DORA software comparison
DORA compliance software compared. Every claim sourced.
11 platforms, read against five DORA duties on the vendors' own pages. No analyst reports, no review sites. Where a vendor states nothing, the table says so.
Book a demoEvery value read from the vendor's own page on 1 September 2026
In short
Most DORA tools name the regulation and stop there.
Of the 11 platforms here, only Matproof states all five duties on its own DORA page. Formalize states three. OneTrust and Orbiq state two. Drata, Vanta, Secfix and Kopexa list DORA as a supported framework and publish no capability detail at all. CisScan blocked automated reads, so its row is marked unverified rather than empty.
The table
Five DORA duties, eight columns, one source per row.
A cell says yes only where the vendor's own page claims the product does it. A page explaining what DORA requires of financial entities is not a product claim, and is not scored as one.
| Vendor | Register of Information | ICT third-party risk | Incident reporting | Resilience testing | TLPT | Published price | Stated hosting |
|---|---|---|---|---|---|---|---|
| CisScan | could not verify | could not verify | could not verify | could not verify | could not verify | could not verify | could not verify |
| Drata | not stated | not stated | not stated | not stated | not stated | not stated | not stated |
| Formalize | Yes | Yes | not stated | Yes | not stated | not stated | not stated |
| Kertos | not stated | Yes | not stated | not stated | not stated | not stated | not stated |
| Kopexa | not stated | not stated | not stated | not stated | not stated | not stated | not stated |
| Matproofus | Yes | Yes | Yes | Yes | Yes | not stated | 100% EU data residency (hosted in Germany) |
| OneTrust | not stated | Yes | not stated | Yes | not stated | not stated | not stated |
| Orbiq | not stated | Yes | Yes | not stated | not stated | not stated | We are headquartered in Hamburg, Germany, and all our infrastructure is hosted in Europe via European data centers |
| Secfix | not stated | not stated | not stated | not stated | not stated | not stated | not stated |
| secjur | not stated | not stated | Yes | Yes | not stated | not stated | Hosted in Germany |
| Vanta | not stated | not stated | not stated | not stated | not stated | not stated | not stated |
Each row reflects one page per vendor, named in the source list below, read on 1 September 2026. “not stated” means that page does not state it; the vendor may state it elsewhere. “could not verify” means the site blocked automated access, which is not the same as an absent capability.
- Drata: “DORA - Improve ICT resilience to meet EU financial-sector operational requirements.” https://drata.com/frameworks
- Formalize: “Formalize produces the complete Register of Information based on the structured information maintained in the platform.” https://formalize.com/en/dora
- Kertos: “Maintain an overview of partner certificates” https://www.kertos.io/en/solutions/fintech
- Kopexa: “Digital Operational Resilience Act. EU regulation for digital resilience in the financial sector.” https://kopexa.com/en/catalog
- Matproof: “Maintain the Art. 28 register of all ICT providers.” https://matproof.com/frameworks/dora
- OneTrust: “Digital operational resilience testing: Basic and advanced testing” https://www.onetrust.com/solutions/digital-operational-resilience-act-dora-compliance/
- Orbiq: “Continuous vendor due diligence that stays current” https://www.orbiqhq.com/
- secjur: “regelmäßige Tests zur operativen Resilienz” https://www.secjur.com/produkte/dora
- Vanta: “DORA - Build resilience to ICT disruptions with this EU regulation for financial services and third-party tech providers.” https://www.vanta.com/products/additional-frameworks
What the regulation asks for
The five duties this table scores.
Regulation (EU) 2022/2554. Article references are to the regulation itself, not to a vendor's reading of it.
| Article | Duty |
|---|---|
| Art. 28(3) | Keep and maintain the Register of Information on every ICT third-party arrangement. |
| Art. 28-30 | Manage ICT third-party risk: due diligence, contractual terms, exit plans. |
| Art. 19 | Report major ICT-related incidents to the competent authority within the set deadlines. |
| Art. 24-25 | Run a digital operational resilience testing programme. |
| Art. 26-27 | Carry out threat-led penetration testing, for the entities that fall in scope. |
Method
How this comparison was built, and where it is weak.
One page per vendor, chosen as the vendor's most DORA-specific public page. Every capability cell traces to that page, listed below with its URL.
A sentence describing what DORA obliges financial entities to do is not a product claim. IRM360 was scored yes on three columns on a first pass for exactly that mistake, and in fact publishes no product claim. The scoring was redone with that separation enforced.
An ICT risk register is not the Register of Information of Art. 28(3). They are different artefacts, and are scored separately.
Sources
- CisScan
https://www.cisscan.com/frameworks/dora - Drata
https://drata.com/frameworks - Formalize
https://formalize.com/en/dora - Kertos
https://www.kertos.io/en/solutions/fintech - Kopexa
https://kopexa.com/en/catalog - Matproof
https://matproof.com/frameworks/dora - OneTrust
https://www.onetrust.com/solutions/digital-operational-resilience-act-dora-compliance/ - Orbiq
https://www.orbiqhq.com/ - Secfix
https://www.secfix.com/frameworks/dora - secjur
https://www.secjur.com/produkte/dora - Vanta
https://www.vanta.com/products/additional-frameworks
Known gaps
- One page per vendor. A capability stated on a different page of the same site is not captured.
- CisScan returned HTTP 403 to automated requests on both URLs tried. Its row is unverified, not negative.
- Prices are only what the read page states. Most of these vendors route buyers to a sales call.
- Matproof's own DORA page states no price. The pricing page does. That gap is ours and it is shown as “not stated” like everyone else's.
Questions
DORA software, answered.
Which DORA compliance software covers the most of the regulation?
Of the 11 platforms compared here on 1 September 2026, Matproof is the only one whose own DORA page states all five duties: Register of Information, ICT third-party risk, incident reporting, resilience testing and TLPT. Formalize states three, OneTrust and Orbiq two each. Drata, Vanta, Secfix and Kopexa name DORA as a supported framework but publish no capability detail. This measures what vendors publish, not what they can do in a demo.
Does DORA require me to buy software?
No. DORA sets duties on financial entities, not a requirement to use a product. A small entity with few ICT providers can maintain the Register of Information and the incident process in documents. Software earns its place when the register has to stay current across many providers, when evidence is collected continuously, or when the Art. 19 deadlines have to be met without manual work.
How much does DORA compliance software cost?
Most vendors publish nothing. On the pages read for this comparison on 1 September 2026, not one of the 11 international platforms states a price on its DORA page. In the Italian market GAPOFF publishes EUR 499, 990 and 1,790 per month, and in France Galea Cyber publishes EUR 1,000 and 2,500 per month excluding tax. Everyone else routes you to a sales call.
What is the Register of Information?
Article 28(3) of Regulation (EU) 2022/2554 requires a financial entity to maintain a register of information on all contractual arrangements for the use of ICT services provided by third-party providers. It is a specific reporting artefact with a defined structure. It is not the same thing as an internal ICT risk register, and several vendors publish the latter while not claiming the former.
Next step
See the five duties in one platform.
A 20-minute demo, no consultant required.
Book a demo