DORA checklist
The obligations of the DORA regulation, article by article
The European regulation on digital operational resilience, turned into 209 control points to tick, article by article, so you can see where you stand.
ICT risk management (obligations 1 to 10)
ICT-related incidents (obligations 11 to 13)
Digital operational resilience testing (14 to 16)
ICT third-party risk (obligations 17 to 22)
Sharing of cyber threat information (obligation 23)
The simplified framework of Article 16, for the entities it covers
Based on Regulation (EU) 2022/2554, applicable since 17 January 2025. Incident classification thresholds, reporting deadlines and the format of the register of information sit in the technical standards: the checklist flags them without paraphrasing them.