The Digital Operational Resilience Act (DORA) is an EU regulation requiring financial entities in the European Union to demonstrate the resilience of their ICT systems, manage ICT-related risks continuously, and report major ICT incidents to competent authorities. DORA mandates that entities identify and classify their critical or important functions (CIFs), maintain continuous vulnerability and threat assessment, and apply secure configuration baselines to ICT assets.
Compliance Assistant helps regulated entities manage DORA compliance by mapping CIFs to monitored IT assets, surfacing ICT risk signals from security and observability data, detecting and evaluating potential major ICT incidents against DORA classification thresholds, and supporting the documentation and reporting workflows required for regulatory notification.
Prerequisites
Required
To use DORA framework in Compliance Assistant, you need to:
Install and configure the Business Flow in your Dynatrace environment. At least one business flow must be created with Smartscape entity enabled. Business flows configured this way become available to designate as critical or important functions (CIFs) in the DORA framework.
Select at least one business flow as a critical or important function (CIF) in the DORA onboarding wizard. CIFs are the compliance-critical entities used to detect potential major incidents, assess economic impact, and track operational exposure. This corresponds to the DORA requirement to identify, classify, and document ICT-supported business functions (Article 8(1) and Article 3(22) DORA).
Recommended
To ensure a better experience, we also recommend that you set up the following:
Runtime Vulnerability Analytics (RVA) for vulnerability signals by severity, assessed over the last 30 minutes.
This adds vulnerability posture to the overall compliance score, supporting continuous ICT vulnerability assessments (Article 8(2) DORA).
Runtime Application Protection (RAP) for security detection findings by severity, assessed over the last 24 hours.
This adds threat detection posture, supporting continuous assessment of cyber threats and vulnerabilities (Article 8(2) DORA and Article 3 of the RTS on the ICT risk management framework).
Security Posture Management (SPM) for ICT asset configuration rule results (passed/failed) by severity.
This adds configuration compliance posture, supporting a secure ICT asset configuration baseline (Article 11(2) RTS on the ICT risk management framework, Article 9(2) DORA).
Use cases
Manage critical or important functions (CIFs) as business processes
DORA requires financial entities to identify, classify, and document ICT-supported business functions and the IT assets that underpin them (Article 8(1), Article 3(22) DORA). Compliance Assistant allows you to select critical or important functions (CIFs) by mapping compliance-relevant IT assets to end-to-end business processes. Compliance Assistant integrates with Business Flow to identify compliance-critical business process with configuration as an entity.
To add a critical or important function (CIF)
Go to Settings > Apps > Compliance Assistant.
Under the compliance framework DORA, select Add CIFs.
From the table, select business processes to add as CIFs.
Select Save to update the compliance framework.
To remove a critical or important function (CIF)
Go to Settings > Apps > Compliance Assistant.
Under the compliance framework DORA, select the menu icon of the CIF to remove.
From the menu, select Remove CIF.
Select Remove to confirm. Be aware that removing a CIF impacts all Compliance Assistant users.
To edit the estimated cost per minute of an incident
Go to Settings > Apps > Compliance Assistant.
Under the compliance framework DORA, select the menu icon of the relevant CIF.
From the menu, select Edit incident cost/min.
Add the estimated incident cost per minute to be used to calculate the economic impact of incidents impacting the relevant CIF.
Select Save.
Continuously monitor operational resilience
Go to Compliance Assistant > DORA > Overview.
Compliance Assistant provides a consolidated view of your organization's DORA compliance posture by surfacing ICT risk signals across three areas mandated by the regulation: critical business function health through business KPIs, ICT risk management, and incident exposure.
The Compliance Snapshot gauge reflects the current DORA compliance risk posture as a tiered score. The score is determined by the most severe active signals.
Article 8(2) DORA and the RTS on the ICT risk management framework require financial entities to maintain continuous vulnerability and threat assessment capabilities. The ICT Risk Management section consolidates critical-severity findings from three integrated capabilities:
Runtime Vulnerability Analytics (RVA)—vulnerability findings by severity and runtime exposure, supporting continuous vulnerability assessment.
Runtime Application Protection (RAP)—security detection findings, providing visibility into active threats and suspicious activity across monitored assets.
Security Posture Management (SPM)—configuration rule results summarized by passed and failed rules by severity, evaluated against the relevant compliance standard.
Select a tile to go to the relevant capability for investigation and remediation.
Investigate and classify potential compliance incidents
Compliance Assistant:
Is designed to help you manage ICT incidents in line with EU DORA requirements.
Automatically classifies ICT incidents against DORA classification thresholds and accelerates reporting of major incidents to align with regulatory deadlines.
Streamlines the assessment of IT-detected incidents affecting business processes configured as CIFs into unclassified problems, potential major incidents, and classified major incidents.
Go to Compliance Assistant > DORA.
See the Incidents section to see the tables of potential major incidents and unclassified problems.
Select the relevant incident to view the following details on any triggered classification threshold according to the EU DORA Regulation:
Critical or important functions (CIFs) affected by the incident.
Incident duration, calculated on the basis of the duration of the underlying problem in nanoseconds. The materiality threshold for the classification criterion is met when the duration of the incident is longer than 24 hours (RTS on the classification of ICT-related incidents and cyber threats).
The economic impact of the incident is calculated on the basis of the estimated incurred cost per minute of the affected CIFs and the duration of the underlying problem. To learn more about configuring the estimated cost value per minute, see Edit the estimated cost per minute of an incident. The materiality threshold for the classification criterion Economic impact is met where the costs and losses incurred by the financial entity due to the incident have exceeded or are likely to exceed €100,000 (RTS on the classification of ICT-related incidents and cyber threats).
To classify an incident as major in line with EU DORA, from the incident details view, select Classify as major.
Optional Add a comment to document your decision. This comment is added to the incident classification business event.
Select Confirm.
Be aware that classification triggers ingestion of a business event with the details of the classified compliance incident; the process may take a few seconds.
You can view the classified incident in Compliance Assistant > DORA > Incidents > Classified incidents.