Free · Member account

DORA readiness check

Measure your digital operational resilience gaps against the Digital Operational Resilience Act — then get prioritised next steps with Pideeco.

  • 15–25 questions · about 10 minutes
  • Branching path tailored to your entity
  • Score by domain · prioritised gaps · free

This check is general information, not a compliance opinion or legal advice. · Based on DORA (EU) 2022/2554

Regulation

What is DORA — and why readiness matters now

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) sets a single EU framework for ICT risk management, incident reporting, resilience testing and ICT third-party oversight in the financial sector.

Since January 2025, in-scope entities must demonstrate operational resilience to supervisors — including NBB, CSSF and other national competent authorities. Gaps in governance, testing or critical ICT outsourcing are now supervisory priorities.

This free check helps CISOs, ICT risk and compliance teams in Belgium, Luxembourg and across the EU see where they stand — before an audit, SREP discussion or board update.

Who it is for

Built for financial entities in scope of DORA

If your organisation falls under Art. 2 of DORA, this self-assessment is designed for the people who own ICT risk and digital resilience.

  • Banks & credit institutions

    ICT risk frameworks, major incident notification and TLPT expectations under prudential supervision.

  • Insurance & reinsurance

    Operational resilience for critical systems, outsourcing and board-level ICT accountability.

  • Investment firms, payment & e-money

    Proportional ICT controls, incident processes and third-party registers for critical functions.

  • Other in-scope entities

    Asset managers, market infrastructures and other financial entities covered by DORA Art. 2.

Coverage

Six DORA domains in one check

Questions map to the main pillars of the regulation. Branching skips blocks that do not apply (e.g. deep TPR or TLPT).

  1. 01

    ICT governanceArt. 5–6

    Management body ownership, digital resilience strategy and three lines of defence.

  2. 02

    ICT risk managementArt. 7–16

    Framework, asset inventory, continuity/DR and detection capabilities.

  3. 03

    Incidents & reportingArt. 17–23

    Incident process, major-incident classification and supervisory notification timelines.

  4. 04

    Resilience testingArt. 24–26

    Testing programme, vulnerability/scenario tests and TLPT readiness when in scope.

  5. 05

    ICT third-party riskArt. 28–30

    Critical providers, register of information, contracts and ongoing oversight.

  6. 06

    Information sharingArt. 13 / 45

    Threat intelligence use, cyber information-sharing and lessons learned.

How it works

From account to actionable gaps in three steps

  1. 1

    Create a free member account

    One Pideeco account unlocks the check, saves your progress and keeps your results available when you return.

  2. 2

    Answer a tailored questionnaire

    Fifteen to twenty-five questions with branching. Skip deep TPR or TLPT blocks when they do not apply to you.

  3. 3

    Get scores, gaps and next steps

    Domain scores, priority gaps and clear follow-ups: DORA training, RegWatch, or a free intro call with our resilience team.

Why a Pideeco readiness check

Pideeco is a Brussels-based compliance, risk and RegTech firm advising financial institutions across Belgium, Luxembourg and the wider EU. This check reflects how we scope DORA engagements — not a generic online quiz.

  • Questions referenced to real DORA articles
  • Aligned with Belux supervisory practice
  • Direct path to training, watch and senior advice

Frequently asked questions

Is this DORA readiness check free?

Yes. The full questionnaire and results are free with a Pideeco member account. We then suggest optional next steps (course, RegWatch or consulting) — nothing is paywalled inside the check.

Who should complete it in my organisation?

Typically the CISO, ICT risk officer, operational resilience lead or a compliance officer with visibility on ICT governance and outsourcing. One account can save a draft and finish later.

Does a high score mean we are DORA compliant?

No. Scores are a self-assessment snapshot for discussion — not a formal gap analysis, legal opinion or supervisory conclusion. Treat them as a structured starting point.

How long does it take?

Most users finish in about 10 minutes. Branching shortens the path when you have no critical ICT third parties or are outside TLPT scope.

Is DORA applicable in Belgium and Luxembourg?

Yes. DORA is an EU regulation directly applicable in all Member States, including Belgium and Luxembourg, under the oversight of national competent authorities such as the NBB and CSSF.

What happens to my answers?

Answers are stored on your member profile so you can resume or retake. Completing the check may notify our team so we can offer relevant follow-up — you stay in control of any commercial next step.

Start your DORA readiness check

Ten minutes. Free with a member account. Clear gaps and next steps for your Belux or EU financial entity.

Create a free account to start