Pillar 1 ICT Risk Management
DORA Articles: 5-16
Applicable RTS: 2024/1774
Key requirements:
- Documented ICT risk management framework approved by management
- Complete inventory of ICT assets with criticality classification
- Identification of Critical or Important Functions (CIFs): the cornerstone concept that drives every other DORA obligation
- Risk assessments at least annually
- Business continuity and disaster recovery policy (BCP/DRP) with regular testing
- Security controls (access, encryption, monitoring, vulnerability management)
Dedicated guide: rts-ict-risk-management.html · CIF methodology
Pillar 2 Digital Operational Resilience Testing
DORA Articles: 24-27
Applicable framework: TIBER-EU (ECB)
Key requirements:
- Regular resilience tests (vulnerability scans, pentests, etc.)
- Mandatory TLPT every 3 years for significant entities
- TIBER-EU methodology or recognized equivalent
- Independent Red Team + scenarios based on real threat intelligence
- Remediation of identified vulnerabilities with timeline
Dedicated guide: rts-tlpt-guide.html
Pillar 3 ICT-related Incident Management & Reporting
DORA Articles: 17-23
Applicable RTS: 2024/1772 (Classification) + 2025/301 (Reporting)
Applicable ITS: 2025/302 (Templates)
Key requirements:
- Incident classification according to 7 RTS 2024/1772 criteria: (1) clients/transactions, (2) reputational impact, (3) duration, (4) geographical spread, (5) data losses, (6) criticality of services affected, (7) economic impact
- Major incident reporting:
- Initial: T+4 hours
- Intermediate: T+72 hours
- Final: T+1 month
- Voluntary notification of significant cyber threats
- Use of standardized XML templates (ITS 2025/302)
Dedicated guides: rts-incident-classification.html + rts-incident-reporting.html
The 4h clock is brutal. Resiplan triggers automated incident workflows matching the 6 RTS criteria, with built-in XML templates for supervisor submission.
See Workflow →
Pillar 4 Third-Party Risk Management
DORA Articles: 28-44
Applicable RTS: 2024/1773 (Contractual clauses) + 2025/532 (Subcontracting)
Applicable ITS: 2024/2956 (Register)
Key requirements:
- Mandatory contractual clauses:
- Access and audit rights (including for supervisors)
- Data location and sovereignty
- Incident notification (2h max)
- Termination rights and exit strategy
- Subcontracting control
- ICT provider register: Annual transmission to authorities (first time: 30 April 2025)
- Due diligence before subcontracting + 30-day notification + customer approval
- Limitation of cascading subcontracting (max 2 levels for critical functions)
Dedicated guide: rts-third-party-risk.html
Tip: Resiplan automates the Register of Information (ITS 2024/2956 template), generate and submit it in 2 clicks instead of spreadsheet work.
Discover →
Pillar 5 Information Sharing
DORA Articles: 45-47
RTS/ITS status: No specific RTS (voluntary arrangements)
Key requirements:
- Possibility to establish voluntary arrangements for sharing cyber threat information
- Protection of sensitive and commercial data
- No legal obligation, but strongly encouraged
- Examples: Sectoral ISACs, IOC sharing (Indicators of Compromise)
Documentation: ESA Guidelines (no dedicated RTS)
1. RTS ICT Risk Management (2024/1774)
File: rts-ict-risk-management.html
Content: Complete ICT risk management framework, governance, asset inventory, risk assessments, security controls, BCP/DRP, simplified framework for small entities
Pages: ~15 | Level: Detailed
2. RTS Incident Classification (2024/1772)
File: rts-incident-classification.html
Content: 7 RTS criteria for classifying major incidents (clients, reputation, duration, geography, data, criticality, economic impact), thresholds by entity type, practical examples, decision tree
Pages: ~18 | Level: Very detailed
3. RTS Incident Reporting (2025/301)
File: rts-incident-reporting.html
Content: Reporting deadlines (4h/72h/1 month), mandatory content of each report, voluntary notification of cyber threats, submission process, penalties
Pages: ~16 | Level: Very detailed
4. RTS Third-Party Risk Management (2024/1773 + 2025/532)
File: rts-third-party-risk.html
Content: 8 mandatory contractual clauses, audit rights, data location, exit strategies, subcontracting rules, provider register (ITS 2024/2956), negotiation strategies
Pages: ~20 | Level: Very detailed
5. TLPT Complete Guide (TIBER-EU)
File: rts-tlpt-guide.html
Content: Complete TIBER-EU framework, 8 phases of TLPT, who is concerned, Red/Blue/White Team methodology, timeline (9-14 months), budgeting (€150k-500k), preparation checklist
Pages: ~18 | Level: Detailed
6. Complete Overview (this document)
File: dora-rts-its-complete-overview.html
Content: Summary table of all RTS/ITS, chronological timeline, mapping of 5 DORA pillars, compliance roadmap, key deadlines
Pages: ~10 | Level: Summary
7. Register of Information: Implementation Methodology NEW
File: dora-ict-third-party-risk-register-methodology
Content: Step-by-step methodology to build the DORA Register of Information, 9 mandatory templates of ITS 2024/2956, xBRL-CSV format, CIF flagging, common rejection causes, 6-step playbook, FAQ.
Reading time: 14 min | Level: Methodology deep-dive
8. TLPT Testing: Phase-by-Phase Methodology NEW
File: dora-tlpt-testing-methodology-phase-by-phase
Content: Complete TLPT methodology under DORA Article 26 and TIBER-EU, 5 phases (preparation, threat intel, red teaming, closure, attestation), Red/Blue/White team setup, 9-14 month timeline, EUR 270k-620k budget breakdown, vendor selection.
Reading time: 16 min | Level: Methodology deep-dive