A practical DORA compliance checklist turns a complex regulation into a manageable set of actions. With DORA in force since January 2025, financial entities and their suppliers need a clear, prioritised list of what to have in place. This guide gives you that checklist, pillar by pillar, plus the gaps organizations most often need to close.

For the full context, start with our complete DORA guide.
The DORA compliance checklist at a glance
At the highest level, DORA compliance means being able to evidence five things: a board-owned ICT risk-management framework, a working incident classification and reporting process, a resilience testing programme, controlled ICT third-party relationships, and clear governance and accountability. Everything below expands these into concrete, checkable items.
ICT risk management checklist
- Documented ICT risk-management framework approved by the management body.
- Asset inventory and risk assessment covering critical functions.
- Protection, detection, response, and recovery measures.
- Business continuity and disaster recovery plans, tested regularly.
Incident reporting checklist
- Incident classification criteria aligned to DORA thresholds.
- A detection-to-reporting workflow that meets regulatory timelines.
- Templates for initial, intermediate, and final incident reports.
- Post-incident review and lessons-learned records.
Testing and third-party checklist
- A digital operational resilience testing programme, with advanced threat-led testing where required.
- Remediation tracking for identified weaknesses.
- A complete register of all ICT third-party arrangements.
- Contracts containing DORA’s mandatory clauses (audit rights, service levels, exit strategy).
- Concentration-risk assessment and ongoing supplier monitoring.
The DORA deadline
DORA has applied since 17 January 2025. There was no phased grace period after that date — the obligations became enforceable at once. If your programme is not yet complete, treat it as an active remediation priority rather than future planning, and focus first on the areas supervisors examine earliest: the risk framework, incident reporting, and the third-party register.
Common gaps to close
The most frequent shortfalls are an incomplete third-party register, contracts missing DORA’s mandatory clauses, incident-reporting workflows that cannot meet the timelines, and a lack of documented board oversight. Addressing these four areas closes the majority of typical compliance gaps and demonstrates genuine, evidenced resilience.
Work through DORA with confidence.
Our DORA Toolkit gives you every policy, procedure, register, and template on this checklist — mapped to the regulation’s five pillars and editable in Word and Excel.
Frequently asked questions
What is on a DORA compliance checklist?
An ICT risk-management framework, business continuity plans, an incident classification and reporting process, a resilience testing programme, a complete ICT third-party register with compliant contracts, and documented board oversight.
What is the DORA deadline?
DORA has applied since 17 January 2025. Its obligations are already enforceable, so compliance is expected now.
What are the most common DORA compliance gaps?
An incomplete third-party register, contracts missing mandatory clauses, incident-reporting workflows that cannot meet timelines, and insufficient documented board oversight.