Start my assessment

Banking, Finance & Insurance: DORA, NIS2 and operational resilience.

In finance and insurance, resilience is not just a matter of having procedures. It has to produce evidence: incidents classified, changes traced, providers registered, tests documented, exit strategies and responsibilities clearly established.

Atlassian Platinum Solution Partner since 2008 · French consultancy · Paris and Lyon

Office towers in a business district at dusk
The dominant constraintDORA and NIS2 turn resilience into operational, auditable requirements.

DORA: producing evidence in the flow of work

Regulation (EU) 2022/2554, known as DORA, concerns the digital operational resilience of the financial sector. It covers European financial entities, credit institutions, insurance and reinsurance undertakings, payment service providers and the other categories listed in Article 2, together with their third-party ICT service providers.

27 December 2022Publication in the Official Journal of the European Union.
17 January 2025Application. A regulation applies directly, with no national transposition.
Chapters II to VICT risk, incidents, resilience testing, third-party providers, register of information and exit strategies.

DORA does not ask for an intention, it asks for a trace.

A record is produced in the service tool, at the moment of the action, not in a spreadsheet rebuilt the day before the audit. That is the point that changes life for an IT department.

NIS2: strengthening control of digital risk

Depending on the entity's activity and scope, NIS2 may also apply alongside DORA. It strengthens the requirements on cybersecurity, risk management, continuity and supplier control.

Our role is to make sure these requirements show up in everyday processes, responsibilities and tools, rather than in parallel arrangements that are hard to maintain.

What we build the tooling for

RequirementWhat the audit expectsWhat BleuLemon puts in place
ICT riskInventory of assets, services and dependenciesAn asset and service repository, links with the service processes, explicit responsibilities.
IncidentsConsistent classification and a reliable historyQualification grids, workflows, notification templates, timestamping and dashboards.
ChangesApproval and traceabilityChange process, impact analysis, approvals, outcome and a history that can be consulted.
Third-party providersVisibility and review of dependenciesRegister of third parties, periodic reviews, responsibilities and links with the services concerned.
Resilience testingScenarios, results, remediationDocumented test sets, switchover exercises, remediation backlog and follow-up.
Exit strategiesReversibility, demonstratedRecovery tests on data, configurations, attachments and permissions in usable formats.

Compliance does not depend on any one tool, but on the ability to produce reliable processes, clear responsibilities and usable records.

Two people checking a configuration, line by line
Monitoring on the big screen

Two engagements carried out in this industry

Opteven

We replaced GLPI with Jira Service Management and Assets. The first release came after 7 weeks. We migrated 500 tickets with no service interruption. The engagement continued as an application maintenance contract (TMA, third-party application maintenance).

Viamedis

We ran an audit, then a data anonymisation PoC, leading to a Cloud trajectory. The PoC validated the anonymisation of a complete production data set, with no functional discrepancy found in acceptance testing.

The full Opteven engagement is set out in our case studies.

Frequently asked questions

A question that finds no answer here is dealt with in a thirty-minute conversation, about your actual context rather than a general case.

Talk to an expert
Since when has DORA applied?

Regulation (EU) 2022/2554 has applied since 17 January 2025. Published in the Official Journal of the European Union on 27 December 2022, it covers European financial entities and their third-party ICT service providers. A regulation applies directly, with no national transposing text.

What is the difference between DORA and NIS 2?

DORA is a sector regulation focused on the digital operational resilience of the financial sector. NIS2 is a broader cybersecurity directive. Depending on the entity and its scope, the two frameworks may need to be considered together.

Do you need to change ITSM tool to comply with these requirements?

Rarely. We start from the existing configuration and the processes actually used, then we fix the blind spots. The quality of the evidence matters more than the brand of the platform.

How do you handle supplier reversibility?

As a continuity matter: data, configurations, permissions and attachments must be recoverable in a usable format. The exit is documented and tested before you need it.

How long does it take to make a service platform auditable?

The pace depends on your history. Our reference path runs to 5 stages over 90 days: assessment and prioritised backlog, portal and knowledge base, automation in production, dashboards by role, review of service commitments. At Opteven, the first release came after 7 weeks.

Going further: IT service management (ITSM / ESM)·Support, application maintenance and managed services·Atlassian Cloud migration·Case studies