What problem does it solve? EU financial entities must comply with Regulation (EU) 2022/2554 (DORA) since 17 January 2025, but navigating its 64 articles and 12 adopted RTS/ITS is complex and error-prone. This Skill provides expert-level guidance on ICT risk management, incident classification and reporting, resilience testing, and third-party risk obligations. ## Core Features & Use Cases - Gap Analysis: Produces structured compliance assessment tables mapping DORA articles to obligations, evidence, and common gaps across all four phases (governance, incidents, testing, third-party risk). - Incident Classification & Reporting: Applies CDR (EU) 2024/1772 thresholds to classify incidents and generates the three-stage reporting timeline (4h initial, 72h intermediate, 1-month final) per Art. 19. - Third-Party Risk & Contracts: Reviews contracts against Art. 30(2)(a)–(i) mandatory provisions, builds the Register of Information per CIR (EU) 2024/2956, and assesses ICT concentration risk. - Use Case: A bank's compliance officer asks whether a 3-hour core banking outage affecting 12% of clients is reportable. The Skill classifies it as major under CDR 2024/1772, starts the 4-hour reporting clock, and drafts the initial notification content. ## Quick Start Ask the assistant to perform a DORA gap analysis of your ICT risk management framework against Articles 5 through 16.