DORA & digital operational resilience
The DORA Regulation has applied to EU financial entities since 17 January 2025. It reaches Albania through EU parent groups and through contracts with European banks and insurers, who must pass DORA's terms on to their technology suppliers. At the same time, Law 25/2024 on cyber security places obligations on Albanian operators of critical infrastructure.
Who it is for
- →Albanian subsidiaries of EU banking and insurance groups
- →Software, cloud, data centre and BPO firms with EU financial clients
- →Domestic financial institutions preparing for alignment
What we do
- →DORA gap assessment
- →ICT risk management framework and supporting policies
- →Incident classification and reporting procedures
- →Business continuity plans
- →Register of ICT third-party contracts and DORA contractual clauses
- →Board training
Legal basis & regulators
- →Regulation (EU) 2022/2554 (DORA) and its technical standards
- →Law no. 25/2024 "On cyber security"
Experience
Procedures for incident reporting, ICT risk management and business continuity under DORA; audit of DORA compliance and of algorithmic trading controls; ICT risk assessment of trading infrastructure.
Frequently asked questions
It applies directly to financial entities in the EU. An Albanian company meets it when it is part of an EU group, or when it supplies ICT services to an EU bank, insurer or investment firm: the client must write DORA's requirements into the contract.
Security and service continuity policies, an incident notification procedure, audit rights for the client and an exit plan for the contract.