Skip to main content
DORA

DORA Foundation

DORA Foundation for financial sector. ICT risk management and incident reporting. PECB-accredited.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers and consultants seeking foundational understanding of DORA requirements for ICT risk management
  • Professionals working in digital operational resilience or cybersecurity within the financial sector
  • Risk and compliance officers building knowledge of DORA obligations
  • Individuals responsible for managing third-party ICT risks in financial institutions
  • Anyone supporting their organization's journey toward DORA compliance

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Legal or regulatory specialists seeking an advanced or jurisdiction-specific legal interpretation of DORA rather than a practical management overview
  • Experienced ICT resilience practitioners who already implement DORA-aligned frameworks and are looking for advanced practitioner or lead implementer training
  • Individuals outside the financial sector with no interest in financial regulation or ICT risk management specific to that context

What you'll be able to do

  • 1Define the core concepts and principles of the Digital Operational Resilience Act (DORA)
  • 2Explain the main DORA requirements that apply to an ICT risk management framework
  • 3Identify practical actions and organizational approaches for achieving compliance with DORA
  • 4Describe how DORA addresses third-party ICT risk within the financial sector
  • 5Summarize the relationship between digital operational resilience and broader ICT risk management
  • 6Recognize the scope and applicability of DORA across different types of financial institutions

Day by day

Day 1Introduction to the Concepts and Requirements of DORA
  • DORA Background and Regulatory Context

    This module explains why DORA was introduced, its regulatory objectives, and the types of financial entities it covers within the European Union.

  • Core Concepts of ICT Risk Management and Digital Operational Resilience

    Participants examine the foundational ICT risk management concepts that DORA builds upon, including resilience objectives, threat scenarios, and key definitions.

  • Overview of DORA Requirements

    This module provides a structured overview of the main requirements DORA places on financial institutions, covering the principal pillars of the regulation.

By end of day

  • Explain the purpose and regulatory scope of DORA and the types of entities it covers
  • Describe the foundational ICT risk management concepts that underpin DORA requirements
Day 2DORA Requirements for ICT Risk Management and Exam Preparation
  • DORA ICT Risk Management Framework Requirements

    This module details the specific requirements DORA sets for building, governing, and maintaining an ICT risk management framework, including policies, testing, and incident reporting.

  • Third-Party ICT Risk and Compliance Approaches

    Participants explore how DORA addresses risks arising from third-party ICT service providers and examine practical compliance approaches organizations can adopt.

  • Course Review and Exam Readiness

    This module consolidates learning across both days and maps course content to the two competency domains assessed in the PECB DORA Foundation exam.

By end of day

  • Outline the key components of a DORA-compliant ICT risk management framework
  • Identify concrete steps an organization can take to advance its DORA compliance posture

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

The “PECB DORA Foundation” exam fully meets all the PECB Examination and Certification Program (ECP) requirements. It covers the following competency domains:

  • Domain 1: Fundamental concepts of ICT risk management and digital operational resilience
  • Domain 2: DORA requirements for an ICT risk management framework
  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 200 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Educational Approach

  • Lecture sessions include discussion questions and examples.
  • Participants are strongly encouraged to interact with one another, exchange ideas, and actively participate in discussions.
  • The quiz structure within the course closely mirrors that of the exam, ensuring participants are well-prepared.

Prerequisites

What is the PECB DORA Foundation course?

The PECB DORA Foundation course offers a comprehensive introduction to the Digital Operational Resilience Act (DORA), a regulatory framework designed to strengthen the IT security and operational resilience of financial entities across the EU. It covers the essential components of DORA, including its purpose, scope, core principles, and the obligations it imposes on entities operating in the financial sector. The course is structured to help participants understand the practical impact of DORA and how organizations can implement a resilience-oriented approach in compliance with the regulation.

Who should attend the DORA Foundation course?

This course is intended for a wide audience, including professionals working in financial institutions, ICT service providers, compliance officers, risk managers, cybersecurity practitioners, and consultants. It is also valuable for individuals seeking to gain a foundational understanding of DORA to support implementation or advisory activities within affected organizations.

What will I learn in the DORA Foundation course?

Participants will gain a strong grasp of DORA's key elements such as ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information-sharing arrangements. The course is designed to provide a high-level but practical perspective, enabling learners to identify and assess operational risks, align internal policies with DORA requirements, and prepare their organizations for compliance audits or supervisory reviews.

How long is the DORA Foundation course?

The course duration is two day, making it ideal for busy professionals who want a focused and impactful learning experience. Despite its concise format, it delivers deep insights into the regulatory landscape and equips learners with actionable knowledge.

Is there a certification exam included in the course?

Yes, the course includes a certification exam at the end. Upon passing, participants receive the PECB Certified DORA Foundation credential, validating their understanding of the regulation and enhancing their professional credibility in risk, compliance, and cybersecurity roles.

Buyers always ask

Who is legally required to comply with DORA, and does that make this course mandatory for those organizations?+

DORA applies to a broad range of financial entities and their critical ICT third-party service providers within the European Union. While affected organizations face a regulatory obligation to comply with the regulation, attending this training course is not itself a legal requirement.

The course provides foundational knowledge to help individuals support their organization's compliance efforts. It does not confer regulatory approval or compliance status.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

What competency domains does the PECB DORA Foundation exam cover?+

The exam assesses two domains: fundamental concepts of ICT risk management and digital operational resilience, and DORA requirements for an ICT risk management framework. These align directly with the two days of training content. For exam format, available languages, and scheduling information, refer to the official PECB List of Exams and Examination Rules and Policies.

Is prior knowledge of ICT risk management or financial regulation needed to benefit from this course?+

PECB lists no formal prerequisites for this course. It is designed to be accessible to professionals entering the topic from a range of backgrounds, including compliance, risk management, cybersecurity, and general management. Familiarity with financial sector operations or ICT concepts may help participants engage more quickly with the material but is not required.

Does the course address third-party ICT risk, and why does that matter under DORA?+

Yes. DORA places significant obligations on financial entities regarding the oversight and management of third-party ICT service providers, including cloud service providers. The course covers how DORA defines and governs these relationships, which is increasingly important as financial institutions rely heavily on outsourced technology services.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.