DORA · The 4-Week Readiness Assessment

DORA has applied since January 2025. Can your board show where you stand?

A fixed-scope, four-week assessment for financial entities in Ireland and across the EU. You leave with an evidenced position against all five pillars of DORA, an executive report your management body can act on, and a prioritised roadmap. No open-ended consultancy.

Under Article 5(2), the management body must "define, approve, oversee and be responsible for the implementation" of the ICT risk management framework. Not the CISO. Not the IT provider. The management body.

Quoted from Article 5(2) of Regulation (EU) 2022/2554 (DORA). The Regulation has applied directly in every Member State since 17 January 2025 — no transposition required.
Source: Regulation (EU) 2022/2554 — Digital Operational Resilience ActRead the Regulation on EUR-Lex · Central Bank of Ireland DORA page
Trusted expertise in regulated digital resilience
Operating since 2014 CyberPrism on Azure Marketplace Enterprise Ireland-backed technology Partnered with eir business
Awards and accreditations: IRM Global Risk Awards 2016, Bank of Ireland Startup Awards 2017 Fintech Award, HM Government G-Cloud approved supplier, CIR Risk Management Awards winner — Risk Management Specialist Company of the Year

This is not a directive waiting to be transposed. It is law now.

DORA is a Regulation, so it applies directly to financial entities without national legislation. The obligations, the reporting clocks and the supervisory powers are already live.

17 JAN 2025

DORA applies

From this date every in-scope financial entity is required to have an ICT risk management framework approved and overseen by its management body, and to report major ICT incidents on DORA's timelines.

ANNUALLY

Register of Information

Financial entities must maintain a register of all contractual arrangements with ICT third-party providers and submit it to their competent authority — in Ireland, the Central Bank — on request and on the supervisory cycle.

EVERY 3 YEARS

Threat-led penetration testing

Entities designated by their competent authority must undergo TLPT at least every three years, alongside the annual testing programme every entity must run.

Supervisors are no longer asking whether you have a programme. They are asking for the evidence that the management body approved it and is overseeing it.

That evidence — decisions, minutes, the register, test results, incident records — is what the assessment assembles.

What DORA expects the management body to have in place

Article 5 places the ICT risk management framework squarely with the management body, and lists what it must do personally rather than delegate.

Under Article 5, the management body is responsible for the framework and must, among other things:

  • Define, approve and oversee the ICT risk management framework
  • Set clear roles and responsibilities for ICT-related functions
  • Set and periodically review the digital operational resilience strategy and risk tolerance
  • Approve and review the policy on ICT third-party arrangements
  • Allocate an appropriate budget to digital operational resilience, including training
  • Keep its own knowledge and skills up to date on ICT risk

Article 6(6) adds that the framework itself must be subject to internal audit by auditors with sufficient independence — and the Central Bank of Ireland, as competent authority, has the supervisory and enforcement powers to test whether that is happening.

BOARD QUESTIONS

What a supervisor will expect you to answer

  • When did the management body last approve the ICT risk management framework, and is it minuted?
  • Which functions are critical or important, and which ICT services support them?
  • Is the Register of Information complete, current and submittable today?
  • What was tested last year, what was found, and what was fixed?
  • Could you classify and report a major ICT incident inside DORA's clock?
THE EVIDENCE BASE

What the assessment assembles for the management body

The artefacts a supervisor asks for, mapped to the five pillars
  • Approved ICT risk management framework with board minutes and review dates
  • Critical or important functions identified and mapped to ICT assets and providers
  • Incident classification and reporting procedure tested against Article 19 timelines
  • Digital operational resilience testing programme and results
  • Register of Information in the ESA template, ready for submission
  • ICT third-party policy and contractual provisions per Article 30
  • Board training record on ICT risk
  • Gap analysis and remediation plan with owners and dates
The four-week assessment is built to produce the scope determination, the five-pillar gap analysis, the remediation plan and the executive report — and to give the management body the evidence base behind them.

Who is in scope

DORA applies to around twenty categories of financial entity and to the ICT providers that serve them. The obligations are proportionate: a simplified framework applies to smaller entities under Article 16, and the largest providers are designated as critical and overseen at EU level.

Financial entities

Article 2 — the main categories
  • Credit institutions and credit unions
  • Payment institutions and e-money institutions
  • Investment firms and fund managers (AIFMs, UCITS management companies)
  • Insurance and reinsurance undertakings and intermediaries
  • Institutions for occupational retirement provision
  • Crypto-asset service providers
  • Trading venues, CCPs, CSDs, trade repositories
  • Crowdfunding service providers and credit rating agencies

ICT third-party providers

Indirect and direct obligations
  • Every ICT provider to a financial entity inherits contractual requirements under Article 30
  • Providers supporting critical or important functions face the fullest requirements — audit rights, exit plans, sub-contracting controls
  • Providers designated as critical are overseen directly by the ESAs
  • Cloud, software, data centre, managed service and outsourced operations providers are all in play
Central Bank of Ireland headquarters, Dublin
Central Bank of Ireland — the competent authority for DORA in Ireland. Not sure which regime, or whether the simplified framework applies to you? That is settled in the first week.

The five pillars — and what each asks of a board

DORA is organised into five areas of obligation. The assessment measures you against all five and expresses the result in the terms your supervisor uses.

CHAPTER II

ICT risk management

A documented framework, approved by the management body, covering identification, protection, detection, response, recovery and learning. Articles 5–16.

CHAPTER III

Incident management and reporting

Classify ICT incidents and report major ones: an initial notification within 4 hours of classification and no later than 24 hours from awareness, an intermediate report within 72 hours, a final report within one month. Articles 17–23.

CHAPTER IV

Resilience testing

An annual testing programme proportionate to the entity, plus threat-led penetration testing at least every three years for designated entities. Articles 24–27.

CHAPTER V

Third-party risk

A strategy and policy for ICT third-party risk, the Register of Information, pre-contract due diligence, and the contractual provisions of Article 30. Articles 28–30.

CHAPTER VI

Information sharing

Voluntary exchange of cyber threat information and intelligence within trusted communities of financial entities. Article 45.

Most management bodies have approved something. Fewer can show it is working.

Eighteen months in, the common picture is a framework signed off in a hurry before January 2025, a Register of Information built from spreadsheets, and a testing programme that exists on paper. The management body is accountable for all of it. Four weeks is enough to establish where you actually stand.

The DORA Readiness Assessment

Fixed scope. Four weeks. Delivered on the CyberPrism platform with a CRI practitioner guiding your team throughout — so the work is done with you, not to you.

WEEK 1

Onboarding and profile

Establish where you start from
  • Confirm entity type, regime and whether the simplified framework applies
  • Identify critical or important functions
  • Inherent ICT risk profile — what an outage would cost you
WEEK 2

Assessment

Measure against the five pillars
  • Structured working sessions with our practitioner — your team answers, we structure
  • Evidence gathered as you go
  • Mapped to the DORA articles and RTS, and to NIST CSF 2.0
WEEK 3

Gap analysis and dashboards

See the position clearly
  • Live dashboards against each pillar and article
  • Register of Information and contract review
  • Findings validated and weighted by exposure
WEEK 4

Board and roadmap

Decide what happens next
  • Executive readiness report delivered
  • Prioritised remediation roadmap
  • Management body briefing in person
Paul C Dwyer, CEO of Cyber Risk International

"DORA moved the question from 'do we have a framework' to 'can the board prove it is overseeing one'. The assessment answers the second question, which is the one the supervisor is asking."

Paul C Dwyer — CEO, Cyber Risk International; President, ICTTF; author of Cyber Risk Leadership

What you receive

Every deliverable is written for the management body accountable under Article 5 — and the report is the artefact it signs off.

Scope and regime determination

Which DORA regime applies to you, whether the simplified framework is available, and which obligations follow.

Critical or important functions map

Your critical functions, the ICT services that support them, and the providers behind those services.

Five-pillar readiness assessment

Your position against Chapters II to VI, article by article, evidenced and mapped to NIST CSF 2.0.

Live dashboards

Your assessment, gaps and evidence on CyberPrism for the programme and 30 days after it.

Executive readiness report

Written for a management body, not an IT department. Where you stand, what matters most, and what closing the gaps will take.

Prioritised remediation roadmap

Actions ordered by exposure and effort, with owners and timeframes your team can commit to.

Register of Information review

A check of your register against the ESA template and of key contracts against Article 30, with the gaps listed.

Board briefing and threat context

A session with your management body, with ThreatLens tying current threat activity to where you are weakest.

The DORA Readiness Executive Resilience Insights report — cover, executive scorecard and pillar chart
The DORA Readiness report — Executive Resilience Insights, sample pages
INSIDE THE REPORT

What your management body will read

  • Executive dashboard — key strengths, compliance gaps and risk areas, critical observations, strategic recommendations
  • Executive scorecard — overall readiness, implementation score, inherent risk exposure and the recommended target tier
  • DORA pillar readiness snapshot — implementation status across all five pillars
  • Threat resilience snapshot — spoofing, tampering, denial of service, ransomware and more
  • Readiness by pillar with a chart for each — ICT risk, incident reporting, testing, third-party risk, information sharing
  • Implementation guidance by pillar — what to do next, pillar by pillar, applying proportionality
  • Assessment methodology and how to interpret the results
5 pillarsExecutive scorecardThreat resilienceImplementation guidance

Built on CyberPrism

CyberPrism holds your assessment, evidence, dashboards and reports in one place — and keeps them current after the assessment ends, rather than leaving you with a document that dates on the day it is delivered.

The DORA assessment is anchored on NIST CSF 2.0 with the DORA articles and regulatory technical standards as an overlay, so the same evidence also answers NIS2, the EU AI Act and other regimes without a second questionnaire. CRI's Independent Validation Assessment can sit on top where Article 6(6) independent review is required.

DORANIST CSF 2.0NIS2UK Op-ResEU AI ActThreatLens
DORA readiness dashboard with compliance donut chart, five pillar breakdown and improvement areas
DORA — pillar-by-pillar compliance, high-priority gaps and maturity scoring.Click to enlarge

After the four weeks

The assessment ends with a decision, not a filing cabinet. Most entities choose one of two paths.

CONTINUOUS ASSURANCE

Keep your CyberPrism environment live. Track remediation, re-assess quarterly, maintain the Register of Information, and give the management body a standing view it can evidence at every meeting — the position supervisors now expect.

DELIVER IT YOURSELVES

Take the report and roadmap and work through it with your own team or existing providers. Nothing in the assessment ties you to CRI, and the roadmap is written so it can be handed to whoever will deliver it.

Oversight of ICT risk is now a standing item for the management body, not an annual one.

Common questions

DORA has applied since January 2025. Isn't it too late for a readiness assessment?

It is the right time for one. The first year was about getting a framework approved; the supervisory phase is about whether it works and whether the management body can evidence its oversight. An assessment now tells you what a supervisor would find before they find it — and produces the evidence pack you would hand over.

We are a credit union. Does DORA really apply to us?

Yes. Credit unions in Ireland are in scope, and the Central Bank has been explicit about that. Many will qualify for the simplified ICT risk management framework under Article 16, which is one of the first things the assessment determines — the obligations are lighter, but the management body's accountability is the same.

We already report to the Central Bank under existing outsourcing and operational-resilience guidance. Do we still need this?

The Central Bank's earlier guidance is a good foundation and the assessment credits it. DORA adds obligations it does not cover — the Register of Information in the ESA format, the incident-reporting clock, the annual testing programme, Article 30 contractual terms — and asks for each to be evidenced. The assessment shows where your existing work carries you and where it does not.

How much of our team's time does it take?

Typically two to three hours a week from a coordinator, plus one short session each with the people who own the relevant areas — IT, risk, compliance, procurement, the outsourcing owner. Our practitioner does the structuring, mapping and analysis so your team is answering questions, not writing reports. Four weeks works because the platform holds the framework; nobody is building spreadsheets.

Is this an audit? Does it satisfy the independent review in Article 6(6)?

No — it is a readiness assessment, designed to give you an accurate position and a plan. Where you need an independent review of the framework, CRI's Independent Validation Assessment is a separate engagement with its own independence safeguards, and the readiness assessment gives it a well-organised evidence base to work from.

What does it cost?

The programme is fixed-price for a defined scope, which is confirmed on the scoping call. We will not sell you a longer engagement than you need.

What if four weeks is not enough for us?

Four weeks suits most single-entity organisations with a coordinator who can give it a few hours a week. Groups, entities with several regulated subsidiaries, or large third-party estates may need longer, and the programme can be extended by agreement at scoping or during week one. The scope, timetable and price are settled before work starts, so an extension is never a surprise.

Know where you stand before the supervisor asks.

A 30-minute scoping call is enough to confirm which regime applies to you, what the four weeks would cover, and when it could start.

Book a scoping call
CRI partner with eir business
Prefer to talk? Call +353 (0)1 905 3260.