dora-expert

Navigate EU DORA regulatory requirements for financial entities.

1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill dora-expert-rifh2000
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dora-expert
Source: https://github.com/rifh2000/claude-grc-engineering./tree/main/plugins/frameworks/dora/skills/dora-expert
Command: npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill dora-expert-rifh2000

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Provides structured, expert guidance to achieve DORA compliance for EU financial entities, translating complex regulation into actionable steps.

Core Features & Use Cases

  • Comprehensive understanding of DORA's five pillars and TLPTs
  • Guidance on ICT risk management, incident reporting, third-party risk, and resilience testing
  • Practical templates and playbooks to align governance with regulatory expectations

Quick Start

Outline a practical 1-week action plan to map current controls to DORA requirements and identify gaps.

Frequently Asked Questions about dora-expert

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
What are the five pillars of DORA compliance for EU financial entities?

DORA incident reporting requires financial entities to document and notify relevant authorities of major ICT-related disruptions. This process provides structured templates and playbooks to align your incident reporting workflows with strict EU regulatory expectations.

How do I plan and execute Threat-Led Penetration Testing (TLPT) for DORA?

Planning TLPT for DORA involves mapping current controls against resilience testing requirements to identify gaps. It consolidates TLPT planning frameworks into actionable guidance tailored for EU financial institutions preparing for regulatory audits.

What is the best way to map current controls to DORA regulatory requirements?

DORA requires specific contract provisions for ICT third-party service providers to ensure financial entities maintain operational resilience. You can use provided templates to embed regulatory expectations and risk management clauses directly into third-party agreements.

How do I manage third-party risk and contract provisions under DORA?

DORA mandates strict oversight of ICT third-party risk through specific contract provisions and continuous monitoring. You can apply provided templates to align vendor agreements with EU regulatory expectations and mitigate third-party operational risks.