Skip to main content

Column 1: ICT Risk Management

Artt. 5-16 DORA - Non-delegable Governance: the board must directly approve and oversee the ICT resilience strategy (Art. 5 DORA).

DORA Art. 5: Management body members are personally responsible for ICT risk management. Full delegation to IT functions is not allowed.
Questions about Pillar 1: ICT Risk Management
Review

Il board/organo di gestione approva e supervisiona la strategia di resilienza ICT (art. 5)?

È documentata la classificazione degli asset ICT critici con RPO/RTO (art. 11)?

Le politiche di gestione del rischio ICT sono formalmente approvate e riviste almeno annualmente?

DORA FAQs

Does DORA apply to my company? (DORA DevOps clarification)

The EU Regulation 2022/2554 (DORA) applies to financial entities as per art. 2: banks, insurance companies, investment firms, payment institutions, electronic money institutions, pension funds, rating agencies, critical ICT third-party providers. DOES NOT apply to generic SMEs or the non-financial sector. NOTE: this tool measures compliance with DORA (EU Regulation), not the "DORA DevOps Research & Assessment metrics" (deployment frequency, lead time, etc.) - that is the /dev-tools/dora-metrics-calculator tool.

When did DORA come into effect and what sanctions does it provide?

DORA came into force on January 17, 2025 (Reg. EU 2022/2554, directly applicable in all EU states without national transposition). Fines vary by type of entity and violation: can reach up to 2% of annual turnover for financial entities (or fixed amount up to 10M€). Critical third-party ICT providers may be subject to direct supervision by ESAs (EBA, ESMA, EIOPA) with fines up to 1% daily turnover.

What are the 5 DORA pillars?

DORA organizes obligations into 5 areas: (1) ICT Risk Management (arts. 5-16): board cannot delegate responsibility; (2) Incident Classification and Notification (arts. 17-23): notify within 4h/72h/1 month; (3) Operational Resilience Testing/TLPT (arts. 24-27): annual mandatory tests, TLPT every 3 years for significant entities; (4) Third Party ICT Risk (arts. 28-44): supplier registry, SLA, exit strategy, CTPP oversight; (5) Information Sharing (arts. 45-56): participation in threat intelligence circles.

What is Pillar 1 DORA irreferrable governance?

Art. 5 DORA: Board members are personally responsible for the ICT resilience strategy. They must approve, oversee actively, and receive periodic reports on the ICT risk management framework. THEY cannot fully delegate this responsibility to the IT function or CISO. This is the main novelty compared to previous regulations: compliance is no longer just a technical issue but a governance responsibility.

What are the TLPT required by DORA?

TLPT (Threat-Led Penetration Testing, art. 26-27 DORA) are advanced penetration tests based on real threat intelligence, conducted by qualified external testers, at least every 3 years for significant financial entities. TLPT test the entire digital supply chain of the entity (including critical vendors' IT systems). The ECB's TIBER-EU framework is the standard methodological reference for TLPT in Italy and the EU.

How to manage third-party ICT risk according to DORA?

Art. 28-44 DORA require: updated register of all ICT supplier contracts (critical/non-critical); mandatory contractual clauses (art. 30) including SLAs, access rights and audit, security standards, exit plans; documented exit strategy for critical suppliers; prior notification to the competent authority for new agreements with "critical" suppliers (CTPP). Critical cloud providers (CTPP) are subject to direct ESA supervision.

How to use DORA Wizard

  1. Check if DORA applies to your organization

    DORA applies to financial entities (Art. 2 Reg. EU 2022/2554). Before starting, check if your organization falls under: banks, insurance companies, payment institutions, investment firms, etc.

  2. Rate Pillar 1: ICT Risk Management

    Answer the 3 questions on the ICT risk management framework and board approval. This pillar has non-delegable governance - it's the most critical for DORA compliance.

  3. Rate Pillars 2-5

    Complete the assessments for pillars 2 (incidents), 3 (TLPT tests), 4 (third-party vendors), and 5 (information exchange). Each pillar has 3 questions; partial answers (in progress) count as 50%.

  4. Analyze the report

    The report shows the overall score (average of 5 pillars × 20%), pillar details, and any governance flags. Scores <40% indicate critical gaps requiring immediate action.

  5. Download PDF report

    Request the full PDF report by email - includes gap analysis per pillar, prioritized recommendations and checklist for compliance with RTS/ITS issued by EBA, ESMA and EIOPA.

DORA: what to know in 2025

The Regulation (EU) 2022/2554 (DORA - Digital Operational Resilience Act) applies directly in all 27 EU member states from January 17, 2025, without the need for national transposition. Unlike NIS2, DORA is a regulation (not a directive) and applies exclusively to the financial sector.

Obliged entities (art. 2 DORA) include banks, credit institutions, payment institutions, electronic money institutions, investment firms, crypto asset service providers (CASP), insurance and reinsurance companies, occupational pension funds, credit rating agencies, alternative fund managers, and critical third-party information and communication technology providers (CTPP).

The most relevant novelty of DORA is direct board responsibility (art. 5): management body members are personally responsible for ICT risk management and must approve the operational digital resilience strategy. Full delegation to IT or the CISO is not allowed.

Operational resilience tests (Pillar 3) require mandatory threat-led penetration testing (TLPT) every 3 years for significant entities, using the ECB's TIBER-EU framework. Critical third-party ICT providers (CTPPs) are subject to direct supervision by European regulatory authorities (EBA, ESMA, EIOPA).

This wizard helps financial institutions quickly identify gaps against the 5 DORA pillars, with automatic scoring (20% per pillar) and governance flags for non-delegable criticalities. The PDF report includes prioritized recommendations based on RTS/ITS issued by EBA, ESMA, and EIOPA.

DORA Glossary

DORA (Reg. EU 2022/2554)
Digital Operational Resilience Act. Directly applicable EU Regulation from 17/01/2025. Mandatory for financial institutions (art. 2). Coordinates and harmonizes ICT security requirements in the EU financial sector. DO NOT confuse with "DORA DevOps Research & Assessment" metrics.
Red Teaming and Threat Led Pentesting
Advanced penetration test based on real threat intelligence (Art. 26-27 DORA). Conducted by qualified external teams every 3 years for significant entities. Reference methodology: TIBER-EU framework (ECB). Tests the entire digital supply chain including critical ICT providers.
CTPP (Critical Third Party Provider)
Critical EU financial sector ICT providers (Art. 28-44 DORA). Designated by the ESA Joint Committee (EBA, ESMA, EIOPA). Subject to direct European supervision with onsite inspection rights. Include major cloud providers.
EU Regulatory Bodies
Relevant European supervisory authorities for DORA: EBA (banking), ESMA (financial markets), EIOPA (insurance/pensions). Coordinate oversight of CTPP and issue technical RTS/ITS supporting DORA.
Regole Tecniche e Standard d'Impiego (RTS/ITS - Technical Use and Implementation Rules)
Regulatory and Implementing Technical Standards issued by EBA, ESMA, EIOPA for DORA implementation details. Covers: incident classification, TLPT procedures, minimum contractual clauses (Art. 30), ICT risk assessment framework.
Deployment Frequency
Score 0-100% calculated by this wizard as the average of the 5 pillars (20% each). Yes=100%, Partial=50%, No=0%. Not an official certificate - it's a guidance tool to identify priority gaps. Score <40% on any pillar indicates significant risk of non-compliance.