DORA operating workspace | Compliancify

Coordinate ICT risk, incidents, resilience testing, third-party registers, contracts, oversight, evidence, and accountable review for an in-scope assessment.

Public scope

Structured context for people and machine readers.

This is a public product and knowledge surface. Illustrative workflows do not establish a professional conclusion, legal or tax advice, guaranteed outcome, or live customer implementation.

  • ICT risk management
  • ICT incident classification & reporting
  • Operational resilience testing
  • Third-party register
  • Contractual provisions & exit
  • Oversight & remediation

Public knowledge 01

Source and applicability boundary

  1. 01

    Official Regulation (EU) 2022/2554

  2. 02

    Delegated and implementing acts plus supervisory materials may apply

  3. 03

    Entity, service, proportionality, national, and group context require qualified review

  4. 04

    DORA has applied since 17 January 2025, but entity scope, proportionality, ICT service classification, reporting, registers, contractual requirements, and supervisory expectations require current-source and professional assessment.

  5. 05

    Official starting point: https://eur-lex.europa.eu/eli/reg/2022/2554/oj

Public knowledge 02

Obligation and control themes

  1. 01

    ICT risk management — Govern strategy, roles, framework, asset and dependency context, protection, detection, response, recovery, learning, and reporting.

  2. 02

    ICT incident classification & reporting — Classify ICT incidents, preserve facts and timing, route reporting thresholds, approvals, communications, and follow-up.

  3. 03

    Operational resilience testing — Maintain risk-based test scope, cadence, scenarios, independence, defects, remediation, validation, and advanced-testing decisions.

  4. 04

    Third-party register — Maintain ICT service, provider, entity, function, criticality, subcontractor, location, contract, dependency, and exit context.

  5. 05

    Contractual provisions & exit — Assess required contract terms, service levels, access, audit, incident support, data, subcontracting, termination, and exit plans.

  6. 06

    Oversight & remediation — Route board oversight, risk acceptance, material issues, supervisory requests, remediation, closure, and recurring review.

Public knowledge 03

Evidence and review expectations

  1. 01

    ICT risk management: Framework, policies, inventories, risk assessments, board reporting, incidents, tests, and improvements. Owner: ICT risk owner. Reviewer: Risk governance reviewer. State: Mapped.

  2. 02

    ICT incident classification & reporting: Incident record, classification rationale, timeline, impact, notification decision, submission record, and remediation. Owner: Incident owner. Reviewer: Regulatory reporting reviewer. State: Review due.

  3. 03

    Operational resilience testing: Test strategy, plans, scenarios, execution, results, defects, remediation, retest, and governance approval. Owner: Resilience testing owner. Reviewer: Independent test reviewer. State: Evidence ready.

  4. 04

    Third-party register: Register, service taxonomy, contracts, risk assessments, concentration analysis, changes, and ownership review. Owner: Vendor owner. Reviewer: Third-party risk reviewer. State: Review due.

  5. 05

    Contractual provisions & exit: Clause assessment, contract, addenda, approvals, exceptions, monitoring, termination rights, and exit test. Owner: Contract owner. Reviewer: Legal reviewer. State: Interpretation pending.

  6. 06

    Oversight & remediation: Governance packs, decisions, issues, supervisory correspondence, action evidence, validation, and closure approval. Owner: Operational resilience owner. Reviewer: Executive risk reviewer. State: Reviewer decision.

Public knowledge 04

Relationships without false equivalence

  1. 01

    NIS2 operational and incident context

  2. 02

    ISO/IEC 27001 management system

  3. 03

    NIST CSF 2.0 resilience outcomes