DORA readiness check
How DORA-ready are you?
Ten questions across governance, incidents, continuity, testing and ICT third-party risk. Answer honestly; you'll get a banded result on screen and a tailored report by email.
1. Do you have a documented ICT risk-management framework owned and approved by your management body?
Art. 5–62. Do you maintain a complete inventory of ICT assets and their dependencies, including third-party services?
Art. 83. Is there a defined ICT-related incident management process with consistent classification of incidents?
Art. 174. Can you produce major-incident reports to regulatory deadlines (initial, intermediate, final)?
Art. 195. Do you have a business continuity policy with recovery objectives (RTO/RPO) derived from a business impact analysis?
Art. 116. Are backup and restoration procedures in place and tested?
Art. 127. Do you run a digital operational resilience testing programme (e.g. vulnerability assessments, scenario tests)?
Art. 24–258. Do you maintain a Register of Information on contractual arrangements with ICT third-party providers?
Art. 289. Do your ICT third-party contracts contain the required provisions, including the enhanced set for critical/important functions?
Art. 3010. Have you identified your critical or important functions and assessed ICT concentration risk?
Art. 6/28
This is an indicative self-assessment, not a formal gap analysis, audit, or legal/compliance advice.