How to Use This Checklist
This 60-point checklist covers all five DORA pillars. Score each item: 0 (Not started), 1 (In progress), 2 (Implemented). A score below 80 indicates significant compliance gaps. Focus remediation on the lowest-scoring pillar first.
Pillar 1: ICT Risk Management (Articles 5-16)
Framework & Governance (12 items)
- ICT risk management framework is documented, approved by management body, and reviewed annually
- Management body has ultimate responsibility for ICT risk — formally assigned with board-level accountability
- ICT risk management function is independent from ICT operations (separation of duties)
- Digital operational resilience strategy is defined with clear objectives, risk appetite, and KRIs
- ICT asset inventory is complete and current — all hardware, software, network components, cloud services
- ICT systems and assets are classified by criticality and business function they support
- Business impact analysis (BIA) completed for all critical ICT services and functions
- Recovery time objectives (RTO) and recovery point objectives (RPO) defined for all critical systems
- ICT risk appetite is quantified and formally approved by management body
- Budget for ICT risk management and digital operational resilience is dedicated and adequate
- Staff training programme covers ICT risk awareness for all employees, with specialised training for ICT staff
- ICT risk management framework is proportionate to entity size, risk profile, and complexity
Pillar 1 Score: ___ / 24
Pillar 2: ICT Incident Management (Articles 17-23)
Detection, Classification & Reporting (12 items)
- ICT-related incident management process is documented with clear roles, escalation paths, and timelines
- Incident classification criteria align with DORA's materiality thresholds (clients affected, transactions impacted, duration, geographic spread, data losses, critical services affected)
- Major ICT incidents are reportable to competent authority — initial notification within 4 hours of classification
- Intermediate report submitted within 72 hours of initial notification
- Final report submitted within 1 month of the incident
- Incident detection capabilities cover all critical ICT systems with automated alerting
- Root cause analysis is performed for all major incidents with documented lessons learned
- Incident response team is defined with clear RACI and on-call rotation
- Communication plan covers internal stakeholders, competent authorities, and affected clients
- Incident log maintained with full timeline, impact assessment, and remediation actions
- Voluntary significant cyber threat reporting mechanism is established
- Post-incident reviews feed back into ICT risk management framework updates
Pillar 2 Score: ___ / 24
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Pillar 3: Digital Operational Resilience Testing (Articles 24-27)
Testing Programme (12 items)
- ICT testing programme is documented with scope, frequency, and methodology for all critical systems
- Vulnerability assessments performed at least annually on all critical ICT systems
- Network security assessments conducted regularly
- Open source software security analysis performed for all OSS components in critical systems
- Gap analyses against relevant standards and frameworks performed annually
- Physical security reviews of data centres and critical ICT infrastructure conducted
- Source code reviews performed where applicable (custom-developed critical applications)
- Scenario-based testing covers plausible but severe ICT disruption scenarios
- Compatibility testing performed for new systems and major changes
- Performance testing validates capacity under stress conditions
- End-to-end testing covers critical business processes from user to back-end
- Threat-led penetration testing (TLPT) performed at least every 3 years for significant entities (TIBER-EU or equivalent framework)
Pillar 3 Score: ___ / 24
Pillar 4: ICT Third-Party Risk Management (Articles 28-44)
Vendor Management (12 items)
- Register of all ICT third-party service providers maintained and current
- ICT third-party providers classified by criticality (supporting critical or important functions)
- Due diligence performed before engaging ICT third-party providers
- Contractual arrangements include all DORA-required clauses (SLAs, audit rights, exit strategies, data location, subcontracting approval, incident notification)
- Concentration risk assessed — no excessive reliance on single provider or few providers
- Exit strategies documented for all critical ICT service providers
- Data location and processing requirements specified in contracts (EU/EEA or approved jurisdictions)
- Right to audit ICT third-party providers is contractually guaranteed and exercised
- Sub-outsourcing arrangements are subject to prior approval and documented
- Incident notification requirements for ICT third-party providers are contractually defined
- Business continuity plans address third-party service disruption scenarios
- Annual review of ICT third-party risk exposure reported to management body
Pillar 4 Score: ___ / 24
Technical Troubleshooting
Diagnostics, networks, and customer-facing problem resolution. In collaboration with Starweaver.
Start on Coursera →Pillar 5: Information Sharing (Article 45)
Threat Intelligence (12 items)
- Participation in at least one cyber threat information sharing arrangement
- Information sharing agreements include safeguards for confidentiality and data protection
- Threat intelligence is consumed and acted upon (not just received)
- Indicators of compromise (IoCs) from sharing arrangements integrated into detection systems
- Internal process exists for evaluating relevance of shared threat intelligence
- Contributing threat intelligence back to sharing communities (not just consuming)
- Management body informed of significant threat intelligence findings
- Threat landscape assessment updated based on shared intelligence
- Cross-sector threat intelligence considered (not just financial services)
- Regulatory guidance on information sharing followed (ESMA/EBA/EIOPA publications)
- Staff trained on information sharing protocols and confidentiality requirements
- Effectiveness of threat intelligence sharing reviewed annually
Pillar 5 Score: ___ / 24
Scoring Guide
- 100-120: Fully compliant. Maintain and continuously improve.
- 80-99: Substantially compliant. Address remaining gaps as priority.
- 60-79: Partially compliant. Significant remediation needed — create a 90-day action plan.
- 40-59: Major gaps. Prioritise by pillar — start with Pillar 1 (framework) and Pillar 2 (incidents).
- 0-39: Not compliant. Requires immediate board-level attention and dedicated programme.
EU AI Act Compliance Checklist
40-point checklist covering risk classification, data governance, transparency, and human oversight. Based on the official regulation.
Get Free Checklist →Next Steps
This checklist gives you a snapshot. For a deeper assessment with specific remediation recommendations, gap analysis against the RTS/ITS requirements, and a prioritised implementation roadmap, our DORA compliance assessment covers all 5 pillars in detail.
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
