Back to Guides
Guide16 September 2026

What are the core DORA compliance requirements and how to implement them?

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. What does the Digital Operational Resilience Act (DORA) require?
  2. How do I implement an ICT - risk - management framework?
  3. How should I classify and report major ICT - related incidents?
  4. How do I maintain a Register of Information (RoI) for ICT - third - party contracts?
  5. What is required for ICT - third - party risk management?
  6. How often must I conduct digital operational - resilience testing?
  7. What contractual clauses must I include with ICT - TPPs?
  8. Is participation in information - sharing arrangements mandatory?
  9. How does oversight of Critical ICT - Third - Party Providers (CTPPs) work?
  10. What governance and senior - management responsibilities are required?
  11. What are the penalties for non - compliance and the enforcement timeline?
  12. Quick starter checklist (derived from the sources)

Key takeaways


What does the Digital Operational Resilience Act (DORA) require?

DORA requires financial and crypto - asset firms to establish a comprehensive ICT - risk - management framework, report major incidents quickly, and manage third - party risk throughout the supply chain. The regulation is laid out in Regulation (EU) 2022/2554 and supporting RTS documents.

The core obligations are summarized in ten numbered requirements (see the checklist below). Each requirement maps to specific articles of the regulation and to publicly available guidance.

How do I implement an ICT - risk - management framework?

Start by drafting a policy that covers identification, protection, detection, response and recovery of ICT risks, then obtain board approval and embed the framework in the overall enterprise risk - management program.

Concrete steps

  1. Inventory all ICT assets and map them to critical business functions.
  2. Define risk - tolerance levels and control objectives.
  3. Assign a risk - owner for each asset.
  4. Document governance processes in a policy document.
  5. Hold a board meeting, record minutes approving the framework, and schedule quarterly reviews.

Classify an incident as “major” when it threatens the continuity of a critical function, causes significant data loss, or impacts a large number of users. Once classified, notify the competent authority within four hours, submit an interim report within 72 hours, and deliver a final root - cause analysis within one month.

Concrete steps

How do I maintain a Register of Information (RoI) for ICT - third - party contracts?

The RoI is a complete, up - to - date inventory of every ICT - third - party contract, including subcontractors, service criticality, concentration risk and identifiers. It must be ready for regulator request at any time.

Concrete steps

  1. Create a spreadsheet or database with columns for provider name, contract ID, service description, criticality rating, concentration risk, and ESG compliance.
  2. Populate the register during the onboarding of each new provider.
  3. Schedule a monthly review to reconcile the register with procurement records.
  4. Store the register in a read - only location accessible to compliance officers and auditors.

What is required for ICT - third - party risk management?

Before signing a contract, perform due - diligence covering business reputation, security standards, sub - contractor use, third - country risks, audit rights and ESG compliance (Article 6). After onboarding, continuously monitor performance and embed exit - strategy clauses (Article 30).

Concrete steps

How often must I conduct digital operational - resilience testing?

All entities must perform at least annual basic testing, such as vulnerability assessments and scenario - based exercises. Significant entities must add a Threat - Led Penetration Test (TLPT) every three years, involving critical ICT - TPPs.

Concrete steps

  1. Schedule a quarterly vulnerability scan using an approved tool.
  2. Design a scenario - based test that simulates a ransomware attack on a critical service.
  3. For TLPT, engage an external assessor, share the scope, and ensure participation of any designated critical ICT - TPPs.
  4. Document findings, remediate within defined timelines, and update the risk - management framework.

What contractual clauses must I include with ICT - TPPs?

Contracts must contain audit rights, a right to test, service - level targets, data - protection obligations, exit - strategy provisions, concentration - risk limits and ESG clauses as required by Article 30.

Concrete steps

Is participation in information - sharing arrangements mandatory?

Participation is optional but encouraged. Joining industry - wide cyber - threat - intelligence platforms helps meet the spirit of Articles 19 - 20 and demonstrates proactive resilience.

Concrete steps

How does oversight of Critical ICT - Third - Party Providers (CTPPs) work?

Regulators may designate certain providers as “critical” (Articles 31 - 44). Critical CTPPs face direct ESA oversight, fees and possible remediation orders.

Concrete steps

What governance and senior - management responsibilities are required?

The management body must approve the ICT - risk - management framework, allocate sufficient resources, and demonstrate knowledge of ICT risks (Articles 5 (2) and 13 (6)).

Concrete steps

What are the penalties for non - compliance and the enforcement timeline?

Full compliance is required by 17 January 2025. Penalties can reach up to 2 % of worldwide turnover for financial entities, €1 million for individuals, and up to €5 million or 1 % of daily turnover for critical ICT - TPPs.

Concrete steps


Quick starter checklist (derived from the sources)


For deeper guidance on each requirement, see the linked sources in the table above.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary