Coreal.
Book a working session →
·Compliance · DORA

DORA compliance for standalone fintech.

Digital Operational Resilience Act (Regulation (EU) 2022/2554). Enforced from 2025-01-17. Supervised by European Banking Authority + national competent authorities (BaFin, FCA-equivalent in EU member states). Coreal generates the evidence pack automatically on every Minctrl build — see /security-compliance for the full posture.

Enforced
2025-01-17
Authority
European…
Penalties
Up to 2% of annual global turnover
Vertical
FINTECH

What this regulation covers.

ICT risk management, incident reporting and third-party oversight for financial entities operating in the EU.

For a standalone fintech, the salient angles are: EMI / PI / MiFID-II licence acquisition timelines (6–15 months); Sponsor-bank dependency for IBAN issuance; Customer-acquisition unit economics vs CAC payback. Primary licence: EMI or PI (most common); MiFID-II for neobrokers.

● RELEVANT ARTICLES
  • Art. 5 — ICT risk management framework
  • Art. 16 — Reporting major ICT-related incidents
  • Art. 24 — Threat-led penetration testing (TLPT)
  • Art. 28 — General principles for third-party ICT services
  • Art. 30 — Concentration risk
● EVIDENCE PACK COREAL GENERATES

What lands in the regulator file.

E01ICT risk register (versioned, per-process)
E02Incident timeline with operator + AI-agent actions
E03Decision journal (7-year retention, replayable)
E04Third-party risk inventory (provider gateway contracts)
E05TLPT scope document + penetration-test reports

All items journaled, replayable, 7-year retention.

● READ NEXT
·Questions we hear

Which DORA articles apply to a fintech?

Primarily: Art. 5 — ICT risk management framework; Art. 16 — Reporting major ICT-related incidents; Art. 24 — Threat-led penetration testing (TLPT). The full mapping is in the Coreal compliance posture document — see /security-compliance.

What evidence does Coreal generate per audit?

ICT risk register (versioned, per-process); Incident timeline with operator + AI-agent actions; Decision journal (7-year retention, replayable). The Minctrl pipeline produces this artefact set automatically on every build — see /company §05 'How we ship'.

What are the penalties for non-compliance?

Up to 2% of annual global turnover; member-state criminal liability for senior management on wilful non-compliance.

·Working session

Bring the perimeter,
leave with a brief.

Book a working session →Read field notes →
Not ready to book 4 hours?

Read the Wave-1 runbook first.

The full 90-day launch sequence — phases, partner-bank gates, who signs off when. No form to read it.

Read the runbook →

INDICATIVE DATA · Numbers and timelines reflect public regulator filings, vendor documentation and our own delivery experience. Per-engagement values vary with operator profile, BSS vintage and regulatory perimeter. Engage early for a fitted estimate under NDA.