DORA for Irish Credit Unions

Organise DORA readiness work into a clear, repeatable rhythm.

Fit2Trade helps credit unions organise policies, recurring checks, vendor records, incident evidence and reporting activity as they prepare for DORA from January 2028.

Clear ownership Recurring records Structured oversight

DORA readiness workflow Fit2Trade support
01OwnResponsibility 02ScheduleFrequency 03CompleteActivity 04EvidenceRecords 05ReviewFollow-up
Examples of the work being organised
Policies ICT risk records Vendor oversight Incidents Testing records Reporting
GovernPolicies and responsibilities OrganiseRecurring checks and records OverseeVendor and asset information EvidenceIncidents, reviews and reporting
What Fit2Trade helps organise

Give the readiness programme a practical operating structure.

Fit2Trade supports the organisation and evidence of agreed DORA-related work. It does not provide cyber monitoring, conduct technical resilience testing or make the compliance decision.

01

Governance & policies

Keep agreed policies, responsibilities, review activity and supporting records in a structured programme.

02

ICT risk & control records

Assign agreed control checks, record completion and retain supporting evidence without implying Fit2Trade performs technical security monitoring.

03

Vendor oversight records

Collect consistent supplier information, record reviews and keep outstanding follow-up actions visible.

04

Incidents & continuity evidence

Maintain internal records, assigned actions and supporting evidence around incidents and continuity activity.

05

Testing records & reporting support

Record agreed testing or review outcomes and organise the information needed for internal oversight and reporting.

The operating rhythm

Own the work, schedule it, keep the evidence and review what needs attention.

Recurring activity can be organised monthly, quarterly or annually according to the agreed programme. Each item can have a clear owner, due point, supporting record and visible follow-up.

  1. 01
    OwnMake the responsible role clear.
  2. 02
    ScheduleSet the agreed recurring frequency.
  3. 03
    CompleteRecord that the activity took place.
  4. 04
    EvidenceAttach or retain the supporting record.
  5. 05
    ReviewSurface exceptions and follow-up.
Shared responsibility

Different roles contribute to the same readiness picture.

The credit union retains responsibility for its programme and compliance decisions. Fit2Trade helps the people involved contribute the records, evidence and oversight their role requires.

01

Board

Use internal reporting to review status, material exceptions, incidents, third-party oversight and planned improvement where these are included in the chosen scope.

02

Manager & compliance

Coordinate owners, policies, schedules, supporting documents, records and follow-up actions.

03

ICT / third-party provider

Supply the technical information or evidence requested by the credit union for the services and controls they are responsible for.

Transparent annual pricing

Core for the operating foundation. Pro for broader governance and oversight.

Both options are priced per credit union per year. Pro includes everything in Core and adds the wider toolkit shown below.

DORA Core
Operating foundation
€1,495 per credit union / year

A focused operating foundation for recurring DORA readiness work.

Includes:
  • Employee technology handbook
  • All-staff awareness module
  • Monthly, quarterly and annual checklists
  • Core ICT policy suite
  • Incident and vendor tools
Discuss DORA Core
DORA Pro
Broader governance & oversight
€2,495 per credit union / year

A broader governance, assessment and oversight toolkit.

Everything in Core, plus:
  • Expanded checklist and policy suite
  • Annual ICT self-assessment
  • Asset and vendor oversight tools
  • Board reporting pack
Discuss DORA Pro

Final scope, responsibilities and implementation are confirmed before agreement.

Scope note

Fit2Trade tools and workflows help organise internal records and readiness activity. They do not provide vulnerability scanning, endpoint monitoring, penetration testing, regulatory submission integrations or a compliance certification. The Pro annual ICT self-assessment is a Fit2Trade workflow and is not presented as a Central Bank regulatory submission.

Important scope

Software supports the programme. It does not make the compliance decision.

Fit2Trade helps organise, complete and evidence resilience work. It does not guarantee DORA compliance or replace competent regulatory, legal, cybersecurity or ICT advice.

See the DORA workflow in context

See how the readiness cycle works.

We’ll show the ownership model, recurring work, evidence structure and the difference between DORA Core and DORA Pro.