Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- What is the DORA compliance checklist and why do I need it?
- How do I prove the scope and governance (Pillar 1 - ICT Governance & Risk - Management)?
- What technical artefacts demonstrate ICT risk - management (Pillar 1 - Operational Content)?
- How do I meet incident - management and reporting obligations (Pillar 2)?
- What testing activities satisfy Digital Operational Resilience Testing (Pillar 3)?
- How do I manage third - party ICT risk (Pillar 4)?
- What evidence is needed for information and intelligence sharing (Pillar 5)?
- How can Decloak help you verify DORA readiness?
- What are the next steps after completing the checklist?
Key takeaways
- Follow the eight - row tables below; each row lists the regulator requirement, why it matters, and the exact artifact you must keep.
- Use version - controlled documents, board minutes and timestamped logs as evidence; these survive an audit.
- Run the required vulnerability scans and penetration tests with a qualified provider and keep the reports in a secure repository.
- Map every third - party contract to the Register of Information (RoI) and maintain a critical - provider register for TLPT eligibility.
- Review the governance framework quarterly and update it after any major incident or supervisory instruction.
What is the DORA compliance checklist and why do I need it?
The checklist is a ready - to - use list of every technical and governance requirement from Regulation (EU) 2022/2554, organized by the five pillars of digital operational resilience. It tells you exactly what evidence supervisors will ask for, so you can prepare before an inspection.
How do I prove the scope and governance (Pillar 1 - ICT Governance & Risk - Management)?
- Create a signed scope - note that references Article 2 and lists the entity type, services and jurisdictions covered.
- Record board approval of the ICT - risk - management framework in the minutes, including the name of the accountable board member.
- Store a version - controlled framework document that shows policies, procedures, review dates and board sign - off.
- Add a risk - appetite statement and a risk - tolerance matrix to the enterprise risk - management policy, and keep the board approval record.
- Appoint a CISO or ICT - risk officer, then file an org - chart, job description and budget allocation that show reporting line to the board.
- Produce quarterly DORA - status reports and a full - year review package, all signed off by the board.
What technical artefacts demonstrate ICT risk - management (Pillar 1 - Operational Content)?
- Maintain an ICT - asset register (spreadsheet or CMDB) that lists hardware, software, cloud services, data - flows, criticality tags and business function links.
- Document the identification of Critical or Important Functions (CIFs) with a decision - record file signed by the responsible manager.
- Use a risk - assessment methodology that quantifies likelihood and impact; keep the risk - assessment reports, treatment plan and KPI/KRI dashboard.
- Implement encryption, MFA, patch - management, SIEM/NDR, anti - malware and access - control; retain configuration logs, policy docs and audit reports as proof.
- Keep a Business Continuity / Disaster Recovery (BC/DR) plan, test reports, sign - off minutes and defined RTO/RPO values.
- Update an ICT - risk register continuously; store it as a live SharePoint list or similar with change - log and owner fields.
- Conduct an annual review of the framework; file the review report, updated version and board approval.
How do I meet incident - management and reporting obligations (Pillar 2)?
- Deploy a 24×7 SIEM/EDR/NDR solution; archive dashboard screenshots and alert - log extracts as evidence of detection capability.
- Define a classification matrix that maps incidents to the thresholds in CDR 2024/1772; keep the matrix and training records.
- Follow the reporting timeline: initial notification within 4 hours, intermediate report within 72 hours, final report within one month. Preserve timestamped report packets, email logs and regulator submission receipts.
- Write incident - response playbooks that include roles, escalation paths and client - notification templates; store versioned playbooks and test - exercise minutes.
- After each incident, produce a root - cause analysis (RCA) report, a corrective - action tracker and board - review minutes.
- Link each incident record to the Register of Information (RoI) entry for the affected third - party service.
What testing activities satisfy Digital Operational Resilience Testing (Pillar 3)?
- Publish a risk - based testing programme that schedules vulnerability scans, penetration tests and scenario - based exercises for all critical assets.
- Perform annual unauthenticated vulnerability scanning and authenticated penetration testing; keep the scan reports, pen - test reports and remediation tickets.
- If you are a G - SII, O - SII or large payment/e - money firm, arrange a Threat - Led Penetration Test (TLPT) every three years using TIBER - EU or an equivalent framework; retain the scope approval, external tester report and remediation plan.
- Run business - continuity stress tests for each CIF; store test scripts, results and sign - off documents.
- Track remediation of high - severity findings in a ticketing system; export the tracker and audit - trail screenshots.
- Review the testing programme annually and obtain board sign - off; keep the review minutes and updated test - plan version.
How do I manage third - party ICT risk (Pillar 4)?
- Compile a Register of Information (RoI) that lists every ICT third - party contract, data - flow, criticality rating and exit - strategy clause.
- Conduct pre - contract due - diligence with a questionnaire, risk score and approval memo; archive these documents.
- Insert mandatory contractual clauses (security SLAs, right - to - audit, breach - notification < 24 h, data - location, exit - and - portability) and keep the signed annexes and a clause - mapping matrix.
- Perform ongoing monitoring with periodic security assessments, KPI dashboards and concentration - risk analysis; retain the monitoring reports and vendor scorecards.
- Identify critical providers whose failure would materially affect a CIF; document them in a critical - provider register with justification.
- Draft an exit - strategy and continuity plan for each critical provider; keep the plan and test - exercise evidence.
What evidence is needed for information and intelligence sharing (Pillar 5)?
- Join sector - wide ISACs or trusted - sharing platforms (e.g., FS - ISAC, ECSC CERT) and keep membership certificates.
- Sign formal sharing - arrangement contracts that define confidentiality, data - protection and usage rules; store the agreements and any data - processing addenda.
- Log internal dissemination of shared threat intel; retain the logs as proof of governed sharing.
How can Decloak help you verify DORA readiness?
- Decloak’s free scan runs eight core layers, including HTTP/TLS posture, static HTML analysis, rendered - page network behaviour, JavaScript CVE scanning, tag - manager intelligence, third - party domain mapping, vibe - coded platform security and an AI - written executive summary. The vibe - coded layer identifies common misconfigurations in platforms such as Supabase, Bubble and Next.js that often cause the exact data - exposure issues DORA regulators flag.
- The free scan delivers a graded, shareable report in about 15 seconds, giving you an instant view of publicly visible risks before you start the formal DORA evidence - gathering process.
- For deeper assurance, upgrade to a Starter or higher tier to add DNS record analysis, subdomain discovery and takeover detection (Layer 9), which helps you complete the third - party mapping required by the Register of Information.
What are the next steps after completing the checklist?
- Store every artifact in a version - controlled repository with read - only access for auditors.
- Conduct a gap analysis against the checklist; prioritize missing evidence that has a high supervisory impact.
- Schedule remediation for any identified gaps and track closure in a ticketing system.
- Run a Decloak scan on your public - facing assets to catch misconfigurations that may have been missed.
- Prepare a DORA - readiness package that includes the checklist tables, all evidence files and the latest Decloak report for quick supervisor reference.
This article is based on the most recent DORA guidance (Regulation (EU) 2022/2554) and publicly available compliance checklists as of 2026.
Related guides
What is NIST in cybersecurity and why should you care?
NIST is the U.S. agency that creates the Cybersecurity Framework and a suite of standards like SP 800 - 53 that guide risk management for both government and private organizations.
Which NIST Cybersecurity Standards Should My Organization Adopt in 2024 - 2025?
Learn the core NIST publications that form a practical, layered security program, how they map together, and concrete steps to start using them today.
Does the EU AI Act apply to U.S. companies?
Yes - the EU AI Act has extraterritorial reach and can bind U.S. AI providers, deployers, importers or distributors whenever their systems are placed on the EU market, used by an EU entity, or produce output that is used in the Union.