HomeStandards › DORA (mobile)

Regulation

DORA and mobile apps

What is DORA, and how does it touch mobile?

DORA (the Digital Operational Resilience Act) is an EU regulation that requires financial firms to manage their technology risk and prove they can keep running through disruption. It is broader than mobile, but it expects firms to test their systems and manage the vulnerabilities they find.

For a bank or fintech, the mobile app is part of that technology estate. Testing it and acting on the results is part of showing the controls work.

How Mobexa helps

Mobexa gives financial teams repeatable testing of mobile builds and signed evidence of the findings and how they were handled. That supports the testing and vulnerability-management expectations DORA places on the technology estate, with the app kept inside your own perimeter where required.

Common questions

Does DORA apply only to banks?
DORA applies to a wide range of EU financial entities, not only banks. Where a firm offers a mobile app, that app is part of the technology estate its resilience obligations cover.

Mobexa maps every finding on your Android and iOS builds to DORA (mobile) and the other standards an auditor recognises.

Start Free Trial