Free · Member account
DORA readiness check
Measure your digital operational resilience gaps against the Digital Operational Resilience Act — then get prioritised next steps with Pideeco.
- 15–25 questions · about 10 minutes
- Branching path tailored to your entity
- Score by domain · prioritised gaps · free
This check is general information, not a compliance opinion or legal advice. · Based on DORA (EU) 2022/2554
Regulation
What is DORA — and why readiness matters now

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) sets a single EU framework for ICT risk management, incident reporting, resilience testing and ICT third-party oversight in the financial sector.
Since January 2025, in-scope entities must demonstrate operational resilience to supervisors — including NBB, CSSF and other national competent authorities. Gaps in governance, testing or critical ICT outsourcing are now supervisory priorities.
This free check helps CISOs, ICT risk and compliance teams in Belgium, Luxembourg and across the EU see where they stand — before an audit, SREP discussion or board update.
Who it is for
Built for financial entities in scope of DORA
If your organisation falls under Art. 2 of DORA, this self-assessment is designed for the people who own ICT risk and digital resilience.
Banks & credit institutions
ICT risk frameworks, major incident notification and TLPT expectations under prudential supervision.
Insurance & reinsurance
Operational resilience for critical systems, outsourcing and board-level ICT accountability.
Investment firms, payment & e-money
Proportional ICT controls, incident processes and third-party registers for critical functions.
Other in-scope entities
Asset managers, market infrastructures and other financial entities covered by DORA Art. 2.
Coverage
Six DORA domains in one check
Questions map to the main pillars of the regulation. Branching skips blocks that do not apply (e.g. deep TPR or TLPT).
- 01
ICT governanceArt. 5–6
Management body ownership, digital resilience strategy and three lines of defence.
- 02
ICT risk managementArt. 7–16
Framework, asset inventory, continuity/DR and detection capabilities.
- 03
Incidents & reportingArt. 17–23
Incident process, major-incident classification and supervisory notification timelines.
- 04
Resilience testingArt. 24–26
Testing programme, vulnerability/scenario tests and TLPT readiness when in scope.
- 05
ICT third-party riskArt. 28–30
Critical providers, register of information, contracts and ongoing oversight.
- 06
Information sharingArt. 13 / 45
Threat intelligence use, cyber information-sharing and lessons learned.
How it works
From account to actionable gaps in three steps
- 1
Create a free member account
One Pideeco account unlocks the check, saves your progress and keeps your results available when you return.
- 2
Answer a tailored questionnaire
Fifteen to twenty-five questions with branching. Skip deep TPR or TLPT blocks when they do not apply to you.
- 3
Get scores, gaps and next steps
Domain scores, priority gaps and clear follow-ups: DORA training, RegWatch, or a free intro call with our resilience team.
Why a Pideeco readiness check
Pideeco is a Brussels-based compliance, risk and RegTech firm advising financial institutions across Belgium, Luxembourg and the wider EU. This check reflects how we scope DORA engagements — not a generic online quiz.
- Questions referenced to real DORA articles
- Aligned with Belux supervisory practice
- Direct path to training, watch and senior advice
Frequently asked questions
Is this DORA readiness check free?
Yes. The full questionnaire and results are free with a Pideeco member account. We then suggest optional next steps (course, RegWatch or consulting) — nothing is paywalled inside the check.
Who should complete it in my organisation?
Typically the CISO, ICT risk officer, operational resilience lead or a compliance officer with visibility on ICT governance and outsourcing. One account can save a draft and finish later.
Does a high score mean we are DORA compliant?
No. Scores are a self-assessment snapshot for discussion — not a formal gap analysis, legal opinion or supervisory conclusion. Treat them as a structured starting point.
How long does it take?
Most users finish in about 10 minutes. Branching shortens the path when you have no critical ICT third parties or are outside TLPT scope.
Is DORA applicable in Belgium and Luxembourg?
Yes. DORA is an EU regulation directly applicable in all Member States, including Belgium and Luxembourg, under the oversight of national competent authorities such as the NBB and CSSF.
What happens to my answers?
Answers are stored on your member profile so you can resume or retake. Completing the check may notify our team so we can offer relevant follow-up — you stay in control of any commercial next step.
Go further on DORA
Start your DORA readiness check
Ten minutes. Free with a member account. Clear gaps and next steps for your Belux or EU financial entity.
Create a free account to start
