How far have you come with DORA? A self-test in 20 questions

20 questions in five areas show how far you have come with DORA: governance, ICT risk, incidents, testing and third-party risk. See the result straight away.

Summary: 20 questions in five areas show how far you have come with DORA, which has applied since 17 January 2025: governance and the ICT risk framework, identifying, protecting and detecting, ICT-related incidents, continuity and testing, and ICT third-party risk. The self-test takes 10–15 minutes, and the result appears straight away on a scale from red to green, with suggestions for what to do next. It is an indication, not a legal opinion or an audit.

About this guide

Who it is for
Financial entities covered by DORA that want to know where they stand.
What you get
A self-test in five areas with four questions each, following DORA’s chapters on ICT risk, incidents, testing and third-party risk, that takes 10–15 minutes and shows the result straight away with suggested next steps – guidance, not an audit.

The questions follow Regulation (EU) 2022/2554 (DORA) and the technical standards that supplement it. Answer yes only if you can show it, for example with a document, a procedure or a decision. “It should exist” counts as no. If you apply the simplified framework under Article 16, some questions apply to a lesser extent; answer for what applies to you. Choose Yes, No or Don’t know for each question, and the result appears straight away on the page.

Your answers stay in your browser and are not stored. We only count that a test was completed and which level it gave. If you would like to be contacted, you send the result yourselves with the form below the result.

First: are you a financial entity covered by DORA, for example a bank, insurer, investment firm, payment institution or fund manager? This question does not count in the result.

Area 1: Governance and the ICT risk framework

  1. Has the management body decided on your ICT risk management framework and taken responsibility for it? (Article 5)
  2. Is there a documented ICT risk management framework, with a digital operational resilience strategy? (Article 6)
  3. Does the management body have knowledge of ICT risk, kept up to date through regular training? (Article 5(4))
  4. Is the ICT risk management framework audited regularly by internal audit? (Article 6(6))

Area 2: Identify, protect and detect

  1. Have you identified your critical or important functions and the ICT assets they depend on? (Article 8)
  2. Are there protective measures for access, encryption and network security based on the risk assessment? (Article 9)
  3. Can you detect anomalous activity in your systems and raise alerts? (Article 10)
  4. Is there a controlled process for changes and updates in the ICT environment? (Article 9)

Area 3: ICT-related incidents

  1. Do you classify incidents using DORA’s criteria, so that you know when an incident is major? (Article 18, Regulation (EU) 2024/1772)
  2. Can you submit the initial notification to Finansinspektionen within four hours of classification and no later than 24 hours from awareness? (Article 19, Regulation (EU) 2025/301)
  3. Are all ICT-related incidents recorded, with root-cause analysis for the major ones? (Article 17)
  4. Is there a plan for informing clients and counterparts about a major incident? (Article 14)

Area 4: Continuity and testing

  1. Do you have an ICT business continuity policy and response plans tested in the past year? (Article 11)
  2. Are recovery times and acceptable data loss set for critical systems, and tested? (Article 12)
  3. Are critical ICT systems and applications tested at least once a year? (Article 24)
  4. Are lessons from incidents and tests used, and reported to the management body? (Article 13)

Area 5: ICT third-party risk

  1. Is your register of information on ICT third-party arrangements complete and current, and did you submit it to Finansinspektionen by 28 February? (Article 28(3), Regulation (EU) 2024/2956)
  2. Is there an ICT third-party risk strategy adopted by the management body? (Article 28(2))
  3. Do the contracts with ICT providers contain the terms DORA requires, especially for critical or important functions? (Article 30)
  4. Are there exit strategies for the providers that support critical or important functions? (Article 28(8))

Reading the result

  • Solid foundation, 18–20 yes: The basics are in place. Review the framework at least once a year and after major incidents.
  • Nearly there, 14–17 yes: Most of it is in place. The remaining gaps can usually be closed with a procedure or a decision.
  • Clear gaps, 10–13 yes: The foundation is partly there, but several parts are missing. Prioritise the areas with two yes answers or fewer.
  • Foundation missing, 9 yes or fewer: Several of the basics are missing. Start with the management body’s decision on the framework, incident classification and reporting, and the register of information.

The same scale applies per area: four yes is a solid foundation, three nearly there, two clear gaps, and one or none means the foundation is missing.

The self-test is an indication. It shows whether the basics seem to be there, not that you comply with DORA. A gap analysis assesses each requirement with evidence. If you answer no or don’t know to the questions on the management body’s decision, incident classification, notification to Finansinspektionen or the register of information, it should be looked into whatever the total, and the result shows this below the scale.

What to do next

Would you like to go through the result with us? Read more about DORA or contact us.

Sources: Regulation (EU) 2022/2554 (DORA), Articles 5–19, 24, 28 and 30; Delegated Regulations (EU) 2024/1772 and 2025/301; Implementing Regulation (EU) 2024/2956; Finansinspektionen, register of information under DORA. Fact-checked on 4 October 2026.

This text is general information and does not constitute legal advice in an individual case.