DORA Engine
Applicability, proportionality and Article 5–30 self-assessment for Regulation (EU) 2022/2554, with the Level 2 RTS on ICT risk management (Delegated Regulation (EU) 2024/1774).
Applicability & proportionality
Answer the questions below to determine whether your entity falls within DORA, whether the simplified framework (Art. 16) applies, and which proportionality flags to consider.
Requirements self-assessment
Maturity 0–4 per article. Group A = DORA Level 1 (Arts. 5–30, 45); Group B = RTS on ICT Risk Management (Delegated Regulation (EU) 2024/1774).
Group A — DORA Level 1 articles
ICT risk management — /4
The management body of the financial entity bears the ultimate responsibility for managing ICT risk, approves and oversees the ICT risk management framework, and allocates appropriate budget. Members of the management body must keep their ICT-related knowledge up to date.
Financial entities maintain a sound, comprehensive and well-documented ICT risk management framework, reviewed at least annually and after major ICT-related incidents.
Use of up-to-date, resilient and reliable ICT systems that fit the activity profile and are subject to documented standards.
Identify, classify and document all ICT-supported business functions, roles, information assets and their interdependencies. Update the inventory at least annually and on every major change.
Continuous monitoring and control of ICT systems' security and functioning; implement policies for resilience, continuity and recovery; deploy security tools and segregation of duties.
Put in place mechanisms to promptly detect anomalous activities and ICT-related incidents, with multiple layers of control and clearly defined alert thresholds.
Maintain an ICT business continuity policy with response and recovery plans, including communication protocols and crisis management arrangements.
Define backup, restoration and recovery procedures appropriate to the criticality of information; periodically test backups against integrity and confidentiality risks.
Capabilities and staff to gather information on vulnerabilities and threats, post-incident reviews integrated into risk management cycle, lessons learned shared with stakeholders.
Crisis communication plans for disclosing ICT-related incidents to clients, counterparties and the public; designation of one or more spokespersons.
EBA, EIOPA and ESMA develop draft RTS to specify ICT risk management framework elements (now implemented via Delegated Reg (EU) 2024/1774).
A simplified ICT risk management framework applies to small and non-interconnected investment firms, exempt payment/credit/e-money institutions, and small IORPs. Lighter requirements proportionate to scale and risk profile.
ICT incident management & reporting — /4
Define, establish and implement an ICT-related incident management process to detect, manage and notify ICT-related incidents; record all incidents and material cyber threats.
Classify incidents and cyber threats per criteria including affected clients, duration, geographic spread, data losses, criticality of services and economic impact (detailed in Delegated Reg (EU) 2024/1772).
Report major ICT-related incidents to the competent authority via an initial notification, intermediate report and final report; voluntary notification of significant cyber threats.
Detailed reporting content, formats and timelines specified in the incident-reporting RTS/ITS package adopted by the ESAs.
ESAs together with ECB and ENISA assess feasibility of a single EU Hub for major ICT incident reporting (transitional study).
Competent authorities provide acknowledgement and may provide guidance based on incident reports.
Specific reporting requirements for payment-related operational or security incidents under PSD2 are integrated with DORA reporting.
Digital operational resilience testing — /4
Establish a sound and comprehensive digital operational resilience testing programme as part of the ICT risk management framework.
Baseline tests applied to all ICT systems supporting critical or important functions (vulnerability assessments, open source analyses, network security assessments, gap analyses, physical security reviews, etc.).
Significant financial entities perform threat-led penetration testing (TLPT) at least every 3 years on live production systems supporting critical or important functions.
TLPT testers (external or internal) must meet specified expertise, reputation and ethical standards; external testers used unless internal capability meets the criteria.
ICT third-party risk — /4
Manage ICT third-party risk as an integral component of the ICT risk management framework. Maintain a Register of Information of all contractual arrangements with ICT third-party providers, updated and reported to competent authorities (Art. 28(3)).
Assess ICT concentration risk before entering a contractual arrangement supporting critical or important functions; consider exit strategies and supplier substitutability.
Contractual arrangements with ICT third-party providers include mandatory provisions covering description of services, locations, data protection, accessibility, recovery, audit rights, termination rights, security incident notification, cooperation with competent authorities.
Information sharing arrangements — /4
Financial entities may exchange cyber threat information and intelligence in trusted communities; notify competent authorities of participation.
Group B — RTS on ICT Risk Management (Delegated Reg (EU) 2024/1774)
RTS articles — /4
Approve, document and review an ICT security policy aligned with the business strategy and ICT risk management framework.
Information classified by confidentiality, integrity, availability and authenticity; handling rules applied across the life cycle.
Maintain an up-to-date inventory of ICT assets and their interconnections; identify owners and criticality.
Documented procedures for operating ICT systems, including segregation of duties and change management.
Policies, procedures and controls for cryptographic protections and key life-cycle management.
Layered network controls, segmentation, secure protocols, monitoring and protection of network perimeters.
Controls for the planning, implementation and review of ICT projects and changes that affect critical or important functions.
Identify, assess, prioritise and remediate ICT vulnerabilities, including third-party software; track residual risks.
Controls protecting ICT premises against physical threats, environmental hazards and unauthorised access.
Manage identities, authentication, privileged access, joiners/movers/leavers and periodic reviews.
Strong authentication for users and systems, multi-factor where risk-appropriate; authentication-credential governance.
Generate, retain and protect logs of ICT-related events; monitor for anomalies and integrity loss.
Detective controls and alerting thresholds calibrated to risk; coordinated escalation procedures.
Define the ICT business continuity policy, governance and integration with the wider business continuity plan.
Document, test and update plans for response and recovery of ICT systems supporting critical or important functions.
Backups appropriate for criticality, including offline copies, integrity checks and periodic restoration testing.
Internal and external communication arrangements during ICT crises, including spokespersons and stakeholder lists.
Use threat intelligence to inform risk assessments, controls and testing.
Background screening, terms of employment, ICT-related awareness training, and termination procedures.
Regular, role-appropriate ICT security training for all staff; targeted training for ICT and management staff.
Annual review and reporting on the ICT risk management framework, including effectiveness and improvement actions.
Lighter requirements for entities eligible under DORA Art. 16: documented ICT security policy, asset inventory, basic controls, incident management, backup, and awareness.
Register of Information (RoI)
Spreadsheet-style editor producing the ESA-mandated Register of Information per Implementing Regulation (EU) 2024/2956. Loaded from the next tab.
TLPT applicability
Questionnaire implementing the threat-led penetration testing identification criteria (DORA Art. 26 + adopted TLPT RTS).
Incident classification helper
Implements the major-incident criteria of Delegated Regulation (EU) 2024/1772 plus the Art. 19/20 reporting-clock countdown.