Skip to main content

DORA Toolkit

The DORA register of information, structured and exportable in XBRL

For CISOs, DPOs and compliance officers in financial entities: DORA Toolkit structures the register of information, produces the XBRL file expected by the competent authority and tracks the regulation’s obligations article by article.

Trial with no credit card and nothing to install. Free 20-question assessment, no account needed, for an indicative estimate. The application is in French.

The situation

The register of information is still prepared in a spreadsheet

DORA requires financial entities to keep a register of information on their contractual arrangements with ICT third-party service providers, in a precise format, ready for submission to the competent authority. Most teams start in Excel: contradictory provider names, missing LEI codes, unchecked clauses, a file rejected on validation.

DORA Toolkit takes the regulatory template and its checks, imports your existing register and produces the export in the expected format. Governance, incidents, tests and contracts are managed in the same place.

The tool covers DORA and DORA only, for banks, insurers, fintechs, payment institutions and asset managers, and for consultants following several entities. The analysis remains your team’s; for the regulatory substance, our partners take over.

An imposed format

Fifteen tables defined by the European technical standards, from scope to nth-rank subcontractors.

A filing that gets rejected

A file in the expected format can still be refused on submission: missing LEI code, wrong classification, badly serialised EBA code. One inconsistency is enough.

Obligations to derive

Depending on whether you are a reporting entity or an ICT provider, every contract triggers its own obligations. Tracked by hand, some go unnoticed until the audit.

Use cases

The situations where DORA Toolkit proves its worth

Audit ahead

The supervisor asks for the ICT third-party register.

New CISO

No documented ICT framework on arrival.

Budget to defend

Justifying the ICT budget to management.

Incident to qualify

Knowing whether an outage is reportable, and when.

New entity

Bringing an acquisition into the DORA scope.

Register of information

The fifteen regulatory tables, fed by guided forms

  • Tables B_01.01 to B_99.01 are filled in from dedicated forms: functions, third parties, contracts, assets. Every field carries its regulatory code.
  • You start from your current register: direct import of a ZIP, CSV or Excel file in the EBA format.
  • The export produces an XBRL-CSV package compliant with the EBA DORA taxonomy, validated at two levels: blocking on mandatory fields, warning on the rest. Nothing is submitted automatically. A .dora.json export serves as an open archive.

Data enriched on entry

INSEE SIRENE lookup

Legal name, SIREN, SIRET, legal form and registered address, pre-filled when you select the entity or provider.

LEI resolution via GLEIF

The LEI code expected in the register is looked up in the public GLEIF database. If it is not found, you enter it yourself. If it does not exist yet, you request one.

Public databases only

Data comes from INSEE, data.gouv and GLEIF. No personal or confidential data is needed.

Obligations

The applicable obligations, derived from your contracts

  • The list of obligations is generated from the declared entities and contracts, each with its trigger: this contract, with that provider, for that critical function.
  • The dashboard tracks 55 DORA articles with a status, evidence and an owner per article, and progress per pillar.
  • Legal references display in detailed or simplified mode, depending on whether the reader is legal counsel or an operational lead.

ICT third parties

Article 30 contracts and the subcontracting chain

Contracts module

Contractual compliance is calculated from the clauses present in each contract, with a distinction between an incomplete contract (missing data) and a non-compliant one (missing clause).

Exit strategies for critical providers are managed in the same place, and renewal deadlines come up as alerts.

Due diligence questionnaire

A questionnaire sent directly to your ICT third-party providers, so that they declare their own subcontractors.

The register’s subcontracting chain updates from their answers, with no re-entry on your side.

Oversight

Incidents, resilience tests and a report for management

  • Classification of major incidents (article 18) and calculation of notification deadlines: 4 hours, 72 hours, 30 days.
  • Test plans for TLPT, penetration tests, vulnerability scans and continuity exercises (articles 24 to 27), findings ranked by severity.
  • The DORA Digest produces a summary report, with the overall score and progress per pillar, ready to hand to management.
  • An AI assistant trained on the regulation and the RTS clarifies a requirement or drafts a first version of a policy. It is available on a dedicated page or as a widget across the application, with its usage quota visible. The analysis remains that of the CISO, the DPO or legal counsel.

Integrations

A public read-only API

Reference data, incidents, tests and compliance status are available through a REST API authenticated by key, to feed your GRC tools, your SIEM or your internal dashboards. Keys are issued on request after qualification, revocable at any time, with a limit of 100 requests per minute. OpenAPI documentation and versioned changelog inside the application, for signed-in accounts.

API documentation

Hosting

Hosted and operated in France

OVHcloud and 3DS OUTSCALE, data centres certified ISO 27001 and ISO 27701, SecNumCloud qualified. Data encrypted at rest and in transit, environments isolated per organisation, role-based access control, audited logging, 3-2-1 backups, tested continuity and recovery plans.

Access and plans

A 14-day trial, then the Standard plan

Trial

Free, 14 days

Complete register, dashboard of the 55 articles, XBRL and .dora.json exports, AI assistant, one legal entity.

Create an account

Standard

Pricing on request

Everything in the trial, email support within 48 hours, regulatory updates and the import of an existing register.

Get in touch

Allow two hours for the first structuring of the register, with your list of ICT third-party providers and contracts at hand. At the end of the trial, the account stays available in read-only mode and your data remains exportable.

Before you start

Frequently asked questions

Is the XBRL export sent to the ACPR automatically?

No. DORA Toolkit generates the XBRL file in the expected format. You review it, then file it yourself through the official channel, the ACPR OneGate portal or the channel of your competent authority. The regulatory submission stays in your hands.

Will the XBRL file be accepted by the OneGate portal?

The validation chain has been strengthened: blocking checks on mandatory fields before export, and an export chain verified internally with a third-party validation tool. A first submission on the ACPR test environment is still recommended before filing in production.

Does the AI assistant replace a DORA consultant?

No. It helps you understand an article, structure an answer or draft a first version of a policy. The analysis remains that of a CISO, a DPO or legal counsel.

Where is the data hosted?

In France, at OVHcloud and 3DS OUTSCALE, in data centres certified ISO 27001 and ISO 27701 and SecNumCloud qualified. Data is encrypted at rest and in transit, and each organisation has its own partitioned space.

Can I take my data with me if I leave?

Yes. You export all of your data in the open .dora.json format and in XBRL, at any time.

What happens at the end of the 14-day trial?

The account switches to read-only. You keep access to your data and to the export, and you move to the Standard plan to resume editing.

The product is in beta. Is that a risk?

The beta label applies to the software. The DORA framework and the RTS it embeds are frozen and audited, and product changes do not touch your data. You can start keeping your register now.

Does DORA Toolkit cover NIS2, ISO 27001 or HDS?

No. DORA Toolkit covers DORA only. To manage several frameworks in one place, the Make IT Safe GRC platform is built for that.

The Make IT Safe suite

The GRC platform and the dedicated solutions

Structure your DORA register of information

14-day free trial, no credit card. Your data remains exportable at any time.