From target process to a prioritised gap list.
Reference process (target state)
The blueprint lays out the documented target process across its modules — every step anchored to the article or clause it derives from.
Map your current state
Map your existing processes module by module against the reference — system of record, owner, last review.
See the gaps
Each module yields a gap status (absent · partial · met) with a severity, a concrete remediation action and a target date.
Evidence, not opinion
The deterministic scanner grades the controls; the specialist advisor assists with the mapping — grounded in the regulation, ready for the auditor.
13 modules, each control covered exactly once.
The reference process groups all 24 DORA controls into 13 modules — from scope classification to cyber threat information sharing.
Scope & proportionality
Map the entity to the 21 financial-entity categories, check exemptions and microenterprise status, document the proportionality calibration.
Governance & management body accountability
The board defines, approves and oversees ICT risk management, assigns a third-party oversight role and trains itself regularly.
ICT risk framework, strategy & systems
Documented framework per RTS 2024/1774, reviewed yearly, with a resilience strategy, segregated control functions and resilient ICT systems.
Identification & asset management
Classify ICT-supported functions, assets and dependencies; identify risk sources continuously; assess legacy systems yearly.
Protection & prevention
Security policies, least-privilege access with strong authentication, network segregation, encryption and patch policies.
Detection, response & recovery
Anomaly detection with multi-layered alert thresholds plus ICT continuity policy, yearly-tested plans and a crisis function.
Backup, restoration & redundancy
Backup policies with defined scope and frequency, physically and logically segregated backup systems, safe restoration.
Learning, evolving & crisis communication
Post-incident root-cause reviews, mandatory awareness training and crisis communication plans with a spokesperson.
Simplified framework (eligible entities)
Reduced obligation set for small non-interconnected or exempted institutions instead of Articles 5-15.
Incident management, classification & reporting
Manage and classify incidents per RTS 2024/1772; report major incidents in three stages — 4h/24h initial, 72h intermediate, 1-month final.
Resilience testing & TLPT
Risk-based testing programme with yearly tests of critical systems; designated entities run TLPT every 3 years per RTS 2025/1190.
ICT third-party risk, contracts & register
Third-party strategy, the mandatory register of information (ITS 2024/2956), concentration checks, contract clauses and subcontracting control.
Cyber threat information sharing
Voluntary threat-intelligence sharing with GDPR/competition safeguards and authority notification.
A final rulebook — referenced act by act.
All core Level-2 acts are final and cited by their real number — from RTS 2024/1774 (risk management) to RTS 2025/1190 (TLPT) and the 2025/301-302 reporting package. What still moves are national procedural details such as the BaFin reporting guidance; those are marked as evolving. Every control and process step carries its real DORA article and source, and the legal text is never conflated with our process opinion.
Set up your DORA blueprint together.
30 minutes with our team: we walk the target process, map it against your current state and show the path to a prioritised gap list — no sales loop.