The DORA Regulation (EU 2022/2554) has applied to financial entities since January 17, 2025 — yet in 2026 we still meet organizations that “have DORA done” only in a presentation for the management board. The checklist below is the set of questions we ask in our first audit meeting. If you cannot answer any of them with evidence (a document, a register, a test result), that is a gap — regardless of what the presentation says.
1. ICT risk management (Art. 5–16)
- Has the management board formally approved the ICT risk management framework, and is this documented in a resolution or minutes?
- Is there an up-to-date map of ICT systems with assigned owners and criticality classification?
- Have business continuity plans been tested in the last 12 months — and is there a test report?
- Is the ICT risk management function independent of IT operations?
2. ICT incidents (Art. 17–23)
- Does the incident classification procedure identify a “major” incident according to the RTS thresholds (number of clients, duration, geographic spread, data loss)?
- Can the organization meet the reporting deadlines: initial notification within 4 hours of classification / 24 hours of detection, intermediate report within 72 hours, final report within 1 month?
- Who exactly — by name — submits the report to the supervisory authority at 3:00 a.m. on a Saturday?
3. Resilience testing (Art. 24–27)
- Is there an annual testing program: vulnerability scans, scenario-based tests, compatibility tests, penetration tests?
- Does the entity know whether it has been designated for TLPT (Threat-Led Penetration Testing) — and does it understand that TLPT is a test in the production environment under the TIBER-EU framework, not a regular pentest?
- Are test results reported to the management board together with a remediation plan and deadlines?
4. Third-party risk (Art. 28–30)
- Is the register of information on ICT contracts maintained in a format compliant with the ITS (ESAs template), and does it also cover providers' subcontractors?
- Do contracts with ICT providers include the mandatory Art. 30 clauses: audit rights, data location, service levels, exit plans?
- Has a concentration analysis been performed — what happens if a single provider supporting several critical functions stops operating?
5. ICT providers: DORA applies to you too
DORA formally applies to financial entities, but Art. 30 shifts its burden onto providers through contracts. In practice, a bank or leasing company will send you a questionnaire with dozens of questions about policies, testing, backup and subcontractors. Answering “we're working on it” can mean losing the contract. Provider checklist: a complete set of security policies, penetration test results no older than one year, a documented vulnerability management process, a business continuity plan with a recovery test, and a list of your own subcontractors with contracts.
The regulator and the financial client ask the same question in different words: “show us the evidence.” Organizations that collect evidence on an ongoing basis get through audits in weeks. Everyone else — in quarters.
Remote Admin Audit Team
Where to start if none of the above is in place
The order we recommend to clients: first the register of information on ICT and a contract review (this is what both the KNF (Polish Financial Supervision Authority) and clients check first), then an incident procedure with a real on-call rota, then the testing program. The formal risk management framework completes the picture — writing policies before the facts are in order produces documents that no one follows.
If you want to know exactly how much is missing, our DORA audit concludes with a maturity report and a prioritized remediation plan. We present the scope and a quote within 48 hours of our call.