Why AD360
 
Solutions
 
Resources
 
 

Achieve DORA (Regulation (EU) 2022/2554) compliance with ManageEngine

The EU strengthened financial-sector digital resilience with the Digital Operational Resilience Act, which has applied directly across all member states since January 17, 2025, mandating robust ICT risk management, identity governance, multi-factor authentication, real-time threat monitoring, major-incident reporting, and comprehensive audit trails to withstand and recover from ICT disruptions.

Compliance

How can ManageEngine support financial entities in meeting these standards?

With ManageEngine AD360 (IAM), banks, insurers, investment firms, and other financial entities can start aligning with the principles of DORA. See the key clauses and how our solution helps in the table below.

Article 6 Article 6 - ICT risk management framework

Clause Functionality Explanation
Article 6(2) The ICT risk management framework shall include strategies, policies, procedures, ICT protocols and tools that are necessary to adequately protect all information assets and ICT assets. This includes computer software, hardware, and servers to protect all relevant physical components and infrastructures, such as premises, data centers, and sensitive designated areas. This ensures that information assets and ICT assets are adequately protected from risks including damage and unauthorized access or usage. AD360 - Role-based access management, OU-based delegation, access certification, MFA, conditional access, SSO. AD360 enforces protection of digital information and ICT assets through access controls, privilege governance, and adaptive authentication.The clause also covers protection of physical premises and data centers, which is a physical-security domain not addressed by AD360; customers should supplement with physical access control and environmental security systems.
Article 6(8)(e) outlining the different mechanisms put in place to detect ICT-related incidents, prevent their impact and provide protection from it; AD360 - Adaptive MFA, conditional access, identity threat protection. AD360 contributes preventive controls at the identity layer through adaptive MFA, conditional access policies, and behavior-based identity threat protection.

Article 8 Article 8 - Identification

Clause Functionality Explanation
Article 8(1) As part of the ICT risk management framework, financial entities shall identify, classify and adequately document all ICT supported business functions, roles and responsibilities. This includes the information assets and ICT assets supporting those functions, and their roles and dependencies in relation to ICT risk. AD360 - Identity life cycle management, role-based access control, access certification campaigns, more than 200 identity and access reports. AD360 (ADManager Plus) catalogs the user roles, group memberships and access entitlements that underpin business functions, and access-certification campaigns drive the periodic review of that classification.
Article 8(4) Financial entities shall identify all information assets and ICT assets, including those on remote sites, network resources and hardware equipment, and shall map those considered critical. They shall map the configuration of the information assets and ICT assets and the links and interdependencies between the different information assets and ICT assets. AD360 - Hybrid AD reporting across Active Directory, Entra ID, Microsoft 365, Exchange, SharePoint, Teams, OneDrive. AD360 contributes a unified inventory of identity-bearing assets across on-premises and Microsoft cloud workloads, while Cloud Security Plus surfaces VPC, IAM and service configuration data that lets teams map dependencies and criticality.
Article 8(6) For the purposes of paragraphs 1, 4 and 5, financial entities shall maintain relevant inventories and update them periodically and every time any major change as referred to in paragraph 3 occurs. AD360 - User, group, computer and OU inventory reports; more than 140 prebuilt reports for AD and Microsoft 365. AD360 produces and refreshes inventories of users, groups, computers, GPOs and OUs through ADManager Plus, with scheduled reports that catch state changes.

Article 9 Article 9 - Protection and prevention

Clause Functionality Explanation
Article 9(2) Financial entities shall design, procure and implement ICT security policies, procedures, protocols and tools that aim to ensure the resilience, continuity and availability of ICT systems. This will support critical or important functions, and maintain high standards of availability, authenticity, integrity and confidentiality of data, whether at rest, in use or in transit. AD360 - MFA, SSO, conditional access, role-based access control, access certification, encryption-key-aware administration. AD360 supports authenticity and confidentiality by binding access to strong authentication, conditional access policies and certified entitlements. Encryption of data in transit (TLS, VPN, MACsec) is a network-stack control delivered by other tooling; customers must supplement AD360 with transit-encryption infrastructure for full coverage of this clause.
Article 9(3) In order to achieve the objectives referred to in paragraph 2, financial entities shall use ICT solutions and processes that are appropriate in accordance with Article 4. Those ICT solutions and processes can be divided into four portions. These shall (a) ensure the security of the means of transfer of data, and (b) minimize the risk of corruption or loss of data, unauthorized access and technical flaws that may hinder business activity. Further, the solution shall, (c) prevent the lack of availability, the impairment of the authenticity and integrity, the breaches of confidentiality and the loss of data. It should also (d) ensure that data is protected from risks arising from data management, including poor administration, processing-related risks and human error. AD360 - Access certification, privileged-action audit, approval workflows, role-based delegation. Sub-requirements (b), (c) and (d) are directly addressed: AD360 prevents unauthorized access and human-error misadministration through workflow-gated changes and access certification.Sub-requirement for the security of the means of transfer of data, that is (a), depends on TLS/IPsec/VPN infrastructure outside the suite; AD360 monitors and audits the resulting flows but does not encrypt them, so customers must rely on their network-layer encryption stack for that part of the clause.
Article 9(4)(a) develop and document an information security policy defining rules to protect the availability, authenticity, integrity and confidentiality of data, information assets and ICT assets, including those of their customers, where applicable; AD360 - more than 140 built-in identity and compliance reports, access certification documentation. AD360 produces the entitlement and certification reports that document who can access what.
Article 9(4)(c) implement policies that limit the physical or logical access to information assets and ICT assets to what is required for legitimate and approved functions and activities only, and establish to that end a set of policies, procedures and controls that address access rights and ensure a sound administration thereof; AD360 - Role-based access control, OU-based delegation, access certification campaigns, approval-based workflows, privileged user auditing, just-in-time provisioning, identity risk management. AD360 implements logical access control at scale: roles and OU-based delegation enforce least privilege, approval-based workflows gate privileged actions, and access-certification campaigns drive periodic recertification of entitlements. ADAudit Plus records every privileged action across Active Directory and Entra ID, closing the administrative-soundness loop the clause requires. Physical access control is a separate domain outside the suite.
Article 9(4)(d) implement policies and protocols for strong authentication mechanisms, based on relevant standards and dedicated control systems, and protection measures of cryptographic keys whereby data is encrypted based on results of approved data classification and ICT risk assessment processes; AD360 - Adaptive MFA with 20 authenticators, FIDO2 passkeys, biometrics, smart card/YubiKey, conditional access, SSO, password policy enforcer. AD360 (ADSelfService Plus) delivers the strong-authentication portion of the clause through adaptive, risk-based MFA with phishing-resistant FIDO2, biometrics, smart card and hardware token support, applied to Windows, Linux, macOS, VPN, OWA and enterprise applications. Cryptographic-key management and data-at-rest encryption are separate disciplines: customers must run a dedicated KMS or HSM and apply encryption based on their own data classifications.
Article 9(4)(e) implement documented policies, procedures and controls for ICT change management. This includes changes to software, hardware, firmware components, systems or security parameters. These are based on a risk assessment approach which are an integral part of the financial entity's overall change management process to ensure that all changes to ICT systems are recorded, tested, assessed, approved, implemented and verified in a controlled manner; AD360 - Approval-based workflows for AD/Entra ID/Microsoft 365 changes, granular role delegation, change audit reports. AD360 enforces the approve-implement-verify loop for identity-related changes through approval workflows and delegated technician roles; every action is captured in the audit trail.

Article 10 Article 10 - Detection

Clause Functionality Explanation
Article 10(3) Financial entities shall devote sufficient resources and capabilities to monitor user activity, the occurrence of ICT anomalies and ICT-related incidents, in particular cyberattacks. AD360 - Real-time logon/logoff tracking, privileged user audit, identity threat protection. AD360 supplies the identity-layer signal -logon successes and failures, privileged actions and lockouts- for correlation against system telemetry.

Article 11Article 11 - Response and recovery

Clause Functionality Explanation
Article 11(2) Financial entities shall implement the ICT business continuity policy through dedicated, appropriate and documented arrangements, plans, procedures and mechanisms. Through five processes, the aim is to: (a) ensure the continuity of the financial entity's critical or important functions; and (b) quickly, appropriately and effectively respond to, and resolve, all ICT-related incidents to limit damage and prioritize recovery actions. The next process is (c) to activate, without delay, dedicated plans that enable containment measures, processes and technologies for each type of ICT-related incident and prevent further damage, and provide a tailored response and recovery procedures in accordance with Article 12. The last processes are (d) to estimate preliminary impacts, damages and losses, and (e) to set out communication and crisis management actions that ensure updated information is transmitted to relevant internal staff and external stakeholders in accordance with Article 14, and report to the competent authorities in accordance with Article 19. AD360 - Approval-based workflows, account-disable automations, Recovery Manager Plus for AD/Entra ID/M365 rollback. AD360 restores Active Directory, Entra ID and Microsoft 365 objects affected by the incident.

Article 12 Article 12 - Backup policies and procedures, restoration and recovery procedures and methods

Clause Functionality Explanation
Article 12(1) Involves two processes for the purpose of ensuring the restoration of ICT systems and data with minimum downtime, limited disruption and loss, as part of their ICT risk management framework, and financial entities shall develop and document. Process (a) backup policies and procedures specifies the scope of the data that is subject to the backup and the minimum frequency of the backup, based on the criticality of information or the confidentiality level of the data. Process (b) addresses restoration and recovery procedures and methods. AD360 - Recovery Manager Plus with scheduled and incremental backups for AD, Entra ID, Microsoft 365, Exchange, Google Workspace, SharePoint Online, OneDrive; configurable retention periods; granular and full restoration. AD360 directly addresses identity-system backups through Recovery Manager Plus: scheduled and incremental backups cover all in-scope identity and collaboration assets, retention is configurable per data class, and the restoration procedure supports attribute-level, object-level and full rollback. The clause's scope is broader than identity—file systems, databases, application data—so customers must combine Recovery Manager Plus with a general-purpose backup product to cover the full ICT estate, and document the consolidated policy.
Article 12(2) Financial entities shall set up backup systems that can be activated in accordance with the backup policies and procedures, as well as restoration and recovery procedures and methods. The activation of backup systems shall not jeopardize the security of the network and information systems or the availability, authenticity, integrity or confidentiality of data. Testing of the backup procedures and restoration and recovery procedures and methods shall be undertaken periodically. AD360 - Recovery Manager Plus with encrypted backup repositories (local, NAS, Azure Blob, AWS S3, S3-compatible), preview-before-restore, version history, and audit trail of backup/recovery operations. Recovery Manager Plus stores backups in encrypted repositories and audits every backup and recovery operation, so activation of the backup system itself does not weaken confidentiality or integrity. The preview-before-restore feature lets administrators verify the content they are about to restore, supporting periodic test-restoration exercises. Test orchestration and pass/fail sign-off remains a customer process.
Article 12(3) When restoring backup data using own systems, financial entities shall use ICT systems that are physically and logically segregated from the source ICT system. The ICT systems shall be securely protected from any unauthorized access or ICT corruption and allow for the timely restoration of services making use of data and system backups as necessary. AD360 - Recovery Manager Plus deployed on segregated infrastructure with its own access control; role-based delegation, MFA-gated console access via AD360 integration, SIEM integration for backup-action forwarding. Recovery Manager Plus runs as a dedicated system separate from the source domain controllers and Exchange servers it protects, satisfying the logical segregation requirement. Console access is controlled through AD360's adaptive MFA and role-based delegation, and audit logs of every backup and restore action are retained for independent monitoring, protecting the backup system itself from unauthorized use.

Article 16 Article 16 - Simplified ICT risk management framework

Clause Functionality Explanation
Article 16(1)(c) [Entities subject to the simplified framework shall] minimize the impact of ICT risk through the use of sound, resilient and updated ICT systems, protocols and tools which are appropriate to support the performance of their activities and the provision of services and adequately protect availability, authenticity, integrity and confidentiality of data in the network and information systems; AD360 - MFA, SSO, conditional access, role-based access control, identity life cycle management. AD360 protects the authenticity and confidentiality dimensions through identity-layer controls (MFA, conditional access, least-privilege roles). Encryption of data in transit is delivered outside the suite and must be addressed through the customer's network-layer stack.
Article 16(1)(f) [Entities subject to the simplified framework shall] ensure the continuity of critical or important functions, through business continuity plans and response and recovery measures, which include, at least, back-up and restoration measures; AD360 - Recovery Manager Plus with scheduled and incremental backups for AD, Entra ID, Microsoft 365, Exchange, Google Workspace, SharePoint Online, OneDrive; granular and full restoration; backup repository encryption. AD360 (Recovery Manager Plus) delivers the back-up and restoration component for identity and collaboration assets: scheduled and incremental backups, configurable retention, attribute-level and object-level restoration, and rollback to a chosen recovery point. Backups outside the identity and Microsoft cloud scope—file systems, databases, application data—must be addressed with a general-purpose backup product alongside Recovery Manager Plus.

Conclusion

Now that you've explored how DORA (Regulation (EU) 2022/2554) strengthens digital operational resilience across the EU's financial sector and how AD360 helps you meet every clause, it's time to take the next step.

Whether it's identity governance, audit logging, threat detection, or building a compliance-ready audit trail, we're here to guide you through it. Start a 30-day free trial to experience our solutions in your own environment, or contact us to schedule a one-on-one consultation.

Disclaimer: The information provided on this page is for general knowledge and awareness purposes only. It is not intended to serve as professional, legal, or regulatory advice. Compliance with DORA (Regulation (EU) 2022/2554) depends on your organization's specific environment, processes, and risk profile.

To accurately assess your compliance posture, we strongly recommend engaging a qualified consultant, compliance agency, or referring directly to the official DORA documentation and guidelines published in the Official Journal of the European Union (OJ L 333, 27.12.2022).

 
Chat now
   

Hello!
How can we help you?

I have a sales question  

I need a personalized demo  

I have a product query  

E-mail our sales team  

Book a meeting  

Chat with sales now  

Back

Book your personalized demo

Thanks for registering, we will get back at you shortly!

Preferred date for demo
  •  
    • Please choose an option.
    • Please choose an option.
  •  
  •  
    This field is required.

    Done

     
  • Contact Information
    •  
    •  
    •  
    •  
  • By clicking ‘Schedule a demo’, you agree to processing of personal data according to the Privacy Policy.
Back

Book a meeting

Thanks for registering, we will get back at you shortly!

Topic

What would you like to discuss?

  •  
  • Details
  •  
    • Please choose an option.
    • Please choose an option.
    Contact Information
    •  
    •  
    •  
    •  
  • By clicking ‘Book Meeting’, you agree to processing of personal data according to the Privacy Policy.