Resources

Download Compliance Resources

Access comprehensive guides, technical standards, templates, and tools to achieve DORA compliance. All resources are free and updated for 2025.

15+ Free Resources
2025 Updated
25K+ Downloads

Featured Resources

Our most comprehensive guides to help you understand and implement DORA requirements

Interactive Tool

DORA Compliance Assessment

Interactive compliance dashboard that helps you assess your current DORA readiness, identify gaps, and create a customized implementation roadmap.

  • Self-Assessment Tool
  • Gap Analysis
  • Custom Roadmap
  • Progress Tracking
Start Assessment

RTS/ITS Technical Standards

Official regulatory technical standards and implementation guidelines

Best entry point · €29.99

DORA RTS/ITS Quick Reference

A fast, cross-referenced lookup of the RTS/ITS standards — what each requires and when it applies. A handy companion, not a deep implementation playbook.

  • All RTS/ITS at a glance
  • Cross-reference index
  • Implementation timeline
Unlock — €29.99 excl. VAT
Premium

RTS Incident Reporting Guide

Complete guide to ICT-related incident reporting requirements including classification criteria, reporting timelines, and notification templates.

  • Classification Framework
  • Reporting Templates
  • Timeline Requirements
Unlock — €69 excl. VAT
Premium

RTS ICT Risk Management

Technical standards for ICT risk management framework, including governance, risk assessment methodologies, and control requirements.

  • Risk Framework
  • Governance Structure
  • Control Catalogue
Unlock — €69 excl. VAT
Premium

RTS Third-Party Risk Management

Standards for managing ICT third-party service providers including due diligence, contract requirements, and oversight framework.

  • Due Diligence Checklist
  • Contract Clauses
  • Register Template
Unlock — €69 excl. VAT
Testing Guide

TLPT Testing Framework

Comprehensive guide to Threat-Led Penetration Testing requirements including scoping, execution, and reporting guidelines.

  • TIBER-EU Framework
  • Testing Methodology
  • Reporting Templates
Unlock — €69 excl. VAT
Best Value · Bundle

DORA Complete Toolkit — All-in-One Bundle

All five pillar playbooks plus the Benchmark and Executive summary — 7 PDFs, ~134 pages. The complete practitioner library; save €175 vs buying separately.

  • Pillars 1–5 playbooks
  • Benchmark + Executive summary
  • Lifetime updates included
Get the Bundle — €199 excl. VAT

Sector-Specific Guides

Tailored compliance guidance for different financial sectors

Sector Guide

Banking Sector Compliance

DORA implementation guide specifically for banks, credit institutions, and payment service providers with sector-specific requirements.

  • Banking-Specific Requirements
  • Payment Systems Focus
  • Case Studies
Learn More
Sector Guide

Insurance Sector Compliance

Tailored guidance for insurance and reinsurance companies addressing specific operational resilience challenges in the insurance sector.

  • Insurance-Specific Risks
  • Solvency II Integration
  • Practical Examples
Learn More
Practical Examples

15 DORA Use Cases

Real-world implementation scenarios covering common challenges and practical solutions for DORA compliance across different contexts.

  • 15 Detailed Scenarios
  • Problem-Solution Format
  • Best Practices
View Use Cases

What's Inside Each Guide

The DORA technical standards are dense regulatory documents — Commission Delegated Regulations and Implementing Regulations running to 50-100+ articles each, written in formal EU legal style with extensive cross-references. Reading them cold is hard work even for experienced compliance teams. The guides on this page are interpretive companions: they translate the binding text into practical implementation language, with the regulatory anchors preserved so you can always trace a statement back to its article reference.

If you are new to the regulation, start with our complete guide to what DORA is for the big picture, run the free 45-point DORA compliance checklist to see where you stand, and read DORA vs NIS2 if your entity is also in scope of the cybersecurity directive. Then come back here for the technical detail.

Complete DORA Implementation Guide (59 pages)

The broadest reference. Covers all 64 articles of Regulation (EU) 2022/2554 organised by the five operational pillars, plus a full chapter on each related RTS. Each chapter includes: the binding requirement (with article citation), how it applies in practice, common implementation pitfalls, supervisory expectations, and a checklist of evidence the entity should hold. Used by 600+ institutions as the on-shelf DORA reference; refreshed quarterly as ESA Q&A documents are published.

RTS Incident Reporting Guide

Deep dive into the RTS on classification of major ICT-related incidents and the ITS on incident reporting templates and procedures. Walks through the 6 primary and 3 secondary classification criteria with worked examples for banks, insurers, investment firms and payment institutions. Includes the harmonised reporting template, the 4h/72h/1-month workflow, NCA portal walkthroughs (BaFin, ACPR, DNB, Banco de España, Banca d'Italia and others), and decision trees the duty officer team can paste into the incident management playbook.

RTS ICT Risk Management Framework Guide

Covers Commission Delegated Regulation 2024/1774 (RTS on ICT risk framework) and the simplified framework alternative. Maps every chapter of the RTS to existing controls under ISO 27001, NIST CSF and the legacy EBA ICT Guidelines so you avoid duplicating work. Includes the minimum content for security policies, the multi-factor authentication requirements for privileged access, the cryptographic agility expectation, and the network segmentation depth supervisors look for.

RTS Third-Party Risk Management Guide

Combines DORA Articles 28-30 with the RTS on subcontracting and the ITS on Register of Information. Includes: the 11-clause Article 30 mandatory contract checklist with negotiation guidance, the Register template with field-by-field guidance, the sub-outsourcing chain visibility methodology, the concentration risk assessment framework, and exit strategy documentation requirements with annual partial-extraction-test expectations.

TLPT Testing Framework Guide

The RTS on threat-led penetration testing operationalises Article 26 in alignment with TIBER-EU. The guide walks through designation criteria, the 5 phases (Preparation, Threat Intelligence, Red Team execution, Closure, Remediation), the white team / red team / blue team controls, NCA notification and supervisory attestation. Includes scoping templates, Targeted Threat Intelligence Report (TTIR) outline, RFP package for red team firm selection, and a defensible attestation file structure.

DORA Complete Toolkit — All-in-One Bundle (€199)

The complete practitioner library in one pack: all five pillar playbooks plus the Benchmark report and the Executive All-in-One — 7 PDFs, ~134 pages. The best-value way to equip the whole compliance function; save €175 versus buying the playbooks individually. Lifetime updates included.

RTS/ITS Quick Reference (€29.99)

A fast lookup companion: a cross-reference matrix between every DORA article and the related RTS/ITS, an article-level implementation timeline, and a short chapter on the Oversight Framework for designated CTPPs (Articles 31-44). A handy desk reference — not a substitute for the deep pillar playbooks above.

Buyer's Guide: Which Pack For Which Need?

Different roles in a financial institution typically need different starting points. Use the matrix below to identify the best fit:

Board / NED

Complete DORA Implementation Guide — covers accountability, governance, supervisory expectations. Read time: 4-6 hours.

CRO / Risk function

RTS ICT Risk Management Framework Guide + Complete Implementation Guide. Focus on integration with existing risk taxonomy.

CISO / Security

RTS ICT Risk Management Framework Guide + TLPT Testing Framework Guide. Operational depth on controls and testing.

Compliance Officer

All-in-One Bundle — the consolidated playbook library. Best for evidence file building and supervisory dialogue.

Procurement / Vendor Management

RTS Third-Party Risk Management Guide — Article 30 clauses, register, sub-outsourcing visibility.

Incident Response Team

RTS Incident Reporting Guide — classification criteria, decision trees and the 4h/72h/1-month workflow. Operational playbook material for the duty officer team.

Internal Audit

Complete Implementation Guide + All-in-One Bundle. Source material for audit programme design.

Legal Counsel

Complete Implementation Guide with article citations to the official Regulation text on EUR-Lex. Reference companion for contract drafting.

Frequently Asked Questions

Common questions about the downloadable resources

Are the DORA RTS/ITS guides on this page free?
A mix. Sector overview pages, the interactive compliance dashboard, and the public RTS/ITS HTML pages on this site are entirely free. The consolidated downloadable PDF package — combining all 6 RTS/ITS into a single curated reference with implementation checklists — is paid (€29.99 one-time). All free resources are clearly labelled.
Are these documents the official RTS/ITS texts published by the Commission?
No. The official binding texts are the Commission Delegated Regulations and Implementing Regulations published in the Official Journal — accessible free at EUR-Lex. The guides are interpretive companions translating the legal text into practical implementation language with cross-references, decision trees and templates.
Which guide should I download first?
Depends on your priority. Starting from zero on DORA: the Complete Implementation Guide. TLPT scoping coming up: TLPT Testing Framework guide. First incident reporting submission: RTS Incident Reporting guide. Building the Register of Information: RTS Third-Party Risk Management guide. Comprehensive reference: the RTS/ITS Complete Overview package.
What format are the downloads in?
PDF optimised for both screen reading and printing. Bookmarks and a clickable table of contents included. Each PDF is digitally signed. Templates or spreadsheets (e.g., Register of Information template, gap analysis register) are provided in editable XLSX format alongside the PDF.
How often are the guides updated?
Quarterly review cycle minimum, with ad-hoc updates whenever ESAs publish new RTS amendments or Q&A. Paid package buyers receive lifetime access including all future revisions at no additional cost. Current version date is on the cover; the changelog tracks all amendments.
Can I share the downloaded guides with my team?
Yes — within your organisation. Each purchase covers internal use across the buying entity (subsidiaries included). Redistribution outside the organisation, public posting, or sharing with consultants engaged by your competitors is not permitted. Bulk licensing for consulting firms is available on request.
Do the guides cover all DORA articles or only some?
The Complete DORA Implementation Guide covers all 64 articles plus the related RTS pack. Topic-specific guides deep-dive into the relevant 8-15 articles per topic. The RTS/ITS Complete Overview combines all topic-specific guides plus Oversight Framework and Information Sharing reference material.
Is there a refund policy?
Digital products are non-refundable once delivered, in line with EU consumer law. We offer a "preview pack" sample for the most popular packages so you can evaluate quality. Materially defective files are replaced immediately at no charge.
Do you offer training that complements the guides?
Yes. The Academy offers DORA-specific courses including the free DORA Fundamentals module and the paid ICT Risk Management Pro programme (€59). Live workshops and tailored in-house training are available through the Services page.
How do I get notified when guides are updated?
Buyers automatically receive update notifications via email. The newsletter also includes a "regulatory updates" channel where major RTS/ITS amendments are summarised within 7 days of publication. Both channels are GDPR-compliant.

Articles That Explain These Guides

Read the context behind each technical standard before downloading

RTS vs ITS: Understanding the Difference

Explains the legal distinction between Regulatory and Implementing Technical Standards — essential context before reading the guides.

Incident Reporting Under DORA: Step-by-Step

Walkthrough of the 4-hour, 72-hour, and final report timelines — pairs directly with the RTS Incident Reporting guide.

TLPT Under DORA Explained

What threat-led penetration testing actually requires under DORA — context for the TLPT RTS guide.

DORA Compliance Checklist 2025

Step-by-step implementation guide that complements the downloaded frameworks with actionable tasks.

19 Designated Critical ICT Providers (CTPPs)

Full list of providers designated by ESAs — essential reading alongside the third-party risk resources.

Latest DORA Technical Standards Updates

Recent ESA amendments — check this before downloading to know if you need the latest version.

Need Expert Guidance?

Our DORA compliance specialists can help you develop a customized implementation strategy tailored to your organization's needs.

How Compliant Is Your Institution?

Take our free 5-minute assessment and get an instant DORA compliance score with personalised recommendations.

Get Your Free DORA Score Join Free Monthly Webinar