dora

Advises on DORA compliance, incident reporting, TLPT, and ICT third-party risk obligations.

Updated Jul 29, 2026
One-click install
npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill dora-fr-lyo-cys-aura
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: dora
Source: https://github.com/FR-LYO-CYS-AURA/GRC-Consultant/tree/main/extracted-skills/dora
Command: npx skills add https://github.com/FR-LYO-CYS-AURA/GRC-Consultant --skill dora-fr-lyo-cys-aura

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve? EU financial entities must comply with Regulation (EU) 2022/2554 (DORA) since 17 January 2025, but navigating its 64 articles and 12 adopted RTS/ITS is complex and error-prone. This Skill provides expert-level guidance on ICT risk management, incident classification and reporting, resilience testing, and third-party risk obligations. ## Core Features & Use Cases - Gap Analysis: Produces structured compliance assessment tables mapping DORA articles to obligations, evidence, and common gaps across all four phases (governance, incidents, testing, third-party risk). - Incident Classification & Reporting: Applies CDR (EU) 2024/1772 thresholds to classify incidents and generates the three-stage reporting timeline (4h initial, 72h intermediate, 1-month final) per Art. 19. - Third-Party Risk & Contracts: Reviews contracts against Art. 30(2)(a)–(i) mandatory provisions, builds the Register of Information per CIR (EU) 2024/2956, and assesses ICT concentration risk. - Use Case: A bank's compliance officer asks whether a 3-hour core banking outage affecting 12% of clients is reportable. The Skill classifies it as major under CDR 2024/1772, starts the 4-hour reporting clock, and drafts the initial notification content. ## Quick Start Ask the assistant to perform a DORA gap analysis of your ICT risk management framework against Articles 5 through 16.

Frequently Asked Questions about dora

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a DORA gap analysis for my financial entity?

A DORA gap analysis maps your current controls against obligations in four phases: governance and ICT risk framework (Art. 5–16), incident management (Art. 17–23), resilience testing (Art. 24–27), and third-party risk (Art. 28–30). Output is a table of article, obligation, status, evidence needed, and gap notes.

What are the DORA incident reporting deadlines?

DORA Art. 19 requires three-stage reporting of major ICT incidents: initial notification within 4 hours of classification as major, an intermediate report within 72 hours, and a final report within 1 month. The clock starts at classification, not detection, and runs 24/7 including weekends.

How is a major ICT incident classified under DORA?

An incident is major if it meets any single materiality threshold in CDR (EU) 2024/1772 across the Art. 18(1) criteria: clients affected, reputational impact, duration and geographic spread, data losses, criticality of services, and economic impact. The logic is OR, not AND.

What is the difference between DORA and NIS2?

DORA is lex specialis for the financial sector under Art. 1, applying to banks, insurers, investment firms, CASPs, and other financial entities. Financial entities subject to DORA are exempt from equivalent NIS2 obligations under NIS2 Art. 4(2); NIS2 applies only where DORA does not.

Which contractual provisions does DORA require for ICT vendors?

Art. 30(2) mandates nine provisions for contracts supporting critical or important functions, including data locations, audit and access rights for the entity and competent authorities, termination rights, data portability, and sub-contracting consent. Non-critical arrangements use the lighter Art. 30(3) set.

Does DORA apply to small financial entities?

Yes, but proportionality under Art. 4 allows micro-enterprises and certain small entities to use the simplified ICT risk management framework in Art. 16, with eligibility criteria in CDR (EU) 2024/1774 Chapter II. When eligibility is uncertain, the full Chapter II framework should be applied.