Complete Overview - All Technical Standards 2025
Ref. | Type | Topic | OJ Publication Date | DORA Pillar | PDF Documents |
---|---|---|---|---|---|
2024/1774 | RTS | ICT Risk Management Framework & Simplified Framework | 25 June 2024 | Pillar 1 | rts-ict-risk-management.pdf |
2024/1772 | RTS | Criteria for Classification of ICT-related Incidents | 25 June 2024 | Pillar 3 | rts-incident-classification.pdf |
2024/1773 | RTS | ICT Third-Party Service Providers - Contractual Policies | 25 June 2024 | Pillar 4 | rts-third-party-risk.pdf |
2025/532 | RTS | Subcontracting of ICT Services | 17 April 2025 | Pillar 4 | |
2025/301 | RTS | Major Incident Reporting - Content & Time Limits | 20 February 2025 | Pillar 3 | rts-incident-reporting.pdf |
2025/302 | ITS | Standard Forms & Templates for Incident Reporting | 20 February 2025 | Pillar 3 | ↑ Included in reporting.pdf |
2024/2956 | ITS | Standard Templates for Register of Information | 29 November 2024 | Pillar 4 | ↑ Included in third-party.pdf |
2025/420 | RTS | Joint Examination Team (JET) Composition | 17 January 2025 | Pillar 4 | Oversight (authorities) |
TIBER-EU | Framework | Threat-Led Penetration Testing (TLPT) | ECB 2018 (incorporated DORA) |
Pillar 2 | rts-tlpt-guide.pdf |
DORA Articles: 5-16
Applicable RTS: 2024/1774
Key requirements:
📄 Dedicated PDF: rts-ict-risk-management.html
DORA Articles: 24-27
Applicable framework: TIBER-EU (ECB)
Key requirements:
📄 Dedicated PDF: rts-tlpt-guide.html
DORA Articles: 17-23
Applicable RTS: 2024/1772 (Classification) + 2025/301 (Reporting)
Applicable ITS: 2025/302 (Templates)
Key requirements:
📄 Dedicated PDFs: rts-incident-classification.html + rts-incident-reporting.html
DORA Articles: 28-44
Applicable RTS: 2024/1773 (Contractual clauses) + 2025/532 (Subcontracting)
Applicable ITS: 2024/2956 (Register)
Key requirements:
📄 Dedicated PDF: rts-third-party-risk.html
DORA Articles: 45-47
RTS/ITS status: No specific RTS (voluntary arrangements)
Key requirements:
📄 Documentation: ESA Guidelines (no dedicated RTS)
File: rts-ict-risk-management.html
Content: Complete ICT risk management framework, governance, asset inventory, risk assessments, security controls, BCP/DRP, simplified framework for small entities
Pages: ~15 pages | Level: Detailed
File: rts-incident-classification.html
Content: 6 criteria for classifying major incidents (clients, duration, geography, data, economic impact, criticality), thresholds by entity type, practical examples, decision tree
Pages: ~18 pages | Level: Very detailed
File: rts-incident-reporting.html
Content: Reporting deadlines (4h/72h/1 month), mandatory content of each report, voluntary notification of cyber threats, submission process, penalties
Pages: ~16 pages | Level: Very detailed
File: rts-third-party-risk.html
Content: 8 mandatory contractual clauses, audit rights, data location, exit strategies, subcontracting rules, provider register (ITS 2024/2956), negotiation strategies
Pages: ~20 pages | Level: Very detailed
File: rts-tlpt-guide.html
Content: Complete TIBER-EU framework, 8 phases of TLPT, who is concerned, Red/Blue/White Team methodology, timeline (9-14 months), budgeting (€150k-500k), preparation checklist
Pages: ~18 pages | Level: Detailed
File: dora-rts-its-complete-overview.html
Content: Summary table of all RTS/ITS, chronological timeline, mapping of 5 DORA pillars, compliance roadmap, key deadlines
Pages: ~10 pages | Level: Summary
Date | Obligation | Concerns | Penalty if Non-Compliant |
---|---|---|---|
17 Jan. 2025 | Full application of DORA | All EU financial entities | General non-compliance = penalties up to 2% of global turnover |
30 April 2025 | First transmission of ICT provider register | All entities (via supervisor) | Fines + remediation order |
Ongoing from Jan 2025 | Major incident reporting (4h/72h/1 month) | All entities | Non-notification: up to 2% turnover | Delay: up to 1% turnover |
17 Jan. 2028 | First mandatory TLPT cycle | Significant entities only (~250 in EU) | Penalties + enhanced oversight |
Annual (every 30 April) | ICT provider register update | All entities | Proportional fines |
Every 3 years | TLPT (after the first) | Significant entities | Penalties + in-depth audit |
Don't do everything at once. Prioritize:
Build a cross-functional team:
Ballpark figures for average entity: