Share this article

The DORA Compliance Checklist
Accelerating security solutions for small businesses Tagore offers strategic services to small businesses. | A partnership that can scale Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. | Standing out from competitors Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market. |
As of January 17, 2025, all financial entities and their information and communication technology (ICT) service providers catering to EU entities must comply with the Digital Operational Resilience Act (DORA).
If you’re new to the regulation, you can reduce the potential overwhelm caused by its various requirements by using a concise compliance checklist. To help, we created this guide that covers everything you should know, including:
- DORA applicability criteria
- The regulation’s key requirements
- An actionable DORA compliance checklist with the key steps you need to take
Who needs DORA compliance?
DORA is aimed specifically at EU-based financial entities and ICT service providers. The following table provides examples of both:
While financial entities affected by DORA are limited to those operating in the EU or serving EU customers, ICTs must comply with the regulation regardless of location if they provide services to EU-based financial organizations.
5 key compliance requirements of DORA
While DORA mandates various security controls and procedures, the most important requirements are the regulation’s five pillars:
- ICT risk management
- ICT-related incident management
- Digital operational resilience testing
- ICT third-party risk management
- Information sharing
Out of the five, information sharing is the only voluntary aspect. You are required to comply with the requirements outlined in the other four pillars. As all of them are comprehensive and call for specific actions, a reliable checklist can help you streamline the compliance process and keep you focused on the main deliverables.
Your DORA compliance checklist: 9 key steps
Before starting the DORA compliance process, you should determine the regulation’s scope and applicability to your organization. The best way to do this is to refer to DORA’s Article 2 to check whether your organization is impacted by it based on your services and location.
If your organization must adhere to DORA, here are the baseline steps you can follow to get closer to full compliance:
{{dora="/checklists"}}





FEATURED VANTA RESOURCE
The ultimate guide to scaling your compliance program
Learn how to scale, manage, and optimize alongside your business goals.