Pideeco

Free · Member account

DORA maturity check

Measure your digital operational resilience gaps against the Digital Operational Resilience Act.

This check is general information, not a compliance opinion or legal advice. · Based on DORA (EU) 2022/2554

Regulation

What is DORA - and why closing gaps matters now

  • 01

    A single EU framework

    DORA (EU 2022/2554) sets a single EU framework for ICT risk, incidents, testing and third-party oversight in finance.

  • 02

    Supervisory expectations since 2025

    Since January 2025, supervisors such as the NBB, CSSF and ACPR expect demonstrable operational resilience.

  • 03

    See gaps before the audit

    This free check helps CISOs and ICT risk teams across Europe see gaps before an audit or board update.

Who it is for

Built for financial entities in scope of DORA

If your organisation falls under Art. 2 of DORA, this self-assessment is designed for the people who own ICT risk and digital resilience.

  • Banks & credit institutions

    ICT risk frameworks, major incident notification and TLPT expectations under prudential supervision.

  • Insurance & reinsurance

    Operational resilience for critical systems, outsourcing and board-level ICT accountability.

  • Investment firms, payment & e-money

    Proportional ICT controls, incident processes and third-party registers for critical functions.

  • Other in-scope entities

    Asset managers, market infrastructures and other financial entities covered by DORA Art. 2.

Coverage

Six DORA domains in one check

Questions map to the main pillars of the regulation. Branching skips blocks that do not apply (e.g. deep TPR or TLPT).

  1. 01

    ICT governanceArt. 5–6

    Management body ownership, digital resilience strategy and three lines of defence.

  2. 02

    ICT risk managementArt. 7–16

    Framework, asset inventory, continuity/DR and detection capabilities.

  3. 03

    Incidents & reportingArt. 17–23

    Incident process, major-incident classification and supervisory notification timelines.

  4. 04

    Resilience testingArt. 24–26

    Testing programme, vulnerability/scenario tests and TLPT readiness when in scope.

  5. 05

    ICT third-party riskArt. 28–30

    Critical providers, register of information, contracts and ongoing oversight.

  6. 06

    Information sharingArt. 13 / 45

    Threat intelligence use, cyber information-sharing and lessons learned.

The offer

A four-step path from snapshot to concrete next moves

Pideeco advises professionals across Belgium, France, Luxembourg, the United Kingdom and the wider EU. This check reflects how we scope DORA engagements - not a generic quiz.

  1. 01

    Free member account

    One Pideeco account unlocks the check, saves your progress and keeps your results available.

  2. 02

    Tailored questionnaire

    Fifteen to twenty-five questions with branching. Skip deep TPR or TLPT when they do not apply.

  3. 03

    Scores and gaps

    Domain scores and priority gaps you can share with leadership or the board.

  4. 04

    Concrete follow-ups

    DORA training, RegWatch or a free intro call with our resilience team - when you are ready.

  • Questions referenced to real DORA articles
  • Aligned with EU supervisory practice
  • A snapshot to share before any next step

Frequently asked questions

Is this DORA maturity check free?

Yes. The full questionnaire and results are free with a Pideeco member account. We then suggest optional next steps (course, RegWatch or consulting) - nothing is paywalled inside the check.

Who should complete it in my organisation?

Typically the CISO, ICT risk officer, operational resilience lead or a compliance officer with visibility on ICT governance and outsourcing. One account can save a draft and finish later.

Does a high score mean we are DORA compliant?

No. Scores are a self-assessment snapshot for discussion - not a formal gap analysis, legal opinion or supervisory conclusion. Treat them as a structured starting point.

How long does it take?

Most users finish in about 10 minutes. Branching shortens the path when you have no critical ICT third parties or are outside TLPT scope.

Where does DORA apply?

DORA is an EU regulation directly applicable in all Member States. National competent authorities (such as the NBB, CSSF, ACPR and the FCA for related UK expectations) oversee how entities demonstrate resilience.

What happens to my answers?

Answers are stored on your member profile so you can resume or retake. You stay in control of any commercial next step.

See where you actually stand

Ten minutes. Free with a member account. Clear gaps and next steps for your European financial entity.

Create a free account to start