secureskies
Cyber Security/Evaluate/DORA Preparation

Resilience
you can prove.

DORA requires financial entities to document ICT risk management, report incidents, test resilience and keep a complete register of all ICT third parties. We prepare those four mandatory areas so they withstand review by BaFin or your supervisory authority — from the service provider’s perspective as well.

FormatAssessment plus buildsupport optional
Duration6–12 weeksdepending on scope
ReferenceRegulation (EU) 2022/2554Art. 5–15 · 17–23 · 24–27 · 28–30
OutcomeImplementation planplus register and test concept
01 · Service

What is included.

For financial entities and their ICT service providers.

ICT risk management

Framework, roles, management-body accountability, asset and dependency inventory, business impact analysis.

Incident reporting

Classification against the thresholds, notification deadlines, notification paths, templates for initial, intermediate and final reports.

Resilience testing

A testing programme under Art. 24–27: scope, frequency, scenarios; and a judgement on whether threat-led penetration testing (TLPT) applies.

Third-party register

The Art. 28 register with the required fields, contract review against Art. 30, and an exit strategy per critical function.

Secureskies does not provide legal advice. The mapping to articles is our technical reading; what governs is the text of the regulation and the interpretation of your supervisory authority.

02 · Process

Five steps,
one deliverable.

01

Classification

Role as financial entity or ICT provider; identify critical or important functions.

02

Gap analysis

Check the four mandatory areas against the text of the regulation; review the evidence.

03

Register

Record third parties, assess contracts and exit capability.

04

Planning

Implementation plan with owners, dates and a test concept.

05

Report

Presentation to the management body and outsourcing function.

03 · Who it fits

When this service
applies.

Financial entities in scope of DORA
ICT providers being asked for DORA clauses by financial clients
Outsourcing officers building the register for the first time
More services · Evaluate

Is your DORA register in place —
and does it hold up?