Skip to main content

DORA Crosswalk

The Digital Operational Resilience Act (DORA — EU Regulation 2022/2554) entered application on 17 January 2025. It establishes a harmonised framework for ICT risk management across EU financial entities, replacing a patchwork of sector-specific ICT guidance with binding, directly applicable requirements.
DORA application date: 17 January 2025. This is not a future deadline — DORA is in force now. Trustees of schemes that fall within DORA’s scope should have assessed their ICT risk management framework, ICT incident management procedures, and ICT third-party risk management arrangements. If this assessment has not been completed, it should be treated as a priority governance matter under IORP II Article 21.

DORA Applicability to Pension Schemes

DORA Article 2 defines “financial entities” in scope. Institutions for Occupational Retirement Provision (IORPs) are explicitly included in the scope of DORA, subject to the following: Full scope: IORPs with more than 15 members are subject to the full DORA framework. Proportionate regime: IORPs with 15 members or fewer benefit from a simplified regime under Article 16 — proportionate requirements for ICT risk management. The Pensions Authority is the competent authority for IORPs in Ireland for DORA purposes, consistent with its role as the IORP II supervisory authority.
PensionsPortal.ie as an ICT third-party service provider: PensionsPortal.ie provides ICT services to Irish pension schemes. Depending on the materiality of those services, PensionsPortal.ie may qualify as a critical ICT third-party service provider (CTPP) subject to direct oversight by the European Supervisory Authorities (ESAs) under DORA Chapter V. We monitor CTPP designation criteria and will notify affected customers of any change in status.

DORA’s Five Pillars: PensionsPortal.ie Coverage

Pillar 1: ICT Risk Management (Articles 5–16)

The ICT risk management framework (ICTRM) must be documented, board-approved, and integrated into the scheme’s overall risk management system (IORP II Article 22). It must cover: ICT risk identification, protection, detection, response, and recovery.PensionsPortal.ie support: The Risk module provides a dedicated ICT risk register. The ORA module incorporates ICT risk as a sub-category of operational risk for Article 28 purposes. The Operations module hosts the ICT continuity plan with documented RTO/RPO.

Pillar 2: ICT-Related Incident Management (Articles 17–23)

Financial entities must establish and maintain ICT incident management processes, including: incident detection and classification, escalation procedures, and notification of major ICT incidents to the competent authority (Pensions Authority) within prescribed timeframes.Major incident classification: Article 18 defines major ICT incidents requiring regulatory notification. Criteria include: number of affected clients, duration of service disruption, geographic spread, data loss, criticality of disrupted services, and economic impact.PensionsPortal.ie support: Incident detection and alerting; severity classification aligned to DORA Article 18 criteria; Pensions Authority notification workflow; post-incident reporting templates aligned to DORA Article 19 requirements.

Pillar 3: Digital Operational Resilience Testing (Articles 24–27)

Financial entities must maintain a digital operational resilience testing programme covering: basic testing (vulnerability assessments, network security assessments, gap analyses, software testing), and for significant entities, threat-led penetration testing (TLPT) under Article 26.PensionsPortal.ie support: Annual independent penetration testing; quarterly vulnerability scanning; automated SAST in CI/CD; application security scanning. Test results and remediation evidence available to trustees as part of the platform security documentation pack.

Pillar 4: ICT Third-Party Risk Management (Articles 28–44)

Financial entities must maintain a register of all ICT third-party service providers, assess the risk of each provider, and ensure written contractual arrangements include mandatory provisions under Article 30 (including: service description, data locations, security standards, incident notification obligations, audit rights, exit provisions).PensionsPortal.ie support: The Outsourcing Register supports documentation of ICT third-party providers. PensionsPortal.ie’s own contractual terms with customers include all Article 30 mandatory provisions. Sub-processor list maintained with security assessments.

Pillar 5: Information and Intelligence Sharing (Article 45)

DORA encourages (but does not mandate) participation in cyber threat intelligence sharing arrangements among financial entities.PensionsPortal.ie approach: We monitor relevant threat intelligence channels including ENISA advisories, NCSC-IE feeds, and financial sector ISACs. Material threat intelligence relevant to platform security or customer risk is shared via platform security advisories.

DORA Article-by-Article Crosswalk


DORA and IORP II: The Relationship

DORA does not replace IORP II’s governance requirements — it supplements them with specific ICT risk requirements. The relationship:
For IORP II-compliant schemes, the most efficient approach is to treat DORA compliance as an extension of the existing IORP II governance framework — adding the ICT-specific requirements to the risk register, the ORA, the continuity plan, and the outsourcing register — rather than creating a parallel DORA compliance workstream. PensionsPortal.ie’s integrated approach supports this.