DORA has applied since January 2025 and supervisors are now running assessments against it. The work splits into five jobs that arrive in a predictable order: decide whether you are in scope and how far you are from ready, stand up an ICT risk management framework the board can approve, build and file a register of information, put incident clocks and classification in place, and run a testing programme you can evidence. The pages below follow that order.
20 pages on DORA, in the order the work happens. Jump to the stage you are at, or read straight through.
Know whether DORA applies to you, how far from ready you are, and what closing the gap costs in money and calendar time.
Write the framework Article 6 requires, pick indicators the board can act on, and understand what a supervisor will ask for.
Build a vendor register that survives submission, and understand why registers come back rejected.
Classify an incident correctly and hit the reporting window without arguing about it at the time.
Plan the annual programme the board approves, and know whether you are in scope for threat-led penetration testing.
Know what an auditor asks for, and judge tools by whether they produce it.
These sit under another subject but bear directly on DORA.
The free compliance check runs the DORA gap assessment in about five minutes and gives you a scored report you can take to a board meeting.
14-day free trial · no credit card · unlimited users