Free resource
For financial entities in scope of DORA (applied 17 January 2025): ICT risk, incident classification and reporting, the Register of Information, resilience testing and third-party risk - the evidence a supervisor asks for.
The actual structure of the file, straight from the template we use on live engagements.
Sheet: Start here
Read this tab first, then work through the checklist. Score honestly - a 'Partly' you can see is worth more than a 'Yes' you cannot evidence. This is a working tool, not a certificate: it shows where an assessor will push, before they do.
| Topic | Detail |
|---|---|
| What this is | A readiness check across DORA's five pillars for financial entities in scope (Regulation (EU) 2022/2554, applied 17 January 2025). It shows where an ISO 27001 ISMS gives you a head start, and where DORA goes further. |
| How to score | Yes = in place and you can show the evidence today. Partly = it exists but is incomplete, informal or unevidenced. No = not in place. Only a clear Yes counts when it is audited. |
| ISMS is a backbone, not a substitute | An ISO 27001 ISMS covers much of pillar 1 (ICT risk). DORA's incident-reporting timeline, Register of Information and third-party contract rules are additional legal duties an ISMS does not give you. |
| The #1 mistake | Treating DORA as an IT project. The management body is explicitly accountable, and the Register of Information plus contract requirements are legal obligations with hard deadlines. |
Sheet: DORA Readiness
Score each item. DORA is the legal obligation; an ISO 27001 ISMS is a useful backbone, not a substitute. The middle columns show what a pass looks like and the failure supervisors see most.
| Pillar | Check item | What good looks like | Most common failure (the red flag) | Status (Yes / Partly / No) | Owner | Evidence / gap |
|---|---|---|---|---|---|---|
| ICT risk management | A documented ICT risk-management framework is in place and maintained | A living framework mapped to your ICT assets, reviewed and version-controlled | A framework written once for the file and never revisited | - | - | - |
| ICT risk management | The management body approves the framework and can evidence oversight | Board minutes show the framework approved and ICT risk on the agenda | ICT risk never reaches the board - DORA makes it their responsibility | - | - | - |
| Incident management | A process classifies incidents against the CDR (EU) 2024/1772 criteria (major or not) | A written test applies the RTS criteria (clients affected, data losses, duration, geography) to each incident | 'Major' decided by gut feel, so the reporting clock starts late or never | - | - | - |
| Incident reporting | You can meet the CDR (EU) 2025/301 timings: initial within 4 hours of classifying an incident major (no later than 24 hours from awareness), intermediate within 72 hours, final within one month | You can produce the initial, intermediate and final reports on the RTS timeline from a single incident record | The reporting process is built after go-live; the initial report, due within 4 hours of classifying an incident major, is missed | - | - | - |
Preview only. The download is a fully editable .xlsx file.
Go deeper
See how this template fits the wider readiness work, and where we pick it up on a live engagement.
Explore the related serviceMore resources