DORA compliance checklist: the key requirements financial entities need to address.
The Digital Operational Resilience Act establishes binding requirements for financial entities operating in the EU and for ICT service providers that support them. This checklist covers the four main pillars of DORA compliance and the practical requirements under each.
The four DORA compliance pillars.
1. ICT risk management framework.
| Requirement | Notes |
|---|---|
| ICT risk management framework documented | Must be comprehensive and regularly updated |
| ICT assets identified and classified | Including hardware, software, data and ICT third-party services |
| Protection and prevention measures in place | Access controls, encryption, network security |
| Detection capabilities established | Monitoring, anomaly detection, alert processes |
| Response and recovery plans tested | Business continuity and disaster recovery procedures |
2. ICT-related incident reporting.
| Requirement | Notes |
|---|---|
| Incident classification process defined | Criteria for determining major vs minor ICT incidents |
| Reporting timelines met | Initial notification, intermediate and final reports within DORA timeframes |
| Competent authority identified | Know which regulator receives reports for your entity type |
| Incident log maintained | All ICT incidents recorded with classification and resolution |
3. Digital operational resilience testing.
| Requirement | Notes |
|---|---|
| Annual testing programme in place | All ICT systems supporting critical functions tested at least annually |
| Vulnerability assessments conducted | Regular scanning and assessment of ICT systems |
| Penetration testing performed | Scenario-based testing of defences |
| Test results acted upon | Findings remediated and retested; evidence retained |
4. ICT third-party risk management.
| Requirement | Notes |
|---|---|
| Register of ICT third-party providers maintained | Including critical ICT third-party service providers (CTPPs) |
| Contractual arrangements reviewed | Contracts must include DORA-required provisions on security, audit rights, exit |
| Due diligence performed pre-contract | Risk assessment of new ICT providers before engagement |
| Ongoing monitoring in place | Regular review of CTPP performance and risk profile |
Who does DORA apply to?
DORA applies to a wide range of financial entities including banks, insurance firms, investment firms, payment institutions and crypto-asset service providers operating in the EU. It also applies to ICT third-party service providers that support these entities — which means technology companies servicing financial sector clients have their own DORA obligations.
When did DORA come into effect?
DORA became applicable from 17 January 2025. Financial entities and their ICT third-party providers are expected to demonstrate compliance with the full framework from that date.
What is the difference between DORA and existing frameworks like ISO 27001?
DORA is a sector-specific regulatory requirement for financial entities — it is not optional. ISO 27001 is a voluntary management system standard. Organisations that have implemented ISO 27001 will have addressed many of the DORA requirements but DORA adds specific obligations around incident reporting to regulators, resilience testing and third-party oversight that go beyond the ISO 27001 scope.
Understand your current DORA position before the next audit cycle.
YDC helps financial entities and ICT service providers assess their DORA readiness and build a practical compliance programme.