dora-expert

Implement DORA-aligned ICT resilience controls for EU financial entities.

367|83|Updated Dec 26, 2025
One-click install
npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill dora-expert-grcengclub
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dora-expert
Source: https://github.com/GRCEngClub/claude-grc-engineering/tree/main/plugins/frameworks/dora/skills/dora-expert
Command: npx skills add https://github.com/GRCEngClub/claude-grc-engineering --skill dora-expert-grcengclub

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

DORA compliance guidance and expert support to help EU financial entities design, implement, and maintain robust ICT resilience, incident reporting, and third-party risk management across all pillars.

Core Features & Use Cases

  • DORA-aligned governance, risk management, incident reporting, testing, TLPT planning, and third-party oversight guidance tailored to financial entities.
  • Practical templates, checklists, and mappings to implement the 5 pillars, with clear roadmaps and evidence artifacts (policies, risk registers, data flows, and incident timelines).
  • Use Case: A financial institution uses this expertise to build a compliant DORA program, close gaps, and prepare for regulator audits.

Quick Start

Assess current ICT resilience posture and draft a DORA-aligned program plan to achieve compliant governance, incident management, and third-party risk controls.

Frequently Asked Questions about dora-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the DORA incident reporting timelines for EU financial entities?

DORA incident reporting timelines require an initial notification within 4 hours, a follow-up report at 72 hours, and a final report within 1 month. This guidance helps implement standardized templates to meet these regulatory deadlines.

How do I implement DORA ICT risk management controls for financial services?

Implement DORA ICT risk management by building asset inventories and maintaining risk registers. This provides tailored functional requirements to identify, assess, and mitigate ICT risks across your financial entity's governance structure.

What should be included in a DORA third-party risk management clause?

DORA third-party clauses must address ICT risk oversight and data protection considerations for external providers. This guidance specifies the functional requirements needed to ensure third-party compliance within the broader ICT resilience framework.

How do I prepare for DORA Threat-Led Penetration Testing (TLPT)?

Prepare for DORA TLPT by establishing a comprehensive testing program and assessing readiness. This involves planning TLPT scenarios aligned with ESAs oversight to validate your ICT resilience controls under threat conditions.

Can I use this to map our current ICT resilience posture against DORA's 5 pillars?

Yes, you can assess your current posture and map it against the DORA 5 pillars. This provides practical templates, checklists, and roadmaps to identify compliance gaps and generate evidence artifacts like policies for regulator audits.

What governance documentation is needed for ESAs oversight under DORA?

ESAs oversight requires governance documentation including policies, risk registers, and standardized reporting templates. This specifies the functional requirements needed to demonstrate compliant ICT resilience governance for EU financial entities.