hash-only: it anchors the SHA-256 fingerprint of a record, never the record itself. The document never leaves your systems, which keeps the approach GDPR-clean and confidentiality-safe.
Yes. Receipts keep verifying against the public chain independently of LedgerProof — anyone can confirm a record existed in a given form at a given time, with no vendor dependency.
LedgerProof produces independently verifiable evidence, not a verdict — it does not make any firm “DORA-compliant.” Whether anchored evidence satisfies a given obligation is a determination your auditor, competent authority, or counsel makes. Authoritative text always remains the version on EUR-Lex / the Official Journal. Proofs are tamper-evident, not tamper-proof. Not legal advice.