Skip to main content

DORA checklist

The obligations of the DORA regulation, article by article

The European regulation on digital operational resilience, turned into 209 control points to tick, article by article, so you can see where you stand.

ICT risk management (obligations 1 to 10)
ICT-related incidents (obligations 11 to 13)
Digital operational resilience testing (14 to 16)
ICT third-party risk (obligations 17 to 22)
Sharing of cyber threat information (obligation 23)
The simplified framework of Article 16, for the entities it covers

Based on Regulation (EU) 2022/2554, applicable since 17 January 2025. Incident classification thresholds, reporting deadlines and the format of the register of information sit in the technical standards: the checklist flags them without paraphrasing them.

The information collected via this form is processed by Make IT Safe to follow up on your enquiry. To learn about and exercise your rights, see our Terms of Use.