DORA implementation library: all five pillar playbooks in one bundle
The executive bundle. All five pillar playbooks + the Benchmark report, plus a dedicated 12-page Executive All-in-One: strategic implications, ROI model, 3-year roadmap, governance and a 3-page board-reporting pack.
What this solves
The five pillars are not five projects. Incident classification depends on which functions are critical; the critical function list comes out of the risk framework; the third-party register depends on both. Buying the pillars one at a time means discovering those dependencies in the wrong order.
The bundle exists for the case where the whole programme is yours and you would rather have the full set on day one than assemble it over six months.
What is inside
- Executive All-in-One (12p) — strategic / ROI / board pack
- Benchmark Report 2026 (20p)
- ICT Risk Management Playbook — Pillar 1 (22p)
- Incident Response Framework — Pillar 2 (21p)
- TLPT Implementation Guide — Pillar 3 (20p)
- Third-Party Risk Playbook — Pillar 4 (20p)
- Information & Intelligence Sharing — Pillar 5 (19p)
- 20 executive KPIs + risk-appetite framework
- 3-year roadmap by quarter
What it covers in the regulation
- Articles 5–16 — ICT risk management
- Articles 17–23 — incident management and reporting
- Articles 24–27 — resilience testing
- Articles 28–44 — third-party risk and oversight
- Article 45 — information sharing
Who uses it, and when
Programme leads owning the whole of DORA, and consultants who need the complete reference set rather than one pillar.
How to work through it
- Start with Pillar 1 — every other pillar refers back to the framework and the critical function list.
- Use the executive summary to agree scope with the board before the detail work starts.
- Work the pillars in dependency order, not in article order.
- Keep the roadmap and ROI model for the budget conversation, which always comes.