SEE MATPROOF ON YOUR STACK — BOOK A 30-MINUTE DEMO

DORA software comparison

DORA compliance software compared. Every claim sourced.

11 platforms, read against five DORA duties on the vendors' own pages. No analyst reports, no review sites. Where a vendor states nothing, the table says so.

Book a demo

Every value read from the vendor's own page on 1 September 2026

In short

Most DORA tools name the regulation and stop there.

Of the 11 platforms here, only Matproof states all five duties on its own DORA page. Formalize states three. OneTrust and Orbiq state two. Drata, Vanta, Secfix and Kopexa list DORA as a supported framework and publish no capability detail at all. CisScan blocked automated reads, so its row is marked unverified rather than empty.

The table

Five DORA duties, eight columns, one source per row.

A cell says yes only where the vendor's own page claims the product does it. A page explaining what DORA requires of financial entities is not a product claim, and is not scored as one.

VendorRegister of InformationICT third-party riskIncident reportingResilience testingTLPTPublished priceStated hosting
CisScancould not verifycould not verifycould not verifycould not verifycould not verifycould not verifycould not verify
Dratanot statednot statednot statednot statednot statednot statednot stated
FormalizeYesYesnot statedYesnot statednot statednot stated
Kertosnot statedYesnot statednot statednot statednot statednot stated
Kopexanot statednot statednot statednot statednot statednot statednot stated
MatproofusYesYesYesYesYesnot stated100% EU data residency (hosted in Germany)
OneTrustnot statedYesnot statedYesnot statednot statednot stated
Orbiqnot statedYesYesnot statednot statednot statedWe are headquartered in Hamburg, Germany, and all our infrastructure is hosted in Europe via European data centers
Secfixnot statednot statednot statednot statednot statednot statednot stated
secjurnot statednot statedYesYesnot statednot statedHosted in Germany
Vantanot statednot statednot statednot statednot statednot statednot stated

Each row reflects one page per vendor, named in the source list below, read on 1 September 2026. “not stated” means that page does not state it; the vendor may state it elsewhere. “could not verify” means the site blocked automated access, which is not the same as an absent capability.

What the regulation asks for

The five duties this table scores.

Regulation (EU) 2022/2554. Article references are to the regulation itself, not to a vendor's reading of it.

ArticleDuty
Art. 28(3)Keep and maintain the Register of Information on every ICT third-party arrangement.
Art. 28-30Manage ICT third-party risk: due diligence, contractual terms, exit plans.
Art. 19Report major ICT-related incidents to the competent authority within the set deadlines.
Art. 24-25Run a digital operational resilience testing programme.
Art. 26-27Carry out threat-led penetration testing, for the entities that fall in scope.

Method

How this comparison was built, and where it is weak.

One page per vendor, chosen as the vendor's most DORA-specific public page. Every capability cell traces to that page, listed below with its URL.

A sentence describing what DORA obliges financial entities to do is not a product claim. IRM360 was scored yes on three columns on a first pass for exactly that mistake, and in fact publishes no product claim. The scoring was redone with that separation enforced.

An ICT risk register is not the Register of Information of Art. 28(3). They are different artefacts, and are scored separately.

Known gaps

  • One page per vendor. A capability stated on a different page of the same site is not captured.
  • CisScan returned HTTP 403 to automated requests on both URLs tried. Its row is unverified, not negative.
  • Prices are only what the read page states. Most of these vendors route buyers to a sales call.
  • Matproof's own DORA page states no price. The pricing page does. That gap is ours and it is shown as “not stated” like everyone else's.

Questions

DORA software, answered.

Which DORA compliance software covers the most of the regulation?

Of the 11 platforms compared here on 1 September 2026, Matproof is the only one whose own DORA page states all five duties: Register of Information, ICT third-party risk, incident reporting, resilience testing and TLPT. Formalize states three, OneTrust and Orbiq two each. Drata, Vanta, Secfix and Kopexa name DORA as a supported framework but publish no capability detail. This measures what vendors publish, not what they can do in a demo.

Does DORA require me to buy software?

No. DORA sets duties on financial entities, not a requirement to use a product. A small entity with few ICT providers can maintain the Register of Information and the incident process in documents. Software earns its place when the register has to stay current across many providers, when evidence is collected continuously, or when the Art. 19 deadlines have to be met without manual work.

How much does DORA compliance software cost?

Most vendors publish nothing. On the pages read for this comparison on 1 September 2026, not one of the 11 international platforms states a price on its DORA page. In the Italian market GAPOFF publishes EUR 499, 990 and 1,790 per month, and in France Galea Cyber publishes EUR 1,000 and 2,500 per month excluding tax. Everyone else routes you to a sales call.

What is the Register of Information?

Article 28(3) of Regulation (EU) 2022/2554 requires a financial entity to maintain a register of information on all contractual arrangements for the use of ICT services provided by third-party providers. It is a specific reporting artefact with a defined structure. It is not the same thing as an internal ICT risk register, and several vendors publish the latter while not claiming the former.

Next step

See the five duties in one platform.

A 20-minute demo, no consultant required.

Book a demo

Related