compliance-framework-dora

Summarize EU DORA ICT risk management and incident reporting provisions for financial entities.

2|Updated Apr 24, 2026
One-click install
npx skills add https://github.com/levicarlosz/OmniSec --skill compliance-framework-dora
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: compliance-framework-dora
Source: https://github.com/levicarlosz/OmniSec/tree/main/compliance/frameworks/dora/dora
Command: npx skills add https://github.com/levicarlosz/OmniSec --skill compliance-framework-dora

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides comprehensive guidance on DORA's complex ICT risk management and incident reporting standards, simplifying compliance for financial entities.

Core Features & Use Cases

  • Regulatory Navigation: Clarifies the structure, key articles, and adopted RTS/ITS of DORA for in-house compliance teams.
  • Gap Analysis & Implementation: Assists in identifying gaps between current practices and regulatory thresholds, supporting compliance improvement efforts.
  • Incident & Third-Party Oversight: Offers tailored procedures for incident classification, reporting timelines, contractual clauses, and oversight of critical ICT service providers.
  • Use Case: A compliance officer consults this Skill to prepare a detailed gap assessment against DORA requirements and develops a prioritized action plan.

Quick Start

Ask the compliance officer about the key obligations for ICT incident reporting under DORA to start aligning policies.

Frequently Asked Questions about compliance-framework-dora

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the key ICT risk management requirements under the EU DORA regulation?

The EU DORA regulation mandates financial entities to implement comprehensive ICT risk management frameworks, covering incident classification, third-party risk oversight, and specific reporting procedures. This Skill summarizes those provisions to provide clear regulatory guidance and actionable compliance steps.

How do I classify ICT incidents for DORA compliance reporting?

To classify ICT incidents for DORA compliance, you must follow the regulation's tailored procedures for incident categorization and adhere to strict reporting timelines. This Skill provides the specific regulatory thresholds and classification steps needed to align your current practices.

How do I perform a DORA gap analysis for financial sector compliance?

Performing a DORA gap analysis involves comparing your current practices against the regulation's key articles and adopted RTS/ITS. This Skill assists in identifying those compliance gaps and helps develop a prioritized action plan for implementation.

What contractual clauses are required for third-party ICT service providers under DORA?

DORA requires specific contractual clauses to ensure proper oversight of critical ICT third-party service providers. This Skill outlines the necessary provisions and oversight procedures to help financial entities manage external risk and meet regulatory expectations.

Does DORA compliance guidance cover both risk management and incident reporting procedures?

DORA compliance guidance comprehensively covers both ICT risk management frameworks and detailed incident reporting procedures. This Skill summarizes the regulation's structure, providing tailored steps for incident classification, reporting timelines, and overall resilience requirements.