Customer portal

DORA Compliance

Now recruiting MSSP partners  ·  deploy dark web monitoring under your own brand in 48 hours  |  Sign up to the Partner Portal →
DORA Compliance · EU Regulation 2022/2554

Dark web monitoring for DORA compliance

The Digital Operational Resilience Act requires financial entities to continuously monitor cyber threats, detect credential exposures, and share threat intelligence. SOS Intelligence delivers the capabilities you need to meet those obligations, deployed in days, not months.

Regulation (EU) 2022/2554In force from 17 Jan 2025NCSC Alumni
DORA Pillar CoverageSOS Intelligence
ICT Risk Management
Articles 5 to 16 · Continuous monitoring
Incident Detection & Reporting
Articles 17 to 23 · Flash alerts
Resilience Testing Support
Articles 24 to 27 · Threat intelligence feeds
Threat Intelligence Sharing
Article 45 · STIX/TAXII export
Third-Party Risk Management
Articles 28 to 44 · Supply chain & vendor monitoring

Regulation mapping

How SOS Intelligence maps
to DORA requirements

DORA introduces five pillars of operational resilience for financial entities. Our platform directly supports all five. Here is how each requirement maps to the capabilities already built into SOS Intelligence.

Art. 9

Detection: Promptly Identify Anomalous Activities

Article 9 requires financial entities to implement mechanisms to promptly detect anomalous activities, including network performance issues, ICT-related incidents, and potential material single points of failure. SOS Intelligence monitors 500+ dark web sources continuously and fires flash alerts within minutes of a new exposure, giving your security team early warning of threats before they become incidents.

SOS Intelligence delivers:
DARKMAP™ Continuous MonitoringReal-Time Flash AlertsCredential Exposure Detection
Art. 10

Response & Recovery: ICT Business Continuity

Article 10 mandates robust ICT business continuity policies with rapid response capabilities. When exposed credentials or data leaks are detected on the dark web, SOS Intelligence alerts your team immediately, enabling containment before threat actors can weaponise the data. Time-to-detection is measured in minutes, not weeks.

SOS Intelligence delivers:
Automated Breach AlertsWebhook IntegrationsSIEM / PSA Push
Art. 13

Learning & Evolving: Cyber Threat Intelligence

Article 13 requires financial entities to gather information on vulnerabilities and cyber threats, analyse their likely impact, and continuously monitor technological developments. SOS Intelligence provides the ongoing threat intelligence feed that satisfies this obligation: indexed dark web data covering credential dumps, ransomware leak sites, and threat actor activity relevant to your organisation.

SOS Intelligence delivers:
DARKSEARCH™ InvestigationThreat Trend ReportingRansomware Group Tracking
Art. 17 to 23

Incident Classification & Reporting

DORA requires structured classification and timely reporting of major ICT-related incidents. SOS Intelligence flash alerts include severity classification, source attribution, and timestamped evidence trails that support your incident reporting workflows. Exportable reports provide the documentation regulators expect.

SOS Intelligence delivers:
Severity-Classified AlertsEvidence-Trail ReportsPDF Export for Regulators
Art. 24 to 27

Resilience Testing: Threat-Led Intelligence

DORA mandates regular resilience testing, including threat-led penetration testing (TLPT) aligned with the TIBER-EU framework. SOS Intelligence threat data (indicators of compromise, attack patterns, threat actor TTPs) provides the external intelligence feed that informs realistic, evidence-based testing scenarios grounded in actual dark web activity targeting your sector.

SOS Intelligence delivers:
IOC FeedsThreat Actor ProfilesSTIX/TAXII Export
Art. 28 to 44

Third-Party Risk: ICT Supply Chain Monitoring

DORA holds financial entities accountable for the resilience of their critical ICT third-party providers, requiring ongoing monitoring of supply-chain risk and concentration risk. SOS Intelligence extends your visibility beyond your own perimeter: monitor your key suppliers, vendors and partners for breached credentials, data leaks and dark web mentions, and detect copycat domains impersonating your supply chain, so a third-party compromise reaches your dashboard before it reaches your business.

SOS Intelligence delivers:
Supply Chain & Vendor MonitoringThird-Party Breach AlertsCopycat Domain Detection
Art. 45

Information Sharing: Cyber Threat Exchange

Article 45 encourages financial entities to participate in trusted information-sharing communities, exchanging indicators of compromise, tactics, techniques, and procedures, and cybersecurity alerts. SOS Intelligence data is natively exportable in STIX/TAXII format, ready to feed into FS-ISAC, MISP, or any industry sharing framework your organisation participates in.

SOS Intelligence delivers:
STIX 2.1 ExportTAXII ServerMISP IntegrationAPI Access

Who is in scope

DORA applies to 20+ types of financial entity

If your organisation operates in financial services within the EU (or serves EU clients), DORA almost certainly applies to you. Here are the most common entity types we support.

Banks & Credit Institutions

Retail and commercial banks, building societies, and credit unions

Investment Firms

Brokerages, asset managers, wealth managers, and trading firms

Insurance & Reinsurance

Insurance undertakings, intermediaries, and reinsurance companies

Payment & E-Money

Payment institutions, e-money issuers, and account information service providers

Pension Funds

Institutions for occupational retirement provisions (IORPs)

Crypto-Asset Providers

Crypto-asset service providers and issuers of asset-referenced tokens

Central Counterparties

Trade repositories, CCPs, and central securities depositories

ICT Service Providers

Critical ICT third-party providers designated by regulators under DORA

Platform capabilities

Purpose-built for financial services
threat intelligence

Every capability in SOS Intelligence was designed to address real-world cyber risk. Here is what you get from day one.

DARKMAP™ Monitoring

Continuous automated scanning across 500+ dark web sources, including Tor marketplaces, closed hacker forums, Telegram groups, paste sites, and ransomware leak sites. Alerts fire within minutes.

Art. 9 · Art. 13

DARKSEARCH™ Investigation

On-demand search engine for the indexed dark web. Query domains, emails, IPs, and keywords across billions of records. Build threat assessments and investigate exposures in real time.

Art. 13 · Art. 24

Flash Alert Engine

Automated, severity-classified notifications via email and webhook the moment your domains, credentials, or keywords appear in dark web sources. Configurable thresholds and digest options.

Art. 9 · Art. 17

Intelligence Reporting

Generate branded PDF reports with severity breakdowns, source attribution, and trend analysis. Purpose-built for board-level reporting, regulatory evidence, and QBR presentations.

Art. 13 · Art. 17

STIX/TAXII & API

Export threat data in STIX 2.1 format. Push to MISP, FS-ISAC, or any TAXII-compatible sharing community. Full RESTful API with sandbox environment for integration testing.

Art. 45 · Art. 24

Credential Exposure Monitoring

Continuous scanning of breach databases and credential dumps for your domains. Detect exposed employee and customer credentials before threat actors use them for account takeover.

Art. 9 · Art. 10

2%
of global annual turnover
Maximum penalty for non-compliance with DORA

Non-compliance is not an option. The clock is already ticking.

DORA entered into force on 17 January 2025 with no transitional period. The European Commission has already opened infringement procedures against 13 Member States for failing to transpose the directive. Financial entities are expected to demonstrate compliance now, not later.

  • Fines of up to 2% of global annual turnover for financial entities
  • Fines of up to €5 million for critical ICT service providers
  • Regulators can impose inspections, remedial actions, and public sanctions
  • Individual liability for management body members (Article 5)
Key dates

DORA compliance timeline

16 Jan 2023

DORA enters into force

Regulation (EU) 2022/2554 published and enters into force, beginning the two-year implementation period for all EU financial entities.

17 Jan 2025

DORA becomes applicable

All financial entities must be fully compliant. No transitional period. Regulatory enforcement begins immediately.

30 Apr 2025

Registers of Information due

National competent authorities must submit Registers of Information on ICT third-party arrangements to the European Supervisory Authorities.

2025 to 2026

Ongoing enforcement Current

Regulators actively auditing compliance. ESAs have confirmed no grace period. The European Commission has opened infringement proceedings against Member States with incomplete transposition.

Approach comparison

Build in-house vs. deploy SOS Intelligence

Most financial entities lack the specialist infrastructure to monitor the dark web effectively. Here is how SOS Intelligence compares to building an in-house capability.

Capability In-House Build SOS Intelligence
Time to deploy 6 to 12 months 48 hours
Dark web source coverage Limited (10 to 50 sources) 500+ sources, continuously updated
Tor infrastructure & crawlers Must build and maintain Fully managed
Credential exposure monitoring Manual or partial Automated, real-time
STIX/TAXII export for sharing Custom development Native support
MISP integration Custom development Built-in
Regulatory-ready reporting Manual compilation One-click PDF generation
Ongoing maintenance Dedicated team required Fully managed SaaS
Annual cost estimate £150k to £300k+ (staff + infra) From £4,788/year

See your DORA exposure in 30 minutes

Book a DORA readiness demo. We will run a live dark web scan on your domain, map findings to DORA requirements, and show you exactly how SOS Intelligence fills the gaps in your compliance posture.

Privacy Settings
We use cookies to enhance your experience while using our website. If you are using our Services via a browser you can restrict, block or remove cookies through your web browser settings. We also use content and scripts from third parties that may use tracking technologies. You can selectively provide your consent below to allow such third party embeds. For complete information about the cookies we use, data we collect and how we process them, please check our Privacy Policy
Youtube
Consent to display content from - Youtube
Vimeo
Consent to display content from - Vimeo
Google Maps
Consent to display content from - Google
Spotify
Consent to display content from - Spotify
Sound Cloud
Consent to display content from - Sound