Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What does a DORA certification actually prove?
- Is a formal DORA certificate required by law?
- Who offers DORA certification and what are the price points?
- How does the certification map to DORA’s regulatory pillars?
- When should an individual pursue a DORA certification?
- How to obtain a DORA certification step by step
- What about organisational DORA attestation?
- What are the penalties for not meeting DORA obligations?
- How does Decloak help you prepare for DORA certification?
- Where to learn more
Key takeaways
- DORA certification is a private credential, not a legal mandate.
- It satisfies the training - record requirement of Article 13(6) of the EU DORA regulation.
- Major providers include DORA Academy, PECB, TRECCERT, ICTTF/ICA and Advisera.
- Courses range from free Foundations to €799 + VAT for Lead Manager programmes.
- Certificates contain a unique ID and QR - code that link to a public verification page.
What does a DORA certification actually prove?
A DORA certification proves you have completed a DORA - focused training programme and passed a final exam, demonstrating competence with the regulation’s five pillars. It is issued by private training organisations, not by the EU, and is recognised by industry as evidence of individual readiness for DORA - related roles.
The credential typically includes:
- Self - paced video lessons (8 - 30 hours).
- Interactive knowledge checks.
- A timed, scenario - based multiple - choice exam.
- A PDF certificate with a unique ID and QR - code that links to a public verification page.
Is a formal DORA certificate required by law?
No. The DORA regulation does not require a third - party attestation. Article 13(6) only obliges firms to record that each employee has completed the required training. A private certificate is the most convenient way to satisfy that record - keeping requirement.
Who offers DORA certification and what are the price points?
| Provider | Typical programmes | Free foundation? | Price range (2024 - 2025) |
|---|---|---|---|
| DORA Academy (Cryptaguard SRL) | Foundations, 20 expert tracks, Masterclass | Yes | Free for Foundations; €49 - €249 per expert track; €499 for Masterclass |
| PECB | DORA Lead Manager (5 - day), DORA Lead Implementer (30 h) | No | €799 + VAT for Lead Manager |
| TRECCERT | DORA Essentials, Practitioner, for Executives | Yes | €49 - €249 per track |
| ICTTF / ICA | DORA Certified Compliance Specialist (DCCS) | No | €299 (exam fee included) |
| Advisera | Foundations (free), Internal Auditor, Lead Implementer | Yes | Free Foundations; €?? for paid tracks (typically €200 - €400) |
All prices are listed in euros and reflect publicly available information from the providers.
How does the certification map to DORA’s regulatory pillars?
Each programme cites the specific DORA articles and the Regulatory Technical Standards (RTS) or Implementing Technical Standards (ITS) that auditors will check. For example:
- ICT - risk management - Articles 5 - 16
- Incident reporting - Articles 17 - 23
- Resilience testing - Articles 24 - 27
- Third - party risk - Articles 28 - 44
- Information sharing - Article 45
The mapping is included in the course syllabus and appears on the verification page, making it easy for auditors to confirm relevance.
When should an individual pursue a DORA certification?
- Career development - Add the badge to LinkedIn to signal readiness for roles such as ICT Risk Officer or Compliance Officer.
- Employer evidence - HR can use certificates to demonstrate compliance with the mandatory training record requirement.
- Consultancy or audit work - Credentials show subject - matter expertise when advising clients on DORA implementation.
How to obtain a DORA certification step by step
- Choose a provider that matches your role and budget.
- Enroll in the free Foundations course to get a baseline understanding (optional but recommended).
- Complete the self - paced video lessons and knowledge - check activities.
- Schedule and take the final exam; ensure you meet the passing score (usually 80 %).
- Download the PDF certificate and store the unique ID for internal records.
- Verify the certificate on the provider’s public verification page; share the QR - code with auditors or recruiters.
What about organisational DORA attestation?
Some consultancies offer a voluntary third - party attestation that an organisation meets DORA obligations. This attestation is a report rather than a formal certificate and can reduce supervisory scrutiny, but it is not required by law.
What are the penalties for not meeting DORA obligations?
Non - compliance can lead to fines of up to 2 % of total annual worldwide turnover for financial entities, and up to 1 % of average daily worldwide turnover per day for critical third - party providers. Additional remedial orders and personal liability for management may also apply.
How does Decloak help you prepare for DORA certification?
Decloak’s free scan runs eight core layers, including static HTML analysis, JavaScript CVE scanning, and vibe - coded platform security. The vibe - coded layer can identify misconfigurations that are common failure points in DORA - related ICT - risk assessments, such as publicly readable databases or missing security headers. The scan’s AI - written executive summary highlights gaps that you can address before taking a DORA training programme.
Where to learn more
- DORA compliance checklist 2026
- DORA Academy programmes
- PECB DORA Lead Manager
- TRECCERT DORA tracks
- ICTTF DORA Certified Compliance Specialist
- Advisera DORA courses
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.