Article 13(6) β financial entities must include ICT-related awareness and resilience training as compulsory staff training, with documented evidence
Loading...
We deliver mandatory DORA training across your workforce β ICT risk management, third-party ICT risk, incident reporting, digital operational resilience testing, and threat-led penetration testing. Managed rollout, audit-ready evidence accepted by EBA, ESMA, EIOPA, and national supervisors. Live for your team in under a week.
DORA Article 13(6) explicitly requires financial entities to develop ICT-related awareness programs and digital operational resilience training as compulsory modules in their staff training schemes. Article 5 makes the management body responsible for the ICT risk-management framework β and personally accountable. The regulation applies to ~22,000 financial entities across the EU plus their critical ICT third-party providers, with no transitional carve-outs after 17 January 2025.
Article 13(6) β financial entities must include ICT-related awareness and resilience training as compulsory staff training, with documented evidence
Article 5 β management bodies are personally accountable for the ICT risk-management framework and its training components
Article 14 β communication strategies for ICT incidents require staff trained on internal and external escalation
Article 28 β third-party ICT risk obligations cascade training requirements to your critical providers
Different roles face different risks. Training tailored to job responsibilities.
A 60-min working session with a specialist. We map your obligations, current training gaps, and regulator priorities in your jurisdiction.
Your processes, contacts, and policies go into the modules. We brand the LMS, wire SSO, and connect HRIS so enrolment is automatic.
Roll out to all staff. Automated nudges hit non-completers. Manager dashboards in real time. Audit-ready records when regulators ask.
Ready to scope your programme?
Book a 30-min discovery call β no slides, no pitch, just specifics.
Dedicated customer success manager handles enrolment, role mapping, kickoff communications, and reminder cadence.
Dated certificates per learner, exportable completion logs, and management-body training records that meet supervisor documentation expectations.
Track completion across teams, business lines, and ICT third-party providers. Export evidence packages for EBA, ESMA, EIOPA, and national authorities.
SAML 2.0, OIDC, and SCIM provisioning. New joiners enrolled automatically. Leavers de-provisioned. Zero admin overhead.
Multi-year licensing rolls learners forward each year with content updates as ESAs publish technical standards (RTS/ITS) and supervisor guidance.
Your logo on certificates, co-branded learner emails, and the option to attach your ICT risk policy, incident response plan, or third-party register procedure to any module.
DORA enforcement landed in January 2025 and we needed Article 13(6) training documented across the entire workforce within weeks. The managed rollout delivered audit-ready evidence β and the management-body briefing covered Article 5 personal-liability points exactly the way our board needed.
Don't see your question? Send us a note β we usually reply same day.
Ask a questionTell us your entity type (credit institution, payment, investment, insurer, CASP, ICT TPP), your DORA proportionality category, and your headcount. We'll come back with a curriculum proposal, pricing, and a rollout plan within 1 business day.