Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DORA requirements across the five pillars and the documentation financial entities must keep

DORA Requirements: The 5 Pillars & What You Must Document

Understanding the DORA requirements is the first step to a compliant, resilient financial operation. The Digital Operational Resilience Act sets out obligations across five pillars, each with its own processes and documentation. This guide breaks down what DORA requires and exactly what you must be able to show a supervisor.

DORA requirements across the five pillars and the documentation financial entities must keep

For the wider context, see our complete DORA guide.

The five pillars behind the DORA requirements

DORA’s obligations are grouped into five pillars. Together they require you to manage ICT risk end to end: govern it at board level, detect and report incidents, test your resilience, control your technology suppliers, and share threat intelligence. Every pillar translates into concrete policies and records, so it helps to treat each as a workstream with its own owner and evidence.

Pillar 1: ICT risk management requirements

You must establish a comprehensive ICT risk-management framework, approved and overseen by your management body. It has to cover identification of assets and risks, protection and prevention measures, detection of anomalies, response and recovery plans, and continuous learning. Business continuity and disaster recovery plans sit here too. The board cannot delegate accountability — DORA makes senior management explicitly responsible.

Pillar 2: incident reporting requirements

DORA requires you to classify ICT-related incidents by severity and report major incidents to your competent authority within strict timelines, using standardised templates. You need a documented incident-management process that detects, logs, classifies, escalates, and reports — and captures lessons afterwards. Getting the classification thresholds and reporting workflow right in advance is essential, because the clock starts the moment a major incident is detected.

Pillar 3: resilience testing requirements

Entities must test their digital operational resilience regularly — from vulnerability assessments and scenario testing to, for the largest and most critical entities, advanced threat-led penetration testing (TLPT). Test results feed back into the risk framework, and identified weaknesses must be remediated on a defined timeline.

Pillar 4: third-party risk requirements

You must maintain a register of all ICT third-party arrangements, perform due diligence, assess concentration risk, and embed specific contractual clauses covering service levels, audit and access rights, sub-outsourcing, and exit strategies. Ongoing monitoring of providers is mandatory. This is one of the most documentation-heavy areas of DORA and a common focus of supervisory attention.

What you must document

Across the pillars, your DORA evidence file typically includes: the ICT risk-management framework and policies; business continuity and recovery plans; the incident classification and reporting procedure; the resilience testing programme and results; the ICT third-party register and compliant contracts; and board minutes showing oversight. If it is not documented, a supervisor will treat it as not done — which is why a ready-made template set is so valuable.

Every DORA requirement, documented.

Our DORA Toolkit covers all five pillars — ICT risk framework, incident reporting, testing plans, and the third-party register — mapped to the regulation and editable in Word and Excel.

Get the DORA Toolkit →

Frequently asked questions

What are the main DORA requirements?

DORA requires ICT risk management, incident classification and reporting, digital operational resilience testing, ICT third-party risk management, and information sharing — each supported by documented policies and records.

What must be documented for DORA?

Core evidence includes the ICT risk-management framework, business continuity plans, the incident-reporting procedure, resilience testing results, the ICT third-party register, compliant contracts, and board oversight records.

Who is responsible for DORA compliance?

The management body holds ultimate accountability. DORA explicitly makes senior management responsible for the ICT risk-management framework and cannot be fully delegated.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.