It starts itself every quarter
A recurring schedule opens the review each quarter and assigns Phase 1 to the ICT risk manager. Mark the review as annual and the yearly obligations appear, so nobody has to remember them.
The Digital Operational Resilience Act, Regulation (EU) 2022/2554, has applied since 17 January 2025 to EU banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers, fund managers and most other regulated financial entities. What remains after go-live is the recurring work: current inventories, tested plans, classified incidents, an up-to-date register of information and a reviewed framework. This free DORA compliance checklist gives ICT risk managers, CISOs and compliance teams a quarterly review with an annual deep review. Conditional logic shows the full or simplified framework tasks, adds the annual phase once a year and adds post-incident tasks after a major incident. Every task has an owner and its evidence, and the management body’s decision is recorded by name.
Many DORA checklists online are gap assessments: forty-odd questions answered once, before the regulation applied. That was the right tool in 2024. Article 6(5) asks for something else: the ICT risk management framework must be reviewed at least once a year (periodically for microenterprises), and also after major ICT-related incidents, supervisory instructions or findings from testing and audits. The competent authority can ask for a report on the review. Other duties are yearly too: asset classification and risk scenarios (Article 8), continuity plan tests (Article 11(6)), tests of systems supporting critical or important functions (Article 24(6)) and register of information reporting (Article 28(3)).
Article 2 lists twenty types of financial entity, from credit institutions to securitisation repositories, with a few exclusions such as occupational pension funds whose schemes have no more than 15 members in total. Article 4 makes the rules proportionate to size, risk profile and complexity. Article 16 puts some smaller entities, such as small and non-interconnected investment firms and exempted payment and e-money institutions, on a simplified framework. Microenterprises outside Article 16 (fewer than 10 staff, turnover or balance sheet up to EUR 2 million) follow the full framework with some lighter duties.
When: once, before go-live or after a restructure.
Output: a list of gaps and a remediation plan.
Weakness: stale the day it is signed.
When: quarterly checks, plus the annual review under Article 6(5).
Output: an approved review report, a current register and tested plans.
This template: Phases 1–7.
When: after a major incident, a supervisory instruction or a test or audit finding.
Output: a post-incident review under Article 13(2) and framework changes.
This template: conditional tasks in Phase 5.
Phases 1, 2, 5 and 7 run every quarter. Your answers in Phase 1 choose between Phase 3 (full framework) and Phase 4 (simplified framework), switch on Phase 6 for the annual review and add post-incident tasks to Phase 5.
Owned by the ICT risk management function. Its three answers decide which phases and tasks appear.
Shown when the full framework applies. Sample the evidence; do not re-test every control.
Shown when the entity uses the simplified framework. Title III of Commission Delegated Regulation (EU) 2024/1774 sets out the detail.
Runs every quarter. The last three tasks appear only when a major ICT-related incident was classified in the period.
Shown only when the review is marked as the annual framework review.
Assigned to the approver named in Phase 1. The management body bears ultimate responsibility for ICT risk (Article 5), so the preparer cannot approve.
DORA sets principles in the regulation and detail in Commission delegated and implementing regulations drafted by the European Supervisory Authorities (EBA, EIOPA and ESMA). The table maps each recurring requirement to its source and the phase that evidences it. Which rules apply to you depends on your entity type, your size and whether you use the simplified framework, so treat the table as a starting point, not legal advice.
| Requirement | Article / RTS-ITS | What evidences it | Phase |
|---|---|---|---|
| Management body responsibility | Art. 5(2) and 5(4) | Minutes approving the strategy and key policies; training records | 2, 7 |
| Framework review | Art. 6(5); Delegated Reg. (EU) 2024/1774, Art. 27 | Dated review report approved by the management body | 6, 7 |
| Resilience strategy and risk tolerance | Art. 6(8) | Strategy with key risk metrics, tracked quarterly | 2, 6 |
| ICT audit and follow-up | Art. 6(6)–(7) | Audit plan and a findings tracker with remediation dates | 2 |
| Identification | Art. 8 | Inventories; yearly classification, scenario and legacy reviews | 3, 6 |
| Protection and detection | Arts 9–10; Delegated Reg. (EU) 2024/1774, Title II | Access reviews, patch and change records, alert thresholds | 3 |
| Response, recovery and backup | Arts 11–12 | Continuity and recovery plan tests at least yearly; restore test results | 3, 6 |
| Learning, training and communication | Arts 13–14 | Post-incident reviews, training completion, crisis communication plan | 3, 5, 6 |
| Simplified framework | Art. 16; Delegated Reg. (EU) 2024/1774, Title III | Documented framework, dependency list, test results | 4 |
| Incident classification and reporting | Arts 17–19; Delegated Regs (EU) 2024/1772 and 2025/301; Implementing Reg. (EU) 2025/302 | Incident log, classification record, timestamped reports | 1, 5 |
| Resilience testing and TLPT | Arts 24–27; Delegated Reg. (EU) 2025/1190 | Yearly test results; TLPT at least every 3 years for entities the authority identifies | 6 |
| ICT third-party risk and register | Arts 28–30; Implementing Reg. (EU) 2024/2956; Delegated Reg. (EU) 2024/1773 | Register of information, authority notifications, contract reviews, exit plans | 5, 6 |
DORA does not apply in the UK. UK firms in scope follow the FCA and PRA operational resilience rules, which required them to be able to stay within impact tolerances for important business services by 31 March 2025. New UK incident and third-party reporting rules apply from 18 March 2027, and UK oversight of the first four designated critical third parties began on 13 July 2026. In the EU, the ESAs designated the first critical ICT third-party providers in November 2025; under Article 28 the financial entity stays fully responsible either way. The Commission’s November 2025 Digital Omnibus proposal would add a single EU entry point for incident reports, DORA included. At the time of writing it is still a proposal, and the Commission says it would not change the reporting obligations themselves.
A recurring schedule opens the review each quarter and assigns Phase 1 to the ICT risk manager. Mark the review as annual and the yearly obligations appear, so nobody has to remember them.
The decision task goes to the approver chosen in Phase 1 and records who decided and when. Approval workflows keep the person who prepared the pack separate from the person who approves it.
The competent authority can ask for your review report at any time. Test results, incident reports and minutes sit on the tasks they support, so you export completed reviews with timestamps instead of rebuilding the story from inboxes.
CheckFlow is a checklist and workflow tool, not a GRC suite, SIEM or regulatory reporting portal. It does not classify incidents, run penetration tests or produce the register of information file your authority accepts. It runs the review, evidence and approval work around those systems. Our guide to financial services workflow automation covers DORA alongside KYC and SOX, and CheckFlow for financial services shows other recurring compliance workflows.
Operating in the US too? The GLBA Safeguards Rule Checklist covers the FTC’s security rule for non-bank financial institutions: a different regime and scope, with a similar annual rhythm. See also CheckFlow’s compliance checklist software.
DORA applies to the twenty types of EU financial entity listed in Article 2(1), including credit institutions, payment and e-money institutions, investment firms, crypto-asset service providers, fund managers, insurers, insurance intermediaries, occupational pension funds, trading venues and central counterparties. ICT third-party service providers are also in scope, mainly through the oversight of critical providers. Article 2(3) excludes some entities, and Article 4 scales the rules to size and risk. A non-EU group is in scope for its EU-authorised entities.
At least once a year, or periodically for microenterprises. Article 6(5) also requires a review after major ICT-related incidents, and after supervisory instructions or findings from resilience testing or audits. Entities on the simplified framework review periodically and after major incidents under Article 16(2). In both cases the competent authority can ask for a report on the review, in the format set by Delegated Regulation (EU) 2024/1774. Lighter quarterly checks, as in this template, give the annual review evidence to draw on.
Under Delegated Regulation (EU) 2025/301, the initial notification of a major ICT-related incident is due within 4 hours of classifying it as major, and no later than 24 hours after becoming aware of it. The intermediate report is due within 72 hours of the initial notification. The final report is due within one month of the latest intermediate report. Weekend and bank holiday relief exists but does not cover every entity, so check it before relying on it. Whether an incident is major is decided with the criteria in Delegated Regulation (EU) 2024/1772.
It is a register of all your contractual arrangements for ICT services, required by Article 28(3) and kept in the templates set by Implementing Regulation (EU) 2024/2956. Entities report it to their competent authority once a year, and authorities pass it to the ESAs by 31 March. In 2026 the data was as at 31 December 2025, and national windows closed around the end of March (the Central Bank of Ireland’s ran from 2 to 31 March). Check your own authority’s window each year.
Not to UK-authorised firms. They follow the FCA and PRA operational resilience rules and the UK critical third parties regime. A UK group with an EU-authorised subsidiary applies DORA in that subsidiary. The template’s review structure still works in the UK, mapped to important business services and impact tolerances instead of DORA articles.
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.