Back to Guides
Guide16 September 2026

What does DORA stand for and why does it matter?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is the Digital Operational Resilience Act (DORA)?
  3. What is DevOps Research and Assessment (DORA)?
  4. What is the San Francisco Declaration on Research Assessment (DORA)?
  5. Which DORA definition applies to me?
  6. How to avoid confusion when searching for DORA
  7. Further reading

Key takeaways

What is the Digital Operational Resilience Act (DORA)?

The Digital Operational Resilience Act is an EU regulation that sets a common framework for ICT risk management in the financial sector. It entered into force on 16 January 2023 and will be fully applicable from 17 January 2025. The act requires banks, insurers, investment firms and market infrastructures to design, test and maintain resilient digital services, so they can withstand, respond to and recover from severe digital disruptions.

How to comply with the EU DORA

  1. Map all critical ICT assets - create an inventory of systems, third - party providers and data flows.
  2. Implement a risk management process - assess threat likelihood, impact and mitigation controls quarterly.
  3. Run regular resilience tests - conduct penetration testing, tabletop exercises and disaster - recovery drills at least annually.
  4. Document and report - maintain a resilience plan and submit required reports to national supervisory authorities.

What is DevOps Research and Assessment (DORA)?

DevOps Research and Assessment is the research team now part of Google Cloud that introduced the DORA metrics used to measure software - delivery performance. The four original metrics are lead time for changes, deployment frequency, change - failure rate and time - to - restore service. In 2024 a fifth metric, deployment - rework rate, was added.

How to use DORA metrics in your team

MetricHow to calculateGood practice
Lead time for changesTime from code commit to production deploymentAim for under 1 day for high - performers
Deployment frequencyNumber of successful deployments per time periodMultiple deployments per day is typical for elite teams
Change - failure ratePercentage of deployments causing a failure in productionKeep below 15 %
Time - to - restore serviceMean time to recover from a failureTarget under 1 hour
Deployment - rework ratePercentage of deployments requiring rework after releaseStay under 10 %

Use continuous integration pipelines to collect these numbers automatically, then compare against the benchmarks published in the State of DevOps report.

What is the San Francisco Declaration on Research Assessment (DORA)?

The San Francisco Declaration on Research Assessment is a global initiative launched in 2012 that calls for better ways to evaluate research outputs. It discourages reliance on journal - impact - factor metrics and promotes assessment based on the content and impact of individual works.

Steps to adopt the research - assessment DORA in your institution

  1. Revise promotion guidelines - replace impact - factor requirements with criteria that value open data, reproducibility and societal relevance.
  2. Train evaluators - provide workshops on narrative CVs, altmetrics and peer - review quality.
  3. Track compliance - audit promotion cases annually to ensure DORA - aligned criteria are applied.

Which DORA definition applies to me?

How to avoid confusion when searching for DORA

  1. Add context keywords - use "EU DORA regulation", "DORA metrics" or "DORA research declaration" in your queries.
  2. Check the source - official EU documents, Google Cloud/DevOps blogs, or the sfdora.org website indicate which DORA is being discussed.
  3. Verify dates - the EU regulation references 2023 - 2025, the research declaration cites 2012, and the DevOps metrics are tied to annual State of DevOps reports.

Further reading

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary