Skip to content
rPResiliencePilot

DORA readiness check

How DORA-ready are you?

Ten questions across governance, incidents, continuity, testing and ICT third-party risk. Answer honestly; you'll get a banded result on screen and a tailored report by email.

  1. 1. Do you have a documented ICT risk-management framework owned and approved by your management body?

    Art. 5–6
  2. 2. Do you maintain a complete inventory of ICT assets and their dependencies, including third-party services?

    Art. 8
  3. 3. Is there a defined ICT-related incident management process with consistent classification of incidents?

    Art. 17
  4. 4. Can you produce major-incident reports to regulatory deadlines (initial, intermediate, final)?

    Art. 19
  5. 5. Do you have a business continuity policy with recovery objectives (RTO/RPO) derived from a business impact analysis?

    Art. 11
  6. 6. Are backup and restoration procedures in place and tested?

    Art. 12
  7. 7. Do you run a digital operational resilience testing programme (e.g. vulnerability assessments, scenario tests)?

    Art. 24–25
  8. 8. Do you maintain a Register of Information on contractual arrangements with ICT third-party providers?

    Art. 28
  9. 9. Do your ICT third-party contracts contain the required provisions, including the enhanced set for critical/important functions?

    Art. 30
  10. 10. Have you identified your critical or important functions and assessed ICT concentration risk?

    Art. 6/28

This is an indicative self-assessment, not a formal gap analysis, audit, or legal/compliance advice.