Regmindr
Templates

DORA compliance checklist

EU financial entity (DORA) · 10 deadlines

DORA (Regulation (EU) 2022/2554) has applied to EU financial entities since 17 January 2025. Most of its recurring obligations are yearly: reviewing the ICT risk management framework, testing continuity plans and critical systems, reporting to the management body and submitting the register of information. This template adds them to Regmindr with the article behind each one.

The deadlines in this template

  • Annual ICT risk management framework reviewDORA · At least once a year

    Review the ICT risk management framework at least once a year, and after any major ICT-related incident, then apply the lessons learned (DORA Art. 6(5)).

  • Annual review of ICT asset classification and risk assessmentDORA · At least once a year

    Review the classification of your ICT-supported business functions and assets, the risk scenarios affecting them and the risks of legacy ICT systems, at least yearly (DORA Art. 8(1), (2) and (7)).

  • Annual business continuity and recovery plan testDORA · At least once a year

    Test the ICT business continuity plans and the ICT response and recovery plans at least yearly, and after substantive changes to systems supporting critical or important functions (DORA Art. 11(6)(a)).

  • Annual testing of ICT systems supporting critical or important functionsDORA · At least once a year

    Run appropriate tests on all ICT systems and applications that support critical or important functions at least yearly, as part of the digital operational resilience testing programme (DORA Art. 24(6)).

  • Annual DORA register of information submissionDORA · Register as at 31 December, due in the first quarter

    Bring the register of information on ICT third-party arrangements up to date as at 31 December and submit it to your competent authority (DORA Art. 28(3)). Each authority sets its own deadline in the first quarter, for example 31 March in Luxembourg for 2026.

  • Annual ICT third-party risk strategy reviewDORA · Regularly, once a year here

    Review the strategy on ICT third-party risk, including the policy on ICT services that support critical or important functions, and the risks in your contracts (DORA Art. 28(2)).

  • Annual ICT report to the management bodyDORA · At least once a year

    Senior ICT staff report to the management body on the lessons learned from ICT incidents and tests, with recommendations, at least yearly (DORA Art. 13(5)).

  • Annual ICT security awareness trainingDORA · Once a year here; DORA sets no interval

    Run the compulsory ICT security awareness and digital operational resilience training for all staff and senior management (DORA Art. 13(6)).

  • Internal audit of the ICT risk management frameworkDORA · Regularly, once a year here

    Have ICT auditors audit the ICT risk management framework on a regular basis, as often as your ICT risk calls for, and follow up the findings (DORA Art. 6(6)). Microenterprises are exempt.

  • Threat-led penetration testDORA · At least every 3 years

    Carry out advanced threat-led penetration testing at least every 3 years, if your competent authority has selected your firm for it (DORA Art. 26(1)).

Download this checklist

Get these tasks as a spreadsheet, with columns for your own dates, owners and evidence, free.

10 deadlines

At least once a year

DORA sets a yearly minimum for the framework review (Art. 6(5)), the review of ICT assets and risks (Art. 8), continuity plan testing (Art. 11(6)), testing of systems that support critical or important functions (Art. 24(6)) and the ICT report to the management body (Art. 13(5)). Where DORA only says "regularly", as for the ICT audit and the third-party risk strategy, the template sets a yearly date you can change.

The register of information

The register of ICT third-party arrangements is brought up to date as at 31 December and submitted to your competent authority (Art. 28(3)). Each authority sets its own date in the first quarter, so check yours and enter it.

Threat-led penetration testing

TLPT is required at least every 3 years, but only for firms their competent authority has selected (Art. 26). Leave it out if you haven't been selected.

Who it's for

Banks, investment firms, payment and e-money institutions, crypto-asset service providers, insurers and the other financial entities listed in Art. 2. Firms under the simplified ICT risk management framework (Art. 16) have lighter requirements, so untick what doesn't apply.

Start with this template

Pick this template when you set up Regmindr, tick the deadlines that apply and check each date. Your team gets an email before each one is due.

Sources

This page is a summary, not legal or regulatory advice. The rules in the sources above take precedence.

Related