Get Demo
↑

DORA Compliance Checklist

Practical DORA compliance checklist across the five pillars — ICT risk, incident reporting clocks.

Published: September 2026 Compliance · DORA 8–12 min read

Use this checklist as a programme board — not as a certification claim. Tick items only when evidence exists, not when a policy PDF exists.

Related: DORA hub · Five pillars · CSA.

How to score: For each item, record owner, evidence location, and last test/review date. Prefer living artefacts (register extracts, incident drills, TLPT remediation trackers) over undated policies.

Governance & ICT Risk (Arts 5–16)

Incident Reporting

Testing

Third-Party

Information Sharing

How CyberSilo Helps

Turn the Checklist into Tracked Evidence

Load checklist items into CSA with owners and proof links.

Frequently Asked Questions

Is this an official ESA checklist?

No. It is a practical CyberSilo programme outline aligned to the five pillars and common examination themes.

Do microenterprises use the same list?

Simplified ICT risk management may apply to certain microenterprises — confirm Article 16 themes and exclusions with counsel.

How often should we re-run the checklist?

At least quarterly for register and incident readiness; deeper annual review before management-body approval of the ICT risk framework.

Hub · What is DORA? · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!