DORA
DORA ICT Risk & Third-Party Resilience Checklist
A DORA checklist for ICT risk management, incident reporting, resilience testing, and ICT third-party registers.
- Estimated time
- 6–18 Months
- Audience
- EU Financial Entities and Critical ICT Providers
- Last updated
Operational reference for DORA preparation. Competent financial authorities supervise; this is not a substitute for regulatory advice.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Scope & Governance
Phase 2: ICT Risk & Incidents
Phase 3: Testing & Third Parties
Phase 4: Oversight Readiness
FAQ
Does DORA apply only to banks?+–
It applies to a defined set of EU financial entities and, for some duties, to critical ICT third-party providers.
Is TLPT mandatory for everyone?+–
Threat-led penetration testing applies to entities identified under DORA’s testing rules, not every small firm.
Can ISO 22301 cover DORA?+–
It helps resilience evidence. DORA still has specific reporting, register, and oversight requirements.
Who supervises?+–
Financial competent authorities; critical ICT providers have an EU-level oversight regime.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer