DORA Readiness Diagnostic

A practical self-assessment for banks, investment firms, CSDs, trading venues, fund managers, insurance undertakings, crypto-asset service providers and ICT third-party providers under the Digital Operational Resilience Act.

Regulation (EU) 2022/2554 · Applied since 17 January 2025 · Ongoing supervisory focus 2026–2027

About this diagnostic

This tool asks focused questions across seven readiness areas drawn from DORA’s five pillars (ICT risk management, incident reporting, resilience testing, third-party risk, information sharing) plus governance and business continuity. It produces a spider chart and prioritised observations. Designed to be completed in 10–15 minutes by a CISO, operational resilience, risk or compliance lead.

Aligned with Regulation (EU) 2022/2554 and related RTS/ITS on ICT risk management, incident classification/reporting, and third-party registers.

Your DORA Readiness Results

Overall Readiness Score
Dimension Score Assessment

Prioritised observations

Disclaimer: This diagnostic is an illustrative self-assessment tool provided by GRT Consulting for educational and discussion purposes only. It does not constitute legal, regulatory or professional advice. Scores and observations are generated from your answers and should not be relied upon as a formal gap analysis or compliance opinion. For a detailed, firm-specific assessment please contact GRT Consulting.

Want a deeper, firm-specific DORA gap assessment?

GRT Consulting can run a full readiness review covering ICT risk framework, incident processes, testing, third-party register and contracts, and evidence packs for supervisors.

T: +44 20 3695 9251  ·  E: info@grtconsult.com

Submit a Request for Proposal →