DORA Checklist
0/45

DORA Compliance Checklist 2026: Are You Fully Compliant?

The supervisory tolerance period is over. This interactive checklist covers all 45 key requirements across the 5 DORA pillars: track your progress online, save it locally, and download the PDF version.

45 compliance items 5 DORA pillars Auto-saved locally PDF version available Updated March 2026
0%
0 of 45 items completed
Start ticking items below to track your DORA compliance status.

How to use this checklist

Tick each item your organisation has fully implemented. Your progress is saved automatically in your browser (localStorage): you can close the page and resume later. Items tagged CRITICAL are the highest-priority requirements under active supervisory scrutiny in 2026. IMPORTANT items are significant but may have phased implementation timelines. RECOMMENDED items represent best practice beyond the minimum legal requirement.

Applicable from 17 January 2025 21 categories of EU financial entities CTPP oversight: up to 1% average daily worldwide turnover (Art. 35(8)); financial entities: national regimes (Art. 50) Updated March 2026
1
ICT Risk Management
Articles 5–16 • 11 items
0/11

Compliance by Pillar

0%
ICT Risk
0%
Incidents
0%
Testing
0%
Third-Party
0%
Info Sharing
0%
Governance

DORA compliance checklist: common questions

Is DORA compliance mandatory for all financial institutions?

Yes. DORA applies to 21 categories of financial entities in the EU including banks, investment firms, insurance companies, payment institutions, crypto-asset service providers, and others. It has been fully applicable since 17 January 2025.

How many items are in the DORA compliance checklist?

This checklist covers 45 key compliance items across 5 DORA pillars: ICT Risk Management (11 items), Incident Management (7 items), Digital Resilience Testing (9 items), Third-Party Risk Management (8 items), Information Sharing (4 items), plus 6 governance items.

What is the penalty for DORA non-compliance?

DORA sets no EU-wide maximum fine for financial entities: Article 50 leaves administrative penalties to national law, so the amount depends on the Member State. The only turnover-based percentage in the Regulation applies to designated critical ICT third-party providers (periodic penalty payments capped at 1% of average daily worldwide turnover, Article 35).

Is TLPT required for all financial entities under DORA?

No. TLPT (Threat-Led Penetration Testing) is only mandatory for "significant" entities, typically large banks with assets over EUR 30bn, major insurance groups, and systemically important financial market infrastructures. Competent authorities designate which entities must conduct TLPT, at least every 3 years.

Get the PDF Checklist

Download a printable PDF version of this checklist: ideal for board presentations, audit preparation or offline review. Enter your details below and we'll send it to you instantly.

Keep your results

Email me my results + the DORA action checklist

We will send your results and the 75-control DORA compliance checklist to your work inbox. Unsubscribe anytime.

Practitioner tools for DORA compliance teams

Workbooks, playbooks and certifications built for EU financial entities. Add several to your cart: volume discounts apply automatically.

academy-bundle

DORA Certifications Bundle

399 € excl. VAT
academy

DORA for IT & Security Teams

199 € excl. VAT
academy

DORA for ICT Providers & Vendors

199 € excl. VAT
200
certificates issued
131
certified professionals
22
programmes awarded

Browse the full library · Excel toolkits · Certifications

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join the Webinar Waiting List