Certified DORA Lead Manager - Digital Operational Resilience Act (Self-Study)

Is this a Certification Course? Yes, this is a certification course. Certification and examination fees are included in the price of the training course.

Delivery Model: Self Study

Exam Duration: 3 hours

Retake Exam: You can retake the exam once within one year

This is a self-study course. 

Looking for an instructor-led online course?    Click Here

Price: US$ 795 / CAD$ 1095

Buy Now

 

The PECB Certified DORA Lead Manager training course equips you with the necessary skills to lead and oversee the implementation of digital operational resilience strategies within financial entities to help them ensure compliance with European Union’s Digital Operational Resilience Act (DORA). 


Why should you attend?


As DORA will come into force on January 17, 2025, there’s never been a more crucial time to grasp its implications and requirements thoroughly. Attending the PECB Certified DORA Lead Manager training course offers a unique opportunity to engage with industry experts and peers, fostering valuable discussions and insights into best practices for digital operational resilience. Through interactive sessions and practical exercises, you will gain real-world perspectives on implementing effective strategies to mitigate ICT risks and enhance digital operational resilience in financial institutions. 


Additionally, attending this course demonstrates your commitment to professional development and positions you as a competent leader in the evolving landscape of digital operational resilience. Upon successfully completing the training course and exam, you can apply for the “PECB Certified DORA Lead Manager” credential. 


Who should attend?


This training course is intended for:


  • Financial institutions executives and decision-makers
  • Compliance officers and risk managers
  • IT professionals
  • Legal and regulatory affairs personnel
  • Consultants and advisors specializing in financial regulation and cybersecurity

Learning objectives


After completing this training course, you will be able to:


  • Understand the regulatory landscape and compliance requirements outlined in DORA, focusing on key pillars such as ICT risk management, ICT-related incident management and reporting, digital operational resilience testing, and ICT third-party risk management
  • Implement effective strategies and measures to enhance digital operational resilience and mitigate ICT risks within financial institutions, aligning with DORA requirements and industry best practices
  • Identify, analyze, evaluate, and treat ICT risks relevant to the financial entities 
  • Develop and maintain robust ICT risk management frameworks, incident response plans, business continuity and disaster recovery plans
  • Foster collaboration and communication with key stakeholders to ensure successful implementation and ongoing compliance with DORA
  • Utilize industry-standard tools and methodologies for monitoring, assessing, and managing ICT risks and vulnerabilities, enhancing the overall security posture of financial institutions

Educational approach


  • The training course incorporates interactive elements, such as essay-type exercises and multiple-choice quizzes, some of which are scenario-based. 
  • Participants are strongly encouraged to communicate and engage in discussions.
  • The quizzes are designed in a manner that closely resembles the format of the certification exam.

Prerequisites 


The main requirement for participating in this training course is having a fundamental understanding of information security and cybersecurity concepts, and familiarity with ICT risk management principles. 




Course Content


Day 1:  Introduction to the concepts and requirements of DORA


Day 2: ICT-related risk and incident management


Day 3: ICT third-party risk management and information sharing


Day 4: Review and continual improvement


Day 5: Certification exam


Examination


The “PECB Certified DORA Lead Manager” exam meets the PECB Examination and Certification Program (ECP) requirements, and it covers the following competency domains:


Domain 1: Fundamental concepts of ICT risk management and digital operational resilience  


Domain 2: Preparing and planning for DORA project implementation 


Domain 3: ICT risk and ICT-related incident management 


Domain 4: Digital operational resilience testing and ICT third-party risk management 


Domain 5: Review and continual improvement


Certification

After successfully passing the exam, you can apply for one of the credentials shown below. You will receive the certificate once you comply with all the requirements related to the selected credential.


The ICT risk management activities should follow best practices and include the following:


  • Drafting a DORA implementation business case
  • Managing a DORA implementation project
  • Implementing an ICT risk management framework
  • Managing documented information
  • Implementing corrective actions
  • Monitoring and improving the performance of the ICT risk management framework

General Information

  • Certification and examination fees are included in the price of the training course
  • Participants will receive the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes. 
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • If candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

 


Price: US$ 795 / CAD$ 1095

Download the Brochure
Buy Now

Our latest blog posts

alt=
September 2, 2026
In this video, we walk through a practical beginner roadmap for getting into AI GRC in 2026: what AI GRC means, why it matters, and what beginners should learn.
alt=
September 2, 2026
In this video, we look at some of the biggest mistakes organizations are making with ISO/IEC 42001 in 2026.
alt=
September 2, 2026
This free downloadable checklist will help you assess your organisation's position and readiness to begin the formal implementation of an AIMS.
alt=
September 1, 2026
If your organisation only uses third-party AI models, are you still responsible for the governance and oversight of that tool? Safeshield breaks down the answer.
September 1, 2026
A large part of AI governance involves systems the organisation didn’t build. Businesses increasingly rely on AI provided through external software, which creates a different governance challenge from working with technology developed entirely in-house. The organisation may have limited visibility into the underlying model, and some information may simply be unavailable. That doesn’t make effective governance impossible. It changes what the organisation can control and, as a result, the questions an AI GRC professional needs to ask. Understanding that distinction is useful for anyone learning how AI governance works in practice.
alt=
August 17, 2026
What is an impact assessment, what does it cover, and how does it help with ISO/IEC 42001? The Safeshield team answers all these questions. Includes downloadable checklist
alt=
August 6, 2026
If you’re looking at professional training in ISO/IEC 42001, Lead Implementer and Lead Auditor are two main options, but how do they compare, and which one is right for you?
August 4, 2026
If you’re researching AI GRC, ISO/IEC 42001 is one of the standards you’re going to need to understand. For individuals, it’s becoming an important reference point for AI GRC career development. For organisations, it offers a structured way to move from informal AI use or broad responsible AI principles toward a more formal AI management system. ISO/IEC 42001 is an international standard for Artificial Intelligence Management Systems. In simple terms, it gives organisations a framework for managing AI governance, risk, accountability and continual improvement. This guide looks at how an AI Management System works, where ISO/IEC 42001 fits into modern AI governance, and how the right training can prepare professionals to support its implementation or audit.
alt=
August 4, 2026
An evidence-led look at the growing demand for applied AI capability and the challenge candidates face when choosing between skills, frameworks and credentials.
alt=
June 23, 2026
AI is outgrowing traditional GRC frameworks. How can you keep up? Safeshield discusses the current industry and next steps for AI GRC.
Show More