Skip to main content
← All posts·
Regulatory Compliance

DORA Compliance Checklist: 60-Point Guide for Financial Services [2026]

Complete DORA compliance checklist for financial institutions. 60 action items across ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. Score your readiness against all 5 DORA pillars.

Luca Berton14 min read

How to Use This Checklist

This 60-point checklist covers all five DORA pillars. Score each item: 0 (Not started), 1 (In progress), 2 (Implemented). A score below 80 indicates significant compliance gaps. Focus remediation on the lowest-scoring pillar first.

Pillar 1: ICT Risk Management (Articles 5-16)

Framework & Governance (12 items)

  1. ICT risk management framework is documented, approved by management body, and reviewed annually
  2. Management body has ultimate responsibility for ICT risk — formally assigned with board-level accountability
  3. ICT risk management function is independent from ICT operations (separation of duties)
  4. Digital operational resilience strategy is defined with clear objectives, risk appetite, and KRIs
  5. ICT asset inventory is complete and current — all hardware, software, network components, cloud services
  6. ICT systems and assets are classified by criticality and business function they support
  7. Business impact analysis (BIA) completed for all critical ICT services and functions
  8. Recovery time objectives (RTO) and recovery point objectives (RPO) defined for all critical systems
  9. ICT risk appetite is quantified and formally approved by management body
  10. Budget for ICT risk management and digital operational resilience is dedicated and adequate
  11. Staff training programme covers ICT risk awareness for all employees, with specialised training for ICT staff
  12. ICT risk management framework is proportionate to entity size, risk profile, and complexity

Pillar 1 Score: ___ / 24

Pillar 2: ICT Incident Management (Articles 17-23)

Detection, Classification & Reporting (12 items)

  1. ICT-related incident management process is documented with clear roles, escalation paths, and timelines
  2. Incident classification criteria align with DORA's materiality thresholds (clients affected, transactions impacted, duration, geographic spread, data losses, critical services affected)
  3. Major ICT incidents are reportable to competent authority — initial notification within 4 hours of classification
  4. Intermediate report submitted within 72 hours of initial notification
  5. Final report submitted within 1 month of the incident
  6. Incident detection capabilities cover all critical ICT systems with automated alerting
  7. Root cause analysis is performed for all major incidents with documented lessons learned
  8. Incident response team is defined with clear RACI and on-call rotation
  9. Communication plan covers internal stakeholders, competent authorities, and affected clients
  10. Incident log maintained with full timeline, impact assessment, and remediation actions
  11. Voluntary significant cyber threat reporting mechanism is established
  12. Post-incident reviews feed back into ICT risk management framework updates

Pillar 2 Score: ___ / 24

📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

Pillar 3: Digital Operational Resilience Testing (Articles 24-27)

Testing Programme (12 items)

  1. ICT testing programme is documented with scope, frequency, and methodology for all critical systems
  2. Vulnerability assessments performed at least annually on all critical ICT systems
  3. Network security assessments conducted regularly
  4. Open source software security analysis performed for all OSS components in critical systems
  5. Gap analyses against relevant standards and frameworks performed annually
  6. Physical security reviews of data centres and critical ICT infrastructure conducted
  7. Source code reviews performed where applicable (custom-developed critical applications)
  8. Scenario-based testing covers plausible but severe ICT disruption scenarios
  9. Compatibility testing performed for new systems and major changes
  10. Performance testing validates capacity under stress conditions
  11. End-to-end testing covers critical business processes from user to back-end
  12. Threat-led penetration testing (TLPT) performed at least every 3 years for significant entities (TIBER-EU or equivalent framework)

Pillar 3 Score: ___ / 24

Pillar 4: ICT Third-Party Risk Management (Articles 28-44)

Vendor Management (12 items)

  1. Register of all ICT third-party service providers maintained and current
  2. ICT third-party providers classified by criticality (supporting critical or important functions)
  3. Due diligence performed before engaging ICT third-party providers
  4. Contractual arrangements include all DORA-required clauses (SLAs, audit rights, exit strategies, data location, subcontracting approval, incident notification)
  5. Concentration risk assessed — no excessive reliance on single provider or few providers
  6. Exit strategies documented for all critical ICT service providers
  7. Data location and processing requirements specified in contracts (EU/EEA or approved jurisdictions)
  8. Right to audit ICT third-party providers is contractually guaranteed and exercised
  9. Sub-outsourcing arrangements are subject to prior approval and documented
  10. Incident notification requirements for ICT third-party providers are contractually defined
  11. Business continuity plans address third-party service disruption scenarios
  12. Annual review of ICT third-party risk exposure reported to management body

Pillar 4 Score: ___ / 24

🎓 Course with Starweaver

Technical Troubleshooting

Diagnostics, networks, and customer-facing problem resolution. In collaboration with Starweaver.

Start on Coursera →

Pillar 5: Information Sharing (Article 45)

Threat Intelligence (12 items)

  1. Participation in at least one cyber threat information sharing arrangement
  2. Information sharing agreements include safeguards for confidentiality and data protection
  3. Threat intelligence is consumed and acted upon (not just received)
  4. Indicators of compromise (IoCs) from sharing arrangements integrated into detection systems
  5. Internal process exists for evaluating relevance of shared threat intelligence
  6. Contributing threat intelligence back to sharing communities (not just consuming)
  7. Management body informed of significant threat intelligence findings
  8. Threat landscape assessment updated based on shared intelligence
  9. Cross-sector threat intelligence considered (not just financial services)
  10. Regulatory guidance on information sharing followed (ESMA/EBA/EIOPA publications)
  11. Staff trained on information sharing protocols and confidentiality requirements
  12. Effectiveness of threat intelligence sharing reviewed annually

Pillar 5 Score: ___ / 24

Scoring Guide

  • 100-120: Fully compliant. Maintain and continuously improve.
  • 80-99: Substantially compliant. Address remaining gaps as priority.
  • 60-79: Partially compliant. Significant remediation needed — create a 90-day action plan.
  • 40-59: Major gaps. Prioritise by pillar — start with Pillar 1 (framework) and Pillar 2 (incidents).
  • 0-39: Not compliant. Requires immediate board-level attention and dedicated programme.
📋 Free Resource

EU AI Act Compliance Checklist

40-point checklist covering risk classification, data governance, transparency, and human oversight. Based on the official regulation.

Get Free Checklist →

Next Steps

This checklist gives you a snapshot. For a deeper assessment with specific remediation recommendations, gap analysis against the RTS/ITS requirements, and a prioritised implementation roadmap, our DORA compliance assessment covers all 5 pillars in detail.

DORA
compliance checklist
financial services
ICT risk
resilience testing
regulatory compliance

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →