Self-survey

DORA readiness self-survey

Twelve checks aligned with the five DORA pillars: ICT risk management, incident reporting, resilience testing, third-party risk, and information sharing. Designed for financial entities scoped by DORA.

About 8 minutes

Where should we send the result?
1 ICT risk management Governance and risk framework for ICT.

Has the management body approved an ICT risk-management framework?

Have you defined risk tolerance for ICT disruption?

Are critical / important functions identified and mapped to underlying ICT assets?

2 ICT-related incident reporting Classification, notification and lessons learned.

Do you classify ICT incidents using DORA's criteria (clients impacted, duration, geographic spread)?

Can you produce an initial notification within 4 hours of classifying an incident as major?

Do you publish a post-incident review for major incidents within 1 month?

3 Digital operational resilience testing Vulnerability and threat-led testing programmes.

Do you run vulnerability assessments on critical ICT systems at least annually?

If you meet the TLPT (Threat-Led Penetration Testing) thresholds, are you ready for it?

Are resilience-testing results presented to the management body?

4 Third-party ICT risk Register, contracts, and concentration risk.

Do you maintain the Register of Information for all ICT third-party arrangements (DORA Art. 28)?

Are contracts with critical ICT providers reviewed for DORA-required clauses?

Do you have an exit strategy documented for each critical ICT provider?

We email the result to you. Nothing is shared without consent.