A fixed-scope, four-week assessment for financial entities in Ireland and across the EU. You leave with an evidenced position against all five pillars of DORA, an executive report your management body can act on, and a prioritised roadmap. No open-ended consultancy.
Under Article 5(2), the management body must "define, approve, oversee and be responsible for the implementation" of the ICT risk management framework. Not the CISO. Not the IT provider. The management body.
Quoted from Article 5(2) of Regulation (EU) 2022/2554 (DORA). The Regulation has applied directly in every Member State since 17 January 2025 — no transposition required.
DORA is a Regulation, so it applies directly to financial entities without national legislation. The obligations, the reporting clocks and the supervisory powers are already live.
From this date every in-scope financial entity is required to have an ICT risk management framework approved and overseen by its management body, and to report major ICT incidents on DORA's timelines.
Financial entities must maintain a register of all contractual arrangements with ICT third-party providers and submit it to their competent authority — in Ireland, the Central Bank — on request and on the supervisory cycle.
Entities designated by their competent authority must undergo TLPT at least every three years, alongside the annual testing programme every entity must run.
Supervisors are no longer asking whether you have a programme. They are asking for the evidence that the management body approved it and is overseeing it.
That evidence — decisions, minutes, the register, test results, incident records — is what the assessment assembles.Article 5 places the ICT risk management framework squarely with the management body, and lists what it must do personally rather than delegate.
Under Article 5, the management body is responsible for the framework and must, among other things:
Article 6(6) adds that the framework itself must be subject to internal audit by auditors with sufficient independence — and the Central Bank of Ireland, as competent authority, has the supervisory and enforcement powers to test whether that is happening.
DORA applies to around twenty categories of financial entity and to the ICT providers that serve them. The obligations are proportionate: a simplified framework applies to smaller entities under Article 16, and the largest providers are designated as critical and overseen at EU level.
DORA is organised into five areas of obligation. The assessment measures you against all five and expresses the result in the terms your supervisor uses.
A documented framework, approved by the management body, covering identification, protection, detection, response, recovery and learning. Articles 5–16.
Classify ICT incidents and report major ones: an initial notification within 4 hours of classification and no later than 24 hours from awareness, an intermediate report within 72 hours, a final report within one month. Articles 17–23.
An annual testing programme proportionate to the entity, plus threat-led penetration testing at least every three years for designated entities. Articles 24–27.
A strategy and policy for ICT third-party risk, the Register of Information, pre-contract due diligence, and the contractual provisions of Article 30. Articles 28–30.
Voluntary exchange of cyber threat information and intelligence within trusted communities of financial entities. Article 45.
Eighteen months in, the common picture is a framework signed off in a hurry before January 2025, a Register of Information built from spreadsheets, and a testing programme that exists on paper. The management body is accountable for all of it. Four weeks is enough to establish where you actually stand.
Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.
"DORA moved the question from 'do we have a framework' to 'can the board prove it is overseeing one'. The assessment answers the second question, which is the one the supervisor is asking."
Paul C Dwyer — CEO, Cyber Risk International; President, ICTTF; author of Cyber Risk LeadershipEvery deliverable is written for the management body accountable under Article 5 — and the report is the artefact it signs off.
Which DORA regime applies to you, whether the simplified framework is available, and which obligations follow.
Your critical functions, the ICT services that support them, and the providers behind those services.
Your position against Chapters II to VI, article by article, evidenced and mapped to NIST CSF 2.0.
Your assessment, gaps and evidence on CyberPrism for the programme and 30 days after it.
Written for a management body, not an IT department. Where you stand, what matters most, and what closing the gaps will take.
Actions ordered by exposure and effort, with owners and timeframes your team can commit to.
A check of your register against the ESA template and of key contracts against Article 30, with the gaps listed.
A session with your management body, with ThreatLens tying current threat activity to where you are weakest.
CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.
The DORA assessment is anchored on NIST CSF 2.0 with the DORA articles and regulatory technical standards as an overlay, so the same evidence also answers NIS2, the EU AI Act and other regimes without a second questionnaire. CRI's Independent Validation Assessment can sit on top where Article 6(6) independent review is required.
The assessment ends with a decision, not a filing cabinet. Most entities choose one of two paths.
Keep your CyberPrism environment live. Track remediation, re-assess quarterly, maintain the Register of Information, and give the management body a standing view it can evidence at every meeting — the position supervisors now expect.
Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.
It is the right time for one. The first year was about getting a framework approved; the supervisory phase is about whether it works and whether the management body can evidence its oversight. An assessment now tells you what a supervisor would find before they find it — and produces the evidence pack you would hand over.
Yes. Credit unions in Ireland are in scope, and the Central Bank has been explicit about that. Many will qualify for the simplified ICT risk management framework under Article 16, which is one of the first things the assessment determines — the obligations are lighter, but the management body's accountability is the same.
The Central Bank's earlier guidance is a good foundation and the assessment credits it. DORA adds obligations it does not cover — the Register of Information in the ESA format, the incident-reporting clock, the annual testing programme, Article 30 contractual terms — and asks for each to be evidenced. The assessment shows where your existing work carries you and where it does not.
Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — IT, risk, compliance, procurement, the outsourcing owner. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the framework; nobody is building spreadsheets.
No — it is a readiness assessment, designed to give you an accurate position and a plan. Where you need an independent review of the framework, CRI's Independent Validation Assessment is a separate engagement with its own independence safeguards, and the readiness assessment gives it a well-organised evidence base to work from.
The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.
Four weeks suits most single-entity organisations with a coordinator who can give it a few hours a week. Groups, entities with several regulated subsidiaries, or large third-party estates may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.
A 30-minute scoping call is enough to confirm which regime applies to you, what the four weeks would cover, and when it could start.