The questions to ask
30 audit-ready questions per domain, grouped by theme, no blank page.
ISO + DORA mapping
Every question cites a control standard and the DORA article behind it.
Scoring & heatmap
Maturity 0–4 and Likelihood×Impact risk, with an auto 5×5 heatmap.
Live dashboard
Scores, charts and risk distribution update as you fill the workbook.
Methodology guide
How to scope, who to interview, how to score and how to report.
Each toolkit is a self-contained engagement kit: one Excel workbook + one methodology PDF. €79 each, or take all eight in the bundle below.
Cyber Security Risk Assessment Toolkit
Assess the cyber security control environment end to end: governance, identify, protect, detect, respond & recover, and security testing.
ISO 27001/27002/27005 + NIST CSF 2.0 - 30 questions
€79 excl. VAT one-off · lifetime updates
Buy & download: €79
IT / ICT Risk Assessment Toolkit
Assess the ICT risk management framework (DORA Pillar 1): governance, framework & policies, asset & dependency mapping, controls and monitoring.
ISO 31000/27005/27001 + COBIT 2019 - DORA Pillar 1 - 30 questions
€79 excl. VAT one-off · lifetime updates
Buy & download: €79
Operational Resilience Assessment Toolkit
Assess operational resilience: critical-function mapping, BIA & impact tolerances, continuity & DR, scenario testing and crisis management.
ISO 22301/22317/22316 + ISO 27031 - DORA Art. 11-12/24-27 - 30 questions
€79 excl. VAT one-off · lifetime updates
Buy & download: €79
Third-Party Risk (ICT TPRM) Assessment Toolkit
Assess ICT third-party risk (Pillar 4): due diligence, Article 30 contracts, Register of Information, monitoring, concentration & exit.
ISO 27036 + ISO 27001 supplier controls - DORA Art. 28-30 - 30 questions
€79 excl. VAT one-off · lifetime updates
Buy & download: €79
ICT Incident Management & Reporting Assessment Toolkit
Assess incident management & reporting (Pillar 2): detection, classification of major incidents, the 4h / 72h / 1-month reporting timelines, root-cause and testing.
ISO 27035 + ISO 27001 incident controls - DORA Pillar 2 (Art. 17-23) - 30 questions
€79 excl. VAT one-off · lifetime updates
Buy & download: €79
Resilience Testing & TLPT Assessment Toolkit
Assess resilience testing & TLPT (Pillar 3): the testing programme, vulnerability management, scenario & penetration testing, and TLPT / TIBER-EU alignment.
ISO 27001 testing + TIBER-EU - DORA Pillar 3 (Art. 24-27) - 30 questions
€79 excl. VAT one-off · lifetime updates
Buy & download: €79
ICT Concentration & Cloud Risk Assessment Toolkit
Assess ICT concentration & cloud risk (Art. 29): dependency mapping, cloud-specific risk, substitutability, sub-outsourcing chains and exit strategies.
ISO 27017/27018/27036 - DORA Art. 29 - 30 questions
€79 excl. VAT one-off · lifetime updates
Buy & download: €79
Governance & Accountability Assessment Toolkit
Assess governance & accountability (Art. 5): management-body responsibility, risk appetite, roles & segregation, policy approval and board oversight.
ISO 27001 leadership + ISO 37000 + COBIT 2019 - DORA Art. 5 - 30 questions
€79 excl. VAT one-off · lifetime updates
Buy & download: €79
The Operational Resilience toolkit measures whether your crisis arrangements exist.
Crisis Management is what builds them,
and the exercise programme is what proves
they work under DORA Article 11(6).
What is inside every toolkit
Cover & how to useScope, methodology and the scoring legend.
Assessment questionnaire30 questions by theme, each mapped to an ISO control and a DORA article, with "what good looks like".
Risk register & heatmapLikelihood×Impact scoring and an auto 5×5 heatmap.
DashboardOverall maturity, maturity by theme and risk distribution charts.
ISO & regulatory mappingThe standards used and a per-question crosswalk to DORA.
Action planRemediation tracker with owners, priority, target dates and status.
Built to be picked up and used on a client engagement the same day.
Independent consultants
A ready-made, re-brandable engagement kit so you can deliver a credible DORA risk assessment without building it from scratch.
GRC & risk teams
Run a structured self-assessment with defensible ISO-based scoring your board and supervisor will recognise.
Internal audit
A consistent question set and evidence trail to test the ICT and resilience control environment.