DORA Compliance Scanner

JK

A self-assessment aid for the EU Digital Operational Resilience Act (Regulation (EU) 2022/2554). Work through 19 requirements drawn from Chapters II–VI — ICT risk management, incident reporting, resilience testing, third-party risk and information sharing — mark the evidence you actually hold, and see your coverage by chapter and overall.

Loading requirement model…

This is not a compliance certification and not legal advice. It reports requirement coverage: the share of the model's requirements you can currently evidence as Present or Partial. Full coverage here means your evidence is consistent with the requirement as plainly described — not that a supervisor, auditor or court has confirmed compliance. It applies regardless of whether you are in scope of DORA as a financial entity; treat it as a structured way to read the regulation, not as a claim of financial-services DORA compliance experience. Everything runs in your browser and nothing you enter is transmitted, logged or sent anywhere — your answers are only ever saved to this browser's local storage, so you can close the tab and come back to where you left off.

1 Work the checklist

Mark Present only where you have evidence you could show someone (a document, a log, a test report). Partial means it exists but is incomplete or overdue for review. Absent means you checked and it is not there. Unknown is the honest default and is reported as a gap rather than quietly counted as absent.

2 Coverage summary

Open gaps — Absent or Unknown

i Scope of this model

The model covers Chapters II–VI of Regulation (EU) 2022/2554 — the obligations a financial entity applies to itself. Chapter V Section II (the oversight framework for critical ICT third-party providers) is a duty of the European Supervisory Authorities, not of financial entities, and is out of scope. Chapters I, VII–IX (definitions, competent authorities, delegated acts, transitional provisions) are institutional or administrative rather than self-assessable controls, and are also out of scope.

Each requirement is a plain-language reading of one article's official title and general scope. It is a summary for orientation, not a verbatim quotation of operative legal text — read the regulation itself before relying on any finding here.