DORA RTS & ITS
OVERVIEW#
DORA (Regulation (EU) 2022/2554) sets high-level digital operational resilience requirements; the detail lives in the Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS). DORA has applied since 17 January 2025. This sheet maps the standards, deadlines, and the five pillars for implementation and audit work.
KEY FACTS#
# Regulation: (EU) 2022/2554 (DORA) # In force: 17 January 2025 (single application date for all RTS/ITS) # Supervisor (LU): CSSF (contact: ictrisksupervision@cssf.lu) # RTS = WHAT to do (substantive requirements) # ITS = HOW (templates, formats, procedures) # Both are directly-applicable Commission Regulations
FIVE PILLARS#
# 1. ICT risk management & governance (Art. 5-16) # 2. ICT-related incident management & reporting (Art. 17-23) # 3. Digital operational resilience testing (Art. 24-27, incl. TLPT) # 4. ICT third-party risk management (Art. 28-44) # 5. Information & intelligence sharing (Art. 45)
BATCH 1 STANDARDS (submitted Jan 2024)#
# RTS on ICT risk management framework + simplified framework (Art.15/16) # RTS on criteria for classification of ICT-related incidents (Art.18) # RTS on policy for ICT services supporting critical/important functions # provided by third parties (Art.28) # ITS on the templates for the Register of Information (Art.28)
BATCH 2 STANDARDS (submitted Jul 2024)#
# RTS/ITS on content, timing & templates for incident reporting (Art.20) # RTS on subcontracting of critical/important ICT services (Art.30) # RTS on threat-led penetration testing (TLPT) - (EU) 2025/1190 (Art.26) # RTS on harmonisation of oversight conditions (CTPP) # Guidelines on aggregated costs/losses from major incidents (JC/GL/2024/34) # Guidelines on ESA-competent authority supervisory cooperation
INCIDENT CLASSIFICATION (7 CRITERIA, Art.18 RTS)#
# 1. Clients / financial counterparties / transactions affected # 2. Reputational impact # 3. Duration & service downtime # 4. Geographical spread # 5. Data losses (availability, authenticity, integrity, confidentiality) # 6. Criticality of services affected # 7. Economic impact (absolute + relative) # -> Thresholds determine "major" vs non-major incident
INCIDENT REPORTING TIMELINE (major incident)#
# Initial notification: within 4 hours of classification as major, # and no later than 24h from detection # Intermediate report: within 72 hours of the initial notification # Final report: within 1 month # + voluntary notification of significant cyber threats # (LU submission: CSSF Circular 25/893 modalities - see CSSF-CIRCULARS)
REGISTER OF INFORMATION (RoI)#
# ITS defines a structured XBRL/XML template of all ICT third-party # contractual arrangements # Submitted annually (reference date + submission window set by ESAs; # first collection was 2025) # Common failure: 35-50% of contracts miss a mandatory field first cycle # Article 30 mandatory contractual clauses must be reflected
TLPT (THREAT-LED PEN TESTING, Art.26)#
# RTS (EU) 2025/1190; built on the TIBER-EU framework # Applies to entities identified by competent authorities (systemic) # Frequency: at least every 3 years # Covers critical/important functions on live production systems # See TIBER-EU.txt for phases, roles, and deliverables
CRITICAL ICT THIRD-PARTY (CTPP) OVERSIGHT#
# ESAs designate critical ICT third-party providers (e.g. major cloud) # subject to an EU oversight framework (Lead Overseer) # Subcontracting rules for critical/important ICT services phased in # from 22 July 2025
ISO/NIST RELATIONSHIP#
# ISO 27001 certification typically covers ~60-75% of the ICT risk # management RTS by design; the delta is DORA-specific: # - incident classification per RTS thresholds # - Register of Information format # - Article 30 third-party clauses # - board-level governance specifics # Supervisors accept ISO/NIST as design evidence but require # independent verification of the DORA delta
EXAMPLES#
# Gap-assess ISO 27001 ISMS against the ICT risk management RTS delta # Build an incident classification decision tree from the 7 criteria # Validate the RoI XBRL export against the ITS taxonomy before filing # Scope TLPT critical/important functions with the control team
NOTES#
- Single application date (17 Jan 2025) applies even to standards finalised later - no phased grace by standard - The "simplified" framework (Art.16) reduces requirements for small, low-risk entities but does NOT exempt incident reporting, RoI, or third-party risk management - Always verify a specific RTS/ITS number on EUR-Lex before citing in a client deliverable - numbering was assigned through 2024-2025 - LU specifics (submission channels, amended circulars) are in CSSF-CIRCULARS.txt; TLPT execution detail in TIBER-EU.txt - This sheet is a practitioner reference, not legal advice
DORA RTS & ITS CHEATSHEET ========================= Source: https://cheatsheet.johlem.net OVERVIEW -------- DORA (Regulation (EU) 2022/2554) sets high-level digital operational resilience requirements; the detail lives in the Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS). DORA has applied since 17 January 2025. This sheet maps the standards, deadlines, and the five pillars for implementation and audit work. KEY FACTS --------- # Regulation: (EU) 2022/2554 (DORA) # In force: 17 January 2025 (single application date for all RTS/ITS) # Supervisor (LU): CSSF (contact: ictrisksupervision@cssf.lu) # RTS = WHAT to do (substantive requirements) # ITS = HOW (templates, formats, procedures) # Both are directly-applicable Commission Regulations FIVE PILLARS ------------ # 1. ICT risk management & governance (Art. 5-16) # 2. ICT-related incident management & reporting (Art. 17-23) # 3. Digital operational resilience testing (Art. 24-27, incl. TLPT) # 4. ICT third-party risk management (Art. 28-44) # 5. Information & intelligence sharing (Art. 45) BATCH 1 STANDARDS (submitted Jan 2024) -------------------------------------- # RTS on ICT risk management framework + simplified framework (Art.15/16) # RTS on criteria for classification of ICT-related incidents (Art.18) # RTS on policy for ICT services supporting critical/important functions # provided by third parties (Art.28) # ITS on the templates for the Register of Information (Art.28) BATCH 2 STANDARDS (submitted Jul 2024) -------------------------------------- # RTS/ITS on content, timing & templates for incident reporting (Art.20) # RTS on subcontracting of critical/important ICT services (Art.30) # RTS on threat-led penetration testing (TLPT) - (EU) 2025/1190 (Art.26) # RTS on harmonisation of oversight conditions (CTPP) # Guidelines on aggregated costs/losses from major incidents (JC/GL/2024/34) # Guidelines on ESA-competent authority supervisory cooperation INCIDENT CLASSIFICATION (7 CRITERIA, Art.18 RTS) ------------------------------------------------ # 1. Clients / financial counterparties / transactions affected # 2. Reputational impact # 3. Duration & service downtime # 4. Geographical spread # 5. Data losses (availability, authenticity, integrity, confidentiality) # 6. Criticality of services affected # 7. Economic impact (absolute + relative) # -> Thresholds determine "major" vs non-major incident INCIDENT REPORTING TIMELINE (major incident) -------------------------------------------- # Initial notification: within 4 hours of classification as major, # and no later than 24h from detection # Intermediate report: within 72 hours of the initial notification # Final report: within 1 month # + voluntary notification of significant cyber threats # (LU submission: CSSF Circular 25/893 modalities - see CSSF-CIRCULARS) REGISTER OF INFORMATION (RoI) ----------------------------- # ITS defines a structured XBRL/XML template of all ICT third-party # contractual arrangements # Submitted annually (reference date + submission window set by ESAs; # first collection was 2025) # Common failure: 35-50% of contracts miss a mandatory field first cycle # Article 30 mandatory contractual clauses must be reflected TLPT (THREAT-LED PEN TESTING, Art.26) ------------------------------------- # RTS (EU) 2025/1190; built on the TIBER-EU framework # Applies to entities identified by competent authorities (systemic) # Frequency: at least every 3 years # Covers critical/important functions on live production systems # See TIBER-EU.txt for phases, roles, and deliverables CRITICAL ICT THIRD-PARTY (CTPP) OVERSIGHT ----------------------------------------- # ESAs designate critical ICT third-party providers (e.g. major cloud) # subject to an EU oversight framework (Lead Overseer) # Subcontracting rules for critical/important ICT services phased in # from 22 July 2025 ISO/NIST RELATIONSHIP --------------------- # ISO 27001 certification typically covers ~60-75% of the ICT risk # management RTS by design; the delta is DORA-specific: # - incident classification per RTS thresholds # - Register of Information format # - Article 30 third-party clauses # - board-level governance specifics # Supervisors accept ISO/NIST as design evidence but require # independent verification of the DORA delta EXAMPLES -------- # Gap-assess ISO 27001 ISMS against the ICT risk management RTS delta # Build an incident classification decision tree from the 7 criteria # Validate the RoI XBRL export against the ITS taxonomy before filing # Scope TLPT critical/important functions with the control team NOTES ----- - Single application date (17 Jan 2025) applies even to standards finalised later - no phased grace by standard - The "simplified" framework (Art.16) reduces requirements for small, low-risk entities but does NOT exempt incident reporting, RoI, or third-party risk management - Always verify a specific RTS/ITS number on EUR-Lex before citing in a client deliverable - numbering was assigned through 2024-2025 - LU specifics (submission channels, amended circulars) are in CSSF-CIRCULARS.txt; TLPT execution detail in TIBER-EU.txt - This sheet is a practitioner reference, not legal advice
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.