New Paradigm Security
Governance, Risk & Compliance
Strategic Foundation
vCISO (Fractional CISO)
Enterprise GRC & Regulatory Compliance
Third Party Risk Management
Business Continuity Management
Vendor Security Guidance
Microsoft Security & Cloud
Technical Integration
Microsoft Purview Solutions
Microsoft Sentinel Services
Microsoft Entra ID Solutions
Microsoft Defender for Endpoint Solutions
Explore all our solutionsOverview
Success StoriesResourcesBlog
Get in Touch
New Paradigm Security

New Paradigm Security is an independent advisory firm specialised in Cybersecurity and Compliance. We help ambitious organisations build a secure, resilient digital future.

Enterprise Security. Strategic Advisory.

Services

  • vCISO (Fractional CISO)
  • Enterprise GRC & Regulatory Compliance
  • Third Party Risk Management
  • Business Continuity Management
  • Vendor Security Guidance
  • Microsoft Purview Solutions
  • Microsoft Sentinel Services
  • Microsoft Entra ID Solutions
  • Microsoft Defender for Endpoint Solutions

Company

  • About Us
  • Blog
  • Resources
  • Success Stories
  • Contact

Contact

contact@newparadigmsecurity.nl+31 20 210 1951
Jane Addamslaan 169, 1187DA Amstelveen

© 2026 New Paradigm Security BV. Amstelveen, The Netherlands.

Privacy PolicyTerms of Service
Free Interactive Tool

DORA Compliance Maturity Assessment

Evaluate your financial institution's Digital Operational Resilience. Measure your actual readiness across all 6 DORA pillars based on your entity classification tier.

5 minutes to complete
Immediate gap analysis
No registration required
Assessment ProgressSelect tier to begin

Select Your Organization Tier

DORA applies proportionate requirements based on your systemic importance.

Why Tier Selection Matters

Tier 1 entities face the most stringent requirements (including mandatory Threat-Led Penetration Testing), while Tier 3 entities have simplified obligations. Your selection automatically filters the assessment questions.

Enterprise-Grade Methodology

This assessment model is engineered by Kerem Ozturk, former CISO at ING Bank Turkiye and Principal Consultant at DXC Technology. It reflects the exact governance and technical prerequisites utilized to secure European financial institutions.

DORA Compliance FAQ

DORA establishes uniform requirements for the security of network and information systems across the EU financial sector. Banks, insurance companies, investment firms, payment service providers, and their critical ICT service providers must demonstrate compliance or face supervisory action and significant penalties.

1. ICT Risk Management — Frameworks for identifying and managing IT risks. 2. Incident Management — Detecting, classifying, and reporting major incidents. 3. Resilience Testing — Regular testing including TLPT. 4. Third-Party Risk — Managing concentration risk and exit strategies. 5. Information Sharing — Cyber threat intelligence collaboration. 6. Governance — Board-level responsibility and internal audit.

DORA applies the principle of proportionality. Tier 1 (Significant Entities) face the most stringent requirements, such as mandatory TLPT which requires 6-12 months of preparation. Tier 3 (Small Entities) have simplified obligations while still maintaining core security baselines.

DORA entered into force on 16 January 2023 and applies from 17 January 2025. Financial entities must be fully compliant and supervisory authorities can take enforcement action for non-compliance.