Skip to main content
TOOLS

DORA Readiness Check

Ten operating questions drawn from the regulation itself — answer honestly. Your score, risk tier and path-to-baseline appear as you go. Nothing is sent anywhere; the check runs entirely in your browser.

DORA applies to EU financial entities — banks, insurers, payment and e-money institutions, investment firms, crypto-asset service providers and more. Non-financial companies usually meet DORA as an ICT service provider to a financial entity.

0/10
  1. 1.Governance: does your management body define, approve and oversee the ICT risk-management framework — and maintain the knowledge and training to do so?

    Art. 5 — governance and organisation

  2. 2.Is the ICT risk-management framework documented, applied across the whole entity, and reviewed at least once a year?

    Art. 6 — ICT risk-management framework

  3. 3.Identification: are ICT-supported business functions, the assets and systems behind them, and their risks identified and kept current?

    Art. 8 — identification

  4. 4.Detection: are ICT anomalies detected early, with events logged and alert thresholds set?

    Art. 10 — detection

  5. 5.Continuity: are business-continuity and response-and-recovery plans in place and tested — including restoration of critical systems?

    Art. 11 — response and recovery

  6. 6.Backup: are backup policies and procedures in place, with restoration actually tested — not just backups taken?

    Art. 12 — backup, restoration and recovery procedures

  7. 7.Incidents: is there a documented incident-management process that classifies incidents against the major-incident criteria and meets the reporting clock — initial within 24 hours, intermediate within 72, final within one month?

    Arts. 17–19 — incident management, classification and reporting

  8. 8.Third parties: is there an ICT third-party risk strategy, and is a register of all ICT service arrangements maintained?

    Arts. 21, 28 — third-party principles and the register of information

  9. 9.Contracts: do ICT service contracts carry the key provisions — audit and access rights, service levels, secure termination and exit strategies?

    Art. 23 — key contractual provisions

  10. 10.Testing: is there a digital operational resilience testing programme — and, if you are designated significant, threat-led penetration testing (TLPT)?

    Arts. 24–27 — digital operational resilience testing

0%

DORA readiness

Answer to score

What the score means

80–100% · Low risk

Controls exist and can mostly be shown. Next step: continuous evidence — the register of information and incident reports should read from live state, not spreadsheets.

40–79% · Medium / High

The usual state: real work done, proof missing. Onboarding turns it into a running operating model in weeks.

0–39% · Critical

Start with the register of information and the reporting clock — the DORA framework page maps both to operating controls.

The DORA framework

Every score

Bring it to a demo — walked through against your actual obligations, not generic advice.

Book a demo

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

Frequently Asked Questions

Who has to comply with DORA?
EU financial entities — banks, insurers, payment and e-money institutions, investment firms, crypto-asset service providers and more. Non-financial companies usually encounter DORA as an ICT service provider to a financial entity, through the contract and register requirements.
What are the DORA incident-reporting deadlines?
For major ICT incidents: an initial report within hours of classification — in any case within 24 hours of becoming aware — an intermediate report within 72 hours or on request, and a final report within one month.
What is the register of information?
The DORA register of every contractual arrangement on ICT services the entity uses — maintained at entity level and reportable to supervisors. It is the backbone of DORA third-party oversight, and a gap the check scores under the third-parties question.
Is the score an official DORA assessment?
No. It is an indicative maturity score from ten questions drawn from the regulation — not an assessment of record. Supervisors judge compliance against the full regulation; the check tells you where the gaps are.