The situation
The register of information is still prepared in a spreadsheet
DORA requires financial entities to keep a register of information on their contractual arrangements with ICT third-party service providers, in a precise format, ready for submission to the competent authority. Most teams start in Excel: contradictory provider names, missing LEI codes, unchecked clauses, a file rejected on validation.
DORA Toolkit takes the regulatory template and its checks, imports your existing register and produces the export in the expected format. Governance, incidents, tests and contracts are managed in the same place.
The tool covers DORA and DORA only, for banks, insurers, fintechs, payment institutions and asset managers, and for consultants following several entities. The analysis remains your team’s; for the regulatory substance, our partners take over.
An imposed format
Fifteen tables defined by the European technical standards, from scope to nth-rank subcontractors.
A filing that gets rejected
A file in the expected format can still be refused on submission: missing LEI code, wrong classification, badly serialised EBA code. One inconsistency is enough.
Obligations to derive
Depending on whether you are a reporting entity or an ICT provider, every contract triggers its own obligations. Tracked by hand, some go unnoticed until the audit.
Use cases
The situations where DORA Toolkit proves its worth
Audit ahead
The supervisor asks for the ICT third-party register.
New CISO
No documented ICT framework on arrival.
Budget to defend
Justifying the ICT budget to management.
Incident to qualify
Knowing whether an outage is reportable, and when.
New entity
Bringing an acquisition into the DORA scope.
Register of information
The fifteen regulatory tables, fed by guided forms
- Tables B_01.01 to B_99.01 are filled in from dedicated forms: functions, third parties, contracts, assets. Every field carries its regulatory code.
- You start from your current register: direct import of a ZIP, CSV or Excel file in the EBA format.
- The export produces an XBRL-CSV package compliant with the EBA DORA taxonomy, validated at two levels: blocking on mandatory fields, warning on the rest. Nothing is submitted automatically. A .dora.json export serves as an open archive.
Data enriched on entry
INSEE SIRENE lookup
Legal name, SIREN, SIRET, legal form and registered address, pre-filled when you select the entity or provider.
LEI resolution via GLEIF
The LEI code expected in the register is looked up in the public GLEIF database. If it is not found, you enter it yourself. If it does not exist yet, you request one.
Public databases only
Data comes from INSEE, data.gouv and GLEIF. No personal or confidential data is needed.
Obligations
The applicable obligations, derived from your contracts
- The list of obligations is generated from the declared entities and contracts, each with its trigger: this contract, with that provider, for that critical function.
- The dashboard tracks 55 DORA articles with a status, evidence and an owner per article, and progress per pillar.
- Legal references display in detailed or simplified mode, depending on whether the reader is legal counsel or an operational lead.
Oversight
Incidents, resilience tests and a report for management
- Classification of major incidents (article 18) and calculation of notification deadlines: 4 hours, 72 hours, 30 days.
- Test plans for TLPT, penetration tests, vulnerability scans and continuity exercises (articles 24 to 27), findings ranked by severity.
- The DORA Digest produces a summary report, with the overall score and progress per pillar, ready to hand to management.
- An AI assistant trained on the regulation and the RTS clarifies a requirement or drafts a first version of a policy. It is available on a dedicated page or as a widget across the application, with its usage quota visible. The analysis remains that of the CISO, the DPO or legal counsel.
Access and plans
A 14-day trial, then the Standard plan
Trial
Free, 14 days
Complete register, dashboard of the 55 articles, XBRL and .dora.json exports, AI assistant, one legal entity.
Create an accountStandard
Pricing on request
Everything in the trial, email support within 48 hours, regulatory updates and the import of an existing register.
Get in touchAllow two hours for the first structuring of the register, with your list of ICT third-party providers and contracts at hand. At the end of the trial, the account stays available in read-only mode and your data remains exportable.
Before you start
Frequently asked questions
Is the XBRL export sent to the ACPR automatically?
No. DORA Toolkit generates the XBRL file in the expected format. You review it, then file it yourself through the official channel, the ACPR OneGate portal or the channel of your competent authority. The regulatory submission stays in your hands.
Will the XBRL file be accepted by the OneGate portal?
The validation chain has been strengthened: blocking checks on mandatory fields before export, and an export chain verified internally with a third-party validation tool. A first submission on the ACPR test environment is still recommended before filing in production.
Does the AI assistant replace a DORA consultant?
No. It helps you understand an article, structure an answer or draft a first version of a policy. The analysis remains that of a CISO, a DPO or legal counsel.
Where is the data hosted?
In France, at OVHcloud and 3DS OUTSCALE, in data centres certified ISO 27001 and ISO 27701 and SecNumCloud qualified. Data is encrypted at rest and in transit, and each organisation has its own partitioned space.
Can I take my data with me if I leave?
Yes. You export all of your data in the open .dora.json format and in XBRL, at any time.
What happens at the end of the 14-day trial?
The account switches to read-only. You keep access to your data and to the export, and you move to the Standard plan to resume editing.
The product is in beta. Is that a risk?
The beta label applies to the software. The DORA framework and the RTS it embeds are frozen and audited, and product changes do not touch your data. You can start keeping your register now.
Does DORA Toolkit cover NIS2, ISO 27001 or HDS?
No. DORA Toolkit covers DORA only. To manage several frameworks in one place, the Make IT Safe GRC platform is built for that.
The Make IT Safe suite