← All cheat sheets

DORA RTS & ITS

Plain-text reference · 5 KB. Read it, search it (Ctrl-F) or print it.

OVERVIEW#

DORA (Regulation (EU) 2022/2554) sets high-level digital operational
resilience requirements; the detail lives in the Regulatory Technical
Standards (RTS) and Implementing Technical Standards (ITS). DORA has
applied since 17 January 2025. This sheet maps the standards, deadlines,
and the five pillars for implementation and audit work.

KEY FACTS#

# Regulation:   (EU) 2022/2554 (DORA)
# In force:     17 January 2025 (single application date for all RTS/ITS)
# Supervisor (LU): CSSF  (contact: ictrisksupervision@cssf.lu)
# RTS = WHAT to do (substantive requirements)
# ITS = HOW (templates, formats, procedures)
# Both are directly-applicable Commission Regulations

FIVE PILLARS#

# 1. ICT risk management & governance (Art. 5-16)
# 2. ICT-related incident management & reporting (Art. 17-23)
# 3. Digital operational resilience testing (Art. 24-27, incl. TLPT)
# 4. ICT third-party risk management (Art. 28-44)
# 5. Information & intelligence sharing (Art. 45)

BATCH 1 STANDARDS (submitted Jan 2024)#

# RTS on ICT risk management framework + simplified framework (Art.15/16)
# RTS on criteria for classification of ICT-related incidents (Art.18)
# RTS on policy for ICT services supporting critical/important functions
#   provided by third parties (Art.28)
# ITS on the templates for the Register of Information (Art.28)

BATCH 2 STANDARDS (submitted Jul 2024)#

# RTS/ITS on content, timing & templates for incident reporting (Art.20)
# RTS on subcontracting of critical/important ICT services (Art.30)
# RTS on threat-led penetration testing (TLPT) - (EU) 2025/1190 (Art.26)
# RTS on harmonisation of oversight conditions (CTPP)
# Guidelines on aggregated costs/losses from major incidents (JC/GL/2024/34)
# Guidelines on ESA-competent authority supervisory cooperation

INCIDENT CLASSIFICATION (7 CRITERIA, Art.18 RTS)#

# 1. Clients / financial counterparties / transactions affected
# 2. Reputational impact
# 3. Duration & service downtime
# 4. Geographical spread
# 5. Data losses (availability, authenticity, integrity, confidentiality)
# 6. Criticality of services affected
# 7. Economic impact (absolute + relative)
# -> Thresholds determine "major" vs non-major incident

INCIDENT REPORTING TIMELINE (major incident)#

# Initial notification:   within 4 hours of classification as major,
#                         and no later than 24h from detection
# Intermediate report:    within 72 hours of the initial notification
# Final report:           within 1 month
# + voluntary notification of significant cyber threats
# (LU submission: CSSF Circular 25/893 modalities - see CSSF-CIRCULARS)

REGISTER OF INFORMATION (RoI)#

# ITS defines a structured XBRL/XML template of all ICT third-party
# contractual arrangements
# Submitted annually (reference date + submission window set by ESAs;
# first collection was 2025)
# Common failure: 35-50% of contracts miss a mandatory field first cycle
# Article 30 mandatory contractual clauses must be reflected

TLPT (THREAT-LED PEN TESTING, Art.26)#

# RTS (EU) 2025/1190; built on the TIBER-EU framework
# Applies to entities identified by competent authorities (systemic)
# Frequency: at least every 3 years
# Covers critical/important functions on live production systems
# See TIBER-EU.txt for phases, roles, and deliverables

CRITICAL ICT THIRD-PARTY (CTPP) OVERSIGHT#

# ESAs designate critical ICT third-party providers (e.g. major cloud)
# subject to an EU oversight framework (Lead Overseer)
# Subcontracting rules for critical/important ICT services phased in
# from 22 July 2025

ISO/NIST RELATIONSHIP#

# ISO 27001 certification typically covers ~60-75% of the ICT risk
# management RTS by design; the delta is DORA-specific:
#   - incident classification per RTS thresholds
#   - Register of Information format
#   - Article 30 third-party clauses
#   - board-level governance specifics
# Supervisors accept ISO/NIST as design evidence but require
# independent verification of the DORA delta

EXAMPLES#

# Gap-assess ISO 27001 ISMS against the ICT risk management RTS delta
# Build an incident classification decision tree from the 7 criteria
# Validate the RoI XBRL export against the ITS taxonomy before filing
# Scope TLPT critical/important functions with the control team

NOTES#

- Single application date (17 Jan 2025) applies even to standards
  finalised later - no phased grace by standard
- The "simplified" framework (Art.16) reduces requirements for small,
  low-risk entities but does NOT exempt incident reporting, RoI, or
  third-party risk management
- Always verify a specific RTS/ITS number on EUR-Lex before citing in
  a client deliverable - numbering was assigned through 2024-2025
- LU specifics (submission channels, amended circulars) are in
  CSSF-CIRCULARS.txt; TLPT execution detail in TIBER-EU.txt
- This sheet is a practitioner reference, not legal advice

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.