Published
Summary: 20 questions in five areas show how far you have come with DORA, which has applied since 17 January 2025: governance and the ICT risk framework, identifying, protecting and detecting, ICT-related incidents, continuity and testing, and ICT third-party risk. The self-test takes 10–15 minutes, and the result appears straight away on a scale from red to green, with suggestions for what to do next. It is an indication, not a legal opinion or an audit.
About this guide
- Who it is for
- Financial entities covered by DORA that want to know where they stand.
- What you get
- A self-test in five areas with four questions each, following DORA’s chapters on ICT risk, incidents, testing and third-party risk, that takes 10–15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.
The questions follow Regulation (EU) 2022/2554 (DORA) and the technical standards that supplement it. Answer yes only if you can show it, for example with a document, a procedure or a decision. “It should exist” counts as no. If you apply the simplified framework under Article 16, some questions apply to a lesser extent; answer for what applies to you. Choose Yes, No or Don’t know for each question, and the result appears straight away on the page.
Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.
First: are you a financial entity covered by DORA, for example a bank, insurer, investment firm, payment institution or fund manager? This question does not count in the result.
Area 1: Governance and the ICT risk framework
- Has the management body decided on your ICT risk management framework and taken responsibility for it? (Article 5)
- Is there a documented ICT risk management framework, with a digital operational resilience strategy? (Article 6)
- Does the management body have knowledge of ICT risk, kept up to date through regular training? (Article 5(4))
- Is the ICT risk management framework audited regularly by internal audit? (Article 6(6))
Area 2: Identify, protect and detect
- Have you identified your critical or important functions and the ICT assets they depend on? (Article 8)
- Are there protective measures for access, encryption and network security based on the risk assessment? (Article 9)
- Can you detect anomalous activity in your systems and raise alerts? (Article 10)
- Is there a controlled process for changes and updates in the ICT environment? (Article 9)
Area 3: ICT-related incidents
- Do you classify incidents using DORA’s criteria, so that you know when an incident is major? (Article 18, Regulation (EU) 2024/1772)
- Can you submit the initial notification to Finansinspektionen within four hours of classification and no later than 24 hours from awareness? (Article 19, Regulation (EU) 2025/301)
- Are all ICT-related incidents recorded, with root-cause analysis for the major ones? (Article 17)
- Is there a plan for informing clients and counterparts about a major incident? (Article 14)
Area 4: Continuity and testing
- Do you have an ICT business continuity policy and response plans tested in the past year? (Article 11)
- Are recovery times and acceptable data loss set for critical systems, and tested? (Article 12)
- Are critical ICT systems and applications tested at least once a year? (Article 24)
- Are lessons from incidents and tests used, and reported to the management body? (Article 13)
Area 5: ICT third-party risk
- Is your register of information on ICT third-party arrangements complete and current, and did you submit it to Finansinspektionen by 28 February? (Article 28(3), Regulation (EU) 2024/2956)
- Is there an ICT third-party risk strategy adopted by the management body? (Article 28(2))
- Do the contracts with ICT providers contain the terms DORA requires, especially for critical or important functions? (Article 30)
- Are there exit strategies for the providers that support critical or important functions? (Article 28(8))
- Several of the basics are missing. Start with the management body’s decision on the framework, incident classification and reporting, and the register of information.
- The foundation is partly there, but several parts are missing. Prioritise the areas with two yes answers or fewer.
- Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision.
- The basics are in place. Review the framework at least once a year and after major incidents.
- Gap analysis against ISO 27001, NIS2 or DORA A documented current state, gaps per requirement and a prioritised action plan management can decide on.
- Annual DORA review and maintenance A yearly review of framework, register, incident procedures and tests, so the DORA work stays current.
- Management cybersecurity training Training for management and the board that meets the Cybersecurity Act and DORA requirements, documented.
- Control testing Independent testing that your controls work, with evidence internal audit and supervisors can use.
- Security maturity assessment An assessment of how well the security measures work in practice, with prioritised improvements.
- Incident preparedness and tabletop exercise An incident procedure with roles and a reporting flow, exercised in a realistic scenario.
- Business continuity management and exercise Impact analysis, continuity plans and an exercise that shows the plans hold.
- Backup and recovery verification We check that the backups exist, are protected and can actually be restored.
- Vulnerability assessment and penetration testing We look for the vulnerabilities before someone else does, with a prioritised list of fixes.
- Supplier and third-party review Security requirements in contracts, risk-assessed suppliers and a follow-up procedure.
Would you like to go through the result with us?
Fill in your details and we will be in touch. The result in the box below is sent with the form, exactly as it reads there. We use the details only to contact you about the result and keep them for one year. Read more in our privacy notice.
Reading the result
- Solid foundation, 18–20 yes: The basics are in place. Review the framework at least once a year and after major incidents.
- Nearly there, 14–17 yes: Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision.
- Clear gaps, 10–13 yes: The foundation is partly there, but several parts are missing. Prioritise the areas with two yes answers or fewer.
- Foundation missing, 9 yes or fewer: Several of the basics are missing. Start with the management body’s decision on the framework, incident classification and reporting, and the register of information.
The same scale applies per area: four yes is a solid foundation, three nearly there, two clear gaps, and one or none means the foundation is missing.
The self-test is an indication. It shows whether the basics seem to be there, not that you comply with DORA. A gap analysis assesses each requirement with evidence. If you answer no or don’t know to the questions on the management body’s decision, incident classification, notification to Finansinspektionen or the register of information, it should be looked into whatever the total, and the result shows this below the scale.
What to do next
- Two yes or fewer in at least two areas: start with a gap analysis against DORA.
- Gaps in single areas: close them yourselves or in an annual DORA review.
- No to the questions on incidents: incident preparedness and a tabletop exercise give a procedure for classification and reporting, exercised in a scenario.
- Solid foundation: review the framework at least once a year and after major incidents.
Would you like to go through the result with us? Read more about DORA or contact us.
Sources: Regulation (EU) 2022/2554 (DORA), Articles 5–19, 24, 28 and 30; Delegated Regulations (EU) 2024/1772 and 2025/301; Implementing Regulation (EU) 2024/2956; Finansinspektionen, register of information under DORA. Fact-checked on 4 October 2026.
This text is general information and does not constitute legal advice in an individual case.

