Skip to main content

DORA, as a reference process you can map against.

Regulation (EU) 2022/2554 turned into a documented target process across 13 modules and 24 grounded controls — from ICT governance and the 4h/24h-72h-1-month incident reporting to the register of information. DORA has applied since 17 January 2025; the gaps are due now, not someday.

24
grounded controls
13
process modules
2025
applicable · 17 Jan
Regulation (EU) 2022/2554 (DORA)
Applicable since
17 January 2025
Level 2 (RTS/ITS)
All core mandates final
Incident reporting
4h/24h · 72h · 1 month
Controls
24 (1:1 to articles)
Grounding
Article + source on every step
Map & Gap

From target process to a prioritised gap list.

01

Reference process (target state)

The blueprint lays out the documented target process across its modules — every step anchored to the article or clause it derives from.

02

Map your current state

Map your existing processes module by module against the reference — system of record, owner, last review.

03

See the gaps

Each module yields a gap status (absent · partial · met) with a severity, a concrete remediation action and a target date.

04

Evidence, not opinion

The deterministic scanner grades the controls; the specialist advisor assists with the mapping — grounded in the regulation, ready for the auditor.

Target process

13 modules, each control covered exactly once.

The reference process groups all 24 DORA controls into 13 modules — from scope classification to cyber threat information sharing.

Art. 1-4

Scope & proportionality

Map the entity to the 21 financial-entity categories, check exemptions and microenterprise status, document the proportionality calibration.

Art. 5

Governance & management body accountability

The board defines, approves and oversees ICT risk management, assigns a third-party oversight role and trains itself regularly.

Art. 6-7

ICT risk framework, strategy & systems

Documented framework per RTS 2024/1774, reviewed yearly, with a resilience strategy, segregated control functions and resilient ICT systems.

Art. 8

Identification & asset management

Classify ICT-supported functions, assets and dependencies; identify risk sources continuously; assess legacy systems yearly.

Art. 9

Protection & prevention

Security policies, least-privilege access with strong authentication, network segregation, encryption and patch policies.

Art. 10-11

Detection, response & recovery

Anomaly detection with multi-layered alert thresholds plus ICT continuity policy, yearly-tested plans and a crisis function.

Art. 12

Backup, restoration & redundancy

Backup policies with defined scope and frequency, physically and logically segregated backup systems, safe restoration.

Art. 13-14

Learning, evolving & crisis communication

Post-incident root-cause reviews, mandatory awareness training and crisis communication plans with a spokesperson.

Art. 16

Simplified framework (eligible entities)

Reduced obligation set for small non-interconnected or exempted institutions instead of Articles 5-15.

Art. 17-23

Incident management, classification & reporting

Manage and classify incidents per RTS 2024/1772; report major incidents in three stages — 4h/24h initial, 72h intermediate, 1-month final.

Art. 24-27

Resilience testing & TLPT

Risk-based testing programme with yearly tests of critical systems; designated entities run TLPT every 3 years per RTS 2025/1190.

Art. 28-30

ICT third-party risk, contracts & register

Third-party strategy, the mandatory register of information (ITS 2024/2956), concentration checks, contract clauses and subcontracting control.

Art. 45

Cyber threat information sharing

Voluntary threat-intelligence sharing with GDPR/competition safeguards and authority notification.

Accuracy first

A final rulebook — referenced act by act.

All core Level-2 acts are final and cited by their real number — from RTS 2024/1774 (risk management) to RTS 2025/1190 (TLPT) and the 2025/301-302 reporting package. What still moves are national procedural details such as the BaFin reporting guidance; those are marked as evolving. Every control and process step carries its real DORA article and source, and the legal text is never conflated with our process opinion.

Book a demo

Set up your DORA blueprint together.

30 minutes with our team: we walk the target process, map it against your current state and show the path to a prioritised gap list — no sales loop.