Back to Guides
Guide16 September 2026

DORA compliance checklist: concrete steps to meet the EU regulation

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. What is the DORA compliance checklist and why do I need it?
  3. How do I prove the scope and governance (Pillar 1 - ICT Governance & Risk - Management)?
  4. What technical artefacts demonstrate ICT risk - management (Pillar 1 - Operational Content)?
  5. How do I meet incident - management and reporting obligations (Pillar 2)?
  6. What testing activities satisfy Digital Operational Resilience Testing (Pillar 3)?
  7. How do I manage third - party ICT risk (Pillar 4)?
  8. What evidence is needed for information and intelligence sharing (Pillar 5)?
  9. How can Decloak help you verify DORA readiness?
  10. What are the next steps after completing the checklist?

Key takeaways

What is the DORA compliance checklist and why do I need it?

The checklist is a ready - to - use list of every technical and governance requirement from Regulation (EU) 2022/2554, organized by the five pillars of digital operational resilience. It tells you exactly what evidence supervisors will ask for, so you can prepare before an inspection.

How do I prove the scope and governance (Pillar 1 - ICT Governance & Risk - Management)?

What technical artefacts demonstrate ICT risk - management (Pillar 1 - Operational Content)?

How do I meet incident - management and reporting obligations (Pillar 2)?

What testing activities satisfy Digital Operational Resilience Testing (Pillar 3)?

How do I manage third - party ICT risk (Pillar 4)?

What evidence is needed for information and intelligence sharing (Pillar 5)?

How can Decloak help you verify DORA readiness?

What are the next steps after completing the checklist?

  1. Store every artifact in a version - controlled repository with read - only access for auditors.
  2. Conduct a gap analysis against the checklist; prioritize missing evidence that has a high supervisory impact.
  3. Schedule remediation for any identified gaps and track closure in a ticketing system.
  4. Run a Decloak scan on your public - facing assets to catch misconfigurations that may have been missed.
  5. Prepare a DORA - readiness package that includes the checklist tables, all evidence files and the latest Decloak report for quick supervisor reference.

This article is based on the most recent DORA guidance (Regulation (EU) 2022/2554) and publicly available compliance checklists as of 2026.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary