Note what that answer is not. Regulation (EU) 2022/2554 entered into force on 16 January 2023 and has applied since 17 January 2025. There is no future deadline to plan towards. If you are reading this because you are not yet where you need to be, you are working against live supervisory expectations, and the sequencing advice below is written for that situation rather than for a comfortable runway.
- How long does DORA take from a standing start?
- What the other results get wrong about this question
- The four phases, and which ones overlap
- What actually sets your duration
- Why the Register of Information is the long pole
- Estimate your own timeline
- What you can compress, and what you cannot
- What to do first if you are already late
- Frequently asked questions
How long does DORA take from a standing start?
The duration depends almost entirely on where you begin. Three starting positions cover most organisations.
| Your starting position | Realistic elapsed time | What dominates the schedule |
|---|---|---|
| ISO 27001 certified, vendor register maintained, incidents tested | Around 4 to 6 months | Re-evidencing existing controls against DORA's articles, and building the register |
| Policies written, evidence collected ad hoc, no central vendor data | Around 6 to 9 months | Gathering contract data, and closing gaps the gap assessment surfaces |
| Spreadsheets, no formal framework, contract data scattered | Around 9 to 12 months | Scoping and classification first, then everything else in sequence |
These are elapsed calendar times for a team doing this alongside their normal work, which is the usual case. They are not effort estimates, and they assume the classification decisions do not get relitigated halfway through. They also assume you start now: nothing in the schedule below runs faster because a supervisor is asking.

What the other results get wrong about this question
Search this question and almost every result answers a different one. They give you the regulatory timeline: published in the Official Journal in December 2022, in force January 2023, applying from January 2025. That is accurate and it is useless to the person asking, who wants to know how long the work will take them, starting today.
The confusion matters because it hides the two things that actually control your schedule. First, several DORA work items run in parallel and a naive plan runs them in series, adding months for no reason. Second, one item has a hard external dependency on other companies responding to you, and no amount of internal resourcing shortens it. A page that recites the legislative history tells you neither.
The four phases, and which ones overlap

Phase 1, scoping and classification (weeks 1 to 4). Establish which legal entities are in scope, inventory business functions, and decide which are critical or important within the meaning of the definition in Article 3 of the Regulation. Short in calendar terms, heavy in senior attention. Everything downstream inherits these decisions, so revisiting them later restarts work rather than adjusting it.
Phase 2, gap assessment and the risk framework (weeks 3 to 10). Score yourself against the regulation and write or adapt the ICT risk management framework that Chapter II requires. This starts before scoping fully finishes, since the assessment itself sharpens the scope. Our guide to scoring DORA readiness covers the domains and weighting, and how to write a DORA ICT risk management framework covers the required contents.
Phase 3, register and contracts (weeks 6 to 20). Populate the Register of Information and remediate ICT contracts. This is the longest phase and it begins as soon as you have a function classification to hang providers off. It is treated separately below because it is where schedules actually slip.
Phase 4, testing and incident readiness (continuous from around week 8). Stand up the resilience testing programme and the ability to classify and report a major incident inside the deadlines. This never finishes, so it should start early rather than being queued behind the register.

What actually sets your duration

Your function classification. How many functions you classify as critical or important determines how many contracts need the stronger provisions, how much testing scope you carry and how closely providers get examined. Over-classifying inflates the schedule with work you did not owe.
Your ICT contract count. The register and the legal remediation both scale directly with this number, and it is usually larger than anyone expects. Counting it is the single most useful thing you can do in week one, because every subsequent estimate depends on it.
Supplier responsiveness. Contract amendments require the other party to agree. Large providers publish standard DORA addenda and move quickly. A small specialist vendor with one lawyer can take months. This line is outside your control, which is why it belongs at the front of the schedule rather than the end.
Why the Register of Information is the long pole
The register is the item that decides whether you finish in four months or nine. It is built from fifteen official templates set out in Implementing Regulation (EU) 2024/2956, and those templates reference one another: entities, branches, contracts, providers and functions all have to reconcile, and a reference pointing at a row that does not exist fails validation rather than producing a warning.
The work is mostly data archaeology. Legal entity identifiers, country codes, contract dates, function links and provider details have to be complete and internally consistent, and in most organisations that data lives across procurement spreadsheets, signed PDFs and individual memory. Gathering it is slow, it cannot be parallelised much beyond a certain point, and it cannot start meaningfully until the function classification exists.
Two further schedule risks sit here. Submissions are rejected on structural validation rules rather than on substance, and each rejection cycle costs days against a filing date, which we covered in why your Register of Information keeps getting rejected. And the register is maintained rather than finished, so the effort does not stop when you first file. The complete guide to the Register of Information walks all fifteen templates.

Estimate your own timeline
Answer these five questions and you will have a better estimate than any published average, because the published averages describe organisations that are not yours.
| Question | If the answer is favourable | If the answer is unfavourable |
|---|---|---|
| Do you hold a current ISO 27001 certification or equivalent? | Subtract roughly two months of framework and control work | Add the framework build to the critical path |
| Can you produce a complete list of ICT contracts this week? | Register work can start almost immediately | Add three to six weeks of data gathering before it can |
| Has anyone classified your critical or important functions? | Phase 1 is a review rather than a project | Add three to four weeks, with senior time |
| How many suppliers will need a contract amendment? | Under ten, mostly large providers: weeks | Dozens, including small vendors: plan for months |
| Is there a named owner with authority across IT, legal and risk? | The phases can overlap as designed | They will run in series, adding months |
Add the unfavourable answers to a four month baseline. That number will be closer to reality than a figure taken from an article about a bank that is not you.
What you can compress, and what you cannot
Compressible. The gap assessment, if you use a scored questionnaire rather than a bespoke consulting exercise. The framework document, if you adapt existing policy rather than starting from a blank page. Evidence collection, if the same evidence already answers ISO 27001 or NIS2 requirements and your controls are mapped across frameworks. Testing programme design, which is a planning exercise before it is an execution one.
Not compressible. Supplier negotiation, because it depends on other companies. Register data gathering below a floor, because someone has to find and verify the facts. Board approval cycles, which run at the cadence the board meets. Threat-led penetration testing where you are designated for it, which is a multi-month engagement by design, covered in DORA TLPT.
The practical consequence: start the incompressible items in week one, even before the work that logically precedes them is finished. Ask suppliers for amendments while you are still classifying functions. Begin the contract data pull before the gap assessment reports.
What to do first if you are already late
Supervisors distinguish between an organisation that has understood its obligations and is working through them on a credible plan, and one that has not started. Moving from the second group to the first is achievable in weeks, and it is worth far more than a partially finished project with no narrative attached.
- Classify your critical or important functions and write down the reasoning. A documented, defensible classification is the foundation of every other answer you will give.
- Produce the contract inventory. Even an incomplete one, dated, with the gaps marked.
- Run a scored gap assessment and keep the result. An honest low score with a dated plan against it is a stronger position than an optimistic one you cannot evidence.
- Get incident classification working. This is the obligation most likely to be tested by events rather than by a supervisor, and the deadlines are short. See DORA major incident classification.
- Start supplier conversations immediately. They run on someone else's clock.
Do this in Venvera
The schedule above compresses when the register, the gap assessment, the contract clause checks, the testing programme and incident classification live in one system that already knows the regulation. The Venvera DORA workspace ships all of them as a maintained control set, with completeness scoring on the register and xBRL-CSV export for filing. Evidence you attach once is reused by every other framework that asks for the same control, which is the largest single lever on the phases above. Pricing is published and flat, from EUR 399 per month, and the free readiness check will give you the scoping answer before you commit to anything.
Frequently asked questions
How long does DORA compliance take?
Roughly four to six months from a mature security programme, six to nine with policies but no central evidence, and nine to twelve from spreadsheets. The Register of Information is the item that sets the floor, because it depends on contract data most organisations have to assemble from scratch.
Is there still a DORA deadline to prepare for?
No. DORA entered into force on 16 January 2023 and has applied since 17 January 2025. Obligations are live and supervised, so any plan is now about closing a gap rather than meeting a future date.
Can DORA be done in three months?
Only from a strong starting position, with a named owner holding authority across IT, legal and risk, and a small contract estate. The binding constraints are supplier response times and register data gathering, and neither responds to additional internal resourcing.
What takes the longest in a DORA programme?
Assembling and reconciling the Register of Information, followed by contract remediation. Both depend on information held outside the compliance team, and contract remediation additionally depends on suppliers agreeing to amendments.
Does having ISO 27001 make DORA faster?
Materially, yes. A working management system, a vendor register and a tested incident process answer a large share of DORA's expectations, turning much of the programme into re-evidencing. The saving is only realised if your controls are mapped across frameworks rather than maintained separately for each one.
Do we have to finish everything before we can be considered compliant?
Obligations apply now, so there is no partial-credit status in the Regulation. In supervisory practice, a documented classification, an honest gap assessment and a dated remediation plan put you in a very different position from an organisation with none of those, which is why they are the first three things to produce.





