DORA

DORA compliance checklist: the key requirements financial entities need to address.

The Digital Operational Resilience Act establishes binding requirements for financial entities operating in the EU and for ICT service providers that support them. This checklist covers the four main pillars of DORA compliance and the practical requirements under each.

The four DORA compliance pillars.

ICT risk management
Incident reporting
Resilience testing
Third-party risk

1. ICT risk management framework.

Requirement Notes
ICT risk management framework documentedMust be comprehensive and regularly updated
ICT assets identified and classifiedIncluding hardware, software, data and ICT third-party services
Protection and prevention measures in placeAccess controls, encryption, network security
Detection capabilities establishedMonitoring, anomaly detection, alert processes
Response and recovery plans testedBusiness continuity and disaster recovery procedures

2. ICT-related incident reporting.

Requirement Notes
Incident classification process definedCriteria for determining major vs minor ICT incidents
Reporting timelines metInitial notification, intermediate and final reports within DORA timeframes
Competent authority identifiedKnow which regulator receives reports for your entity type
Incident log maintainedAll ICT incidents recorded with classification and resolution

3. Digital operational resilience testing.

Requirement Notes
Annual testing programme in placeAll ICT systems supporting critical functions tested at least annually
Vulnerability assessments conductedRegular scanning and assessment of ICT systems
Penetration testing performedScenario-based testing of defences
Test results acted uponFindings remediated and retested; evidence retained

4. ICT third-party risk management.

Requirement Notes
Register of ICT third-party providers maintainedIncluding critical ICT third-party service providers (CTPPs)
Contractual arrangements reviewedContracts must include DORA-required provisions on security, audit rights, exit
Due diligence performed pre-contractRisk assessment of new ICT providers before engagement
Ongoing monitoring in placeRegular review of CTPP performance and risk profile

Who does DORA apply to?

DORA applies to a wide range of financial entities including banks, insurance firms, investment firms, payment institutions and crypto-asset service providers operating in the EU. It also applies to ICT third-party service providers that support these entities — which means technology companies servicing financial sector clients have their own DORA obligations.

When did DORA come into effect?

DORA became applicable from 17 January 2025. Financial entities and their ICT third-party providers are expected to demonstrate compliance with the full framework from that date.

What is the difference between DORA and existing frameworks like ISO 27001?

DORA is a sector-specific regulatory requirement for financial entities — it is not optional. ISO 27001 is a voluntary management system standard. Organisations that have implemented ISO 27001 will have addressed many of the DORA requirements but DORA adds specific obligations around incident reporting to regulators, resilience testing and third-party oversight that go beyond the ISO 27001 scope.

DORA readiness support

Understand your current DORA position before the next audit cycle.

YDC helps financial entities and ICT service providers assess their DORA readiness and build a practical compliance programme.

Related pages.