Ask a supervisor where a DORA conversation starts and the answer is the register of information. Not the ICT risk framework, not the incident policy — the list of every ICT arrangement, which ones support critical functions, and what the contracts say.
This assessment scores 78 questions across all five DORA pillars, from the ICT risk framework to the register of information, with the incident clocks and the Article 30 contract terms a supervisor will actually test. It is free, it saves as you go, and you can stop and come back to it.
What this is
DORA applied from 17 January 2025, so this is a compliance check rather than a readiness one. It scores all five pillars — ICT risk management, incident reporting, resilience testing, third-party risk and information sharing — along with the scope and proportionality questions that decide how much of the framework you actually owe. We have the background elsewhere — the five pillars, who is in scope, the checklist and how it overlaps with NIS2. Come here when you want a score.
What it covers
| Area | Questions |
|---|---|
| Scope and proportionality — entity type, microenterprise, simplified framework | 6 |
| Governance and organisation — Article 5 | 5 |
| ICT risk management framework — Articles 6–8 | 7 |
| Protection and prevention — Articles 7 and 9 | 7 |
| Detection — Article 10 | 3 |
| Response and recovery — Articles 11–12 | 6 |
| Learning and communication — Articles 13–14 | 4 |
| Incident management and classification — Articles 17–18 | 6 |
| Incident reporting — Articles 19 and 23 | 7 |
| Resilience testing — Articles 24–25 | 5 |
| Threat-led penetration testing — Articles 26–27 | 5 |
| Third-party risk: principles — Articles 28–29 | 8 |
| Third-party risk: contracts — Article 30 | 5 |
| Oversight and information sharing — Articles 31 and 45 | 4 |
The register of information is the tell
Supervisors have a cheap way to gauge an entity’s ICT risk maturity: ask for the register of information. It has to list every contractual arrangement for ICT services, identify which of them support critical or important functions, and be reported to the competent authority in a prescribed format. Entities that have one usually have the rest. Entities that do not usually cannot answer the concentration risk, sub-outsourcing or exit strategy questions either, because the register is where those answers live.
The other reliable gap is contractual. Article 30 sets minimum terms for every arrangement and a longer list for those supporting critical or important functions — audit and access rights, participation in threat-led penetration testing, exit and termination triggers. Those have to be in the contract, not in a policy that says contracts should have them.
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
DORA is explicitly proportionate: a microenterprise runs a simplified framework, and not every entity is subject to threat-led penetration testing. Mark what does not apply as not applicable, with your reasoning in the notes, rather than scoring it zero.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by pillar, a prioritised gap list, and the documents from the DORA Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 40 minutes. The third-party sections take longest, and are much faster if the register of information is already in front of you.
What to do with your score
Below 40% — build the register of information and identify your critical or important functions. Roughly a third of the framework becomes answerable once those exist.
40–70% — the common profile: the ICT risk framework is in place, incident classification and the reporting timetable are not. Work Articles 17 to 19 next, because those have clocks attached.
Above 70% — test the contracts. Pull three arrangements supporting critical or important functions and check them line by line against Article 30(3). That is the exercise a supervisor runs.
Frequently asked questions
Is this assessment really free?
Yes. All 78 questions, the pillar breakdown and your overall score cost nothing. The $39 report is optional.
We are an ICT provider, not a financial entity. Does DORA apply to us?
Indirectly, and heavily. Your financial-entity clients have to impose the Article 30 terms on you, and if you are designated critical you come under direct EU oversight. The scope section covers the distinction.
Does ISO 27001 or NIS2 work cover this?
Parts of the first pillar, yes. The register of information, the incident classification thresholds, the reporting deadlines and threat-led penetration testing have no equivalent in either. If you are in scope for both, the overlap guide sets out what carries over.
Is threat-led penetration testing mandatory?
Only for entities identified by their competent authority on the basis of risk profile and systemic importance, and at least every three years for those in scope. The assessment asks whether you have been identified before scoring the rest of that section.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.