DORAVendorReady

DORA diagnostic for ICT vendors

Select the coverage level for each requirement. The score highlights priorities before answering a financial entity.

Readiness checklist

The grid covers controls expected by financial clients: governance, security, continuity, subcontractors, data location, incident notification and evidence traceability.

GovernanceA vendor DORA owner is appointed and has a clear mandate.
GovernanceICT services provided to financial clients are mapped by criticality.
ContractArticle 30 obligations are covered in contract templates.
SecurityAccess controls, encryption, logging and access reviews are documented.
ResilienceRTO/RPO targets are defined, tested and linked to critical services.
IncidentsThe client incident notification process is documented with deadlines and contacts.
OutsourcingMaterial subcontractors are identified, monitored and notifiable to the client.
EvidencePolicies, test reports, attestations and continuity plans are ready to share.
DataProcessing locations and transfers outside the EEA are documented.
ExitAn exit assistance and reversibility plan is available.
Score: 0%