All frameworks

Digital Operational Resilience Act

DORA readiness assessment

Know which operational-resilience obligations are evidenced before supervisory scrutiny exposes the gaps.

An article-level requirement library (37) across DORA's five resilience pillars.

37 article-level requirement entries · versioned & change-controlled

Who it’s for

Financial entities and their critical ICT third-party providers in scope for the EU Digital Operational Resilience Act.

What readiness means for DORA

For DORA, readiness means each article-level requirement across the five pillars — ICT risk management, incident reporting, resilience testing, third-party risk and information sharing — is evidenced.

How Netallion handles it

Your DORA readiness journey

  1. 1

    Scope entity & pillars

    Confirm your standing — financial entity or critical ICT third-party provider — and scope the article-level requirements across the five pillars that apply to you.

  2. 2

    Map evidence to requirements

    Attach the ICT risk framework, incident procedures, test results and the third-party register to the article-level requirements they support, with ownership and review dates.

  3. 3

    Assess evidence

    Each requirement is assessed for whether the evidence demonstrates it in operation — a resilience test actually run, an incident classified and reported on the regulatory timeline — not merely a documented intention.

  4. 4

    Surface blockers

    Requirements with missing or stale evidence — a critical provider with no exit strategy, a test never performed — become explicit, ranked blockers.

  5. 5

    Review & finalise

    An authorised assessor reviews the determinations and pins a readiness conclusion; DORA is supervised by the competent authority, so there is no certification for Netallion to issue.

The control library

What the DORA library gives you

An article-level requirement library (37) across DORA's five resilience pillars.

A curated, versioned catalogue of this framework’s 37 article-level requirement entries — with provenance — to collect, own, organise and track the currency of your evidence against.

From the field

Common DORA blockers we find

Where evidence most often falls short — surfaced explicitly, not averaged away.

  • A third-party register exists but critical ICT providers lack documented exit strategies, so concentration risk has no mitigation.
  • Incident procedures are written but there is no evidence a major ICT incident was classified and reported within the regulatory timeline.
  • A testing programme is defined but the higher-tier scenario tests it commits to have never been executed.
  • The register of information omits the subcontracting chain, so a fourth-party dependency is invisible.

Evidence

The evidence you'll bring

You upload and own your evidence; Netallion organises it and tracks ownership and expiry. For this framework it typically spans:

ICT risk management

  • ICT risk-management framework
  • asset & dependency mapping
  • protection & prevention controls
  • business-continuity & response policies

Incident management

  • ICT-incident classification criteria
  • major-incident register
  • regulatory reporting records & timelines
  • root-cause analyses

Resilience testing

  • testing programme & schedule
  • vulnerability assessments & scans
  • scenario-based tests
  • threat-led penetration testing scope (where applicable)

Third-party ICT

  • register of information (contracts)
  • concentration-risk analysis
  • exit strategies for critical providers
  • subcontracting-chain records

Start now — free

Prepare your DORA evidence

Assess your DORA evidence with Netallion

There’s no self-serve kit for DORA yet. On an assessed engagement, Netallion scopes the requirements, organises your evidence, and determines readiness with explicit blockers.

From evidence to a conclusion

How readiness is reached

The kit helps you prepare. Netallion organises the evidence, assesses whether it's sufficient, and reaches a traceable readiness conclusion.

  1. 1Scope

    The applicable requirement set for your framework and scope.

  2. 2Applicable requirements

    A fixed denominator — every in-scope requirement counts.

  3. 3Evidence

    You attach and own evidence; ownership and expiry are tracked.

  4. 4Evidence assessment

    The evidence is read against each requirement for sufficiency.

  5. 5Determination

    A requirement-level verdict with byte-verified citations.

  6. 6Blocker

    Negative findings surface as explicit blockers, not averages.

  7. 7Remediation

    Track the fix; reassessment — not a checkbox — resolves it.

  8. 8Review (R0–R3)

    Controlled human review with recorded provenance.

  9. 9Finalisation

    A signed, scope-pinned readiness conclusion.

  10. 10Report / export

    Readiness report, evidence index, SoA, audit ZIP + SHA-256.

  11. 11Lifecycle & reassessment

    Evidence expires/changes → affected requirements reopen.

Schematic of the assurance workflow. Evidence collection and management are available today; the assessment, determination, review and finalisation stages are the System-B assurance engine.

What you get out

  • Requirement-level readiness across all 37 DORA article-level requirements
  • results grouped by the five resilience pillars
  • explicit blocker list with reasons
  • evidence index + audit ZIP with SHA-256 manifest

FAQ

DORA readiness — common questions

Is DORA something you get certified in?

No. DORA compliance is supervised by the relevant financial-services competent authority; there is no DORA certification. Netallion assesses your readiness against its requirements.

Does Netallion cover third-party ICT risk?

Yes — the third-party-risk pillar is part of the 37 article-level requirements assessed, including register completeness and exit-strategy evidence.

Who is DORA for?

Banks, insurers, investment firms, crypto-asset service providers and other financial entities, plus their critical ICT providers.

Related

Cross-framework leverage

Evidence you assemble for one framework often supports another. Commonly paired with:

Readiness, not certification. Netallion provides evidence assurance and readiness assessment; it does not issue or guarantee any formal outcome. Where a framework has a formal certification, attestation, authorisation or conformity-assessment scheme, that outcome remains with the appropriately authorised third party or authority. DORA is supervised by the relevant financial-services competent authority; there is no DORA certification Netallion could issue. Where the boundary sits.

See what your DORA evidence proves

See how Netallion assesses whether your evidence is sufficient — with explicit blockers and a traceable readiness conclusion.