DORA Readiness Check
Ten operating questions drawn from the regulation itself — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.
DORA applies to EU financial entities — banks, insurers, payment and e-money institutions, investment firms, crypto-asset service providers and more. Non-financial companies usually meet DORA as an ICT service provider to a financial entity.
1.Governance: does your management body define, approve and oversee the ICT risk-management framework — and maintain the knowledge and training to do so?
Art. 5 — governance and organisation
2.Is the ICT risk-management framework documented, applied across the whole entity, and reviewed at least once a year?
Art. 6 — ICT risk-management framework
3.Identification: are ICT-supported business functions, the assets and systems behind them, and their risks identified and kept current?
Art. 8 — identification
4.Detection: are ICT anomalies detected early, with events logged and alert thresholds set?
Art. 10 — detection
5.Continuity: are business-continuity and response-and-recovery plans in place and tested — including restoration of critical systems?
Art. 11 — response and recovery
6.Backup: are backup policies and procedures in place, with restoration actually tested — not just backups taken?
Art. 12 — backup, restoration and recovery procedures
7.Incidents: is there a documented incident-management process that classifies incidents against the major-incident criteria and meets the reporting clock — initial within 24 hours, intermediate within 72, final within one month?
Arts. 17–19 — incident management, classification and reporting
8.Third parties: is there an ICT third-party risk strategy, and is a register of all ICT service arrangements maintained?
Arts. 21, 28 — third-party principles and the register of information
9.Contracts: do ICT service contracts carry the key provisions — audit and access rights, service levels, secure termination and exit strategies?
Art. 23 — key contractual provisions
10.Testing: is there a digital operational resilience testing programme — and, if you are designated significant, threat-led penetration testing (TLPT)?
Arts. 24–27 — digital operational resilience testing
DORA readiness
Answer to scoreWhat the score means
80–100% · Low risk
Controls exist and can mostly be shown. Next step: continuous evidence — the register of information and incident reports should read from live state, not spreadsheets.
40–79% · Medium / High
The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.
0–39% · Critical
Start with the register of information and the reporting clock — the DORA framework page maps both to operating controls.
The DORA frameworkEvery score
Bring it to a demo — walked through against your actual obligations, not generic advice.
Book a demoTruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.