All resources
Checklist10 min readCompliance leads, heads of ICT risk

DORA Readiness Checklist

A self-assessment you can run in an afternoon to see where your ICT third-party programme stands against DORA, and what to fix first.

How to use it

Score each statement as in place, partial or absent. Anything partial or absent on a critical or important function is your first tranche of work; everything else can follow the normal review cycle.

What good looks like

A ready programme is not one with perfect scores. It is one where the gaps are known, owned, dated and reported upward, and where the underlying records are accurate enough that the Register can be produced on demand.

Checklist

Work through it.

Print this, or use it as the acceptance criteria for your own programme.

Inventory and classification

  • Complete inventory of ICT providers and services
  • Criticality classified with documented rationale
  • Critical and important functions mapped to services
  • Data locations recorded per service

Assessments and evidence

  • Assessment cycle defined per criticality tier
  • No overdue assessments on critical providers
  • Evidence in date, in scope and centrally held
  • Automated expiry reminders running

Contracts

  • All arrangements reviewed against Article 30
  • Audit rights and exit strategies in place for critical services
  • Subcontracting notification obligations agreed
  • Gap remediation plan tied to renewal dates

Register and reporting

  • Register generated from source records, not maintained by hand
  • Validation runs continuously
  • Field-level lineage available
  • Board receives trend-based third-party risk reporting

See how this works in the product.

See how one platform connects your ICT providers, assessments, evidence, contracts, risks and DORA Register.