DORA Compliance

Keep your Digital Operational Resilience Act programme in one place — the entity profile, the ICT asset register, your third-party providers, your resilience tests, and the Article 18 incident classification.

DORA (the Digital Operational Resilience Act, EU 2022/2554 — the European law that requires banks, insurers, investment firms and similar financial entities to show their IT can withstand and recover from disruption) rests on five pillars. This module holds the records a supervisor asks for: who you are under DORA, which ICT systems carry your critical functions, which suppliers you depend on, how you test, and which incidents crossed the reporting thresholds. It is a pay-per-framework module: without the DORA entitlement on your licence, this page becomes a short upgrade message and every sub-page redirects back to it.

Who uses it

Access is granted by permission, not by one minimum role. Every DORA page requires dora:read; anyone without it is redirected to /unauthorized. Writing needs dora:update, and the buttons that need it are hidden rather than disabled. Classifying an incident needs dora:classify, and each register's Export CSV button needs dora:report — without it the button is not rendered at all.

Role What they can do in DORA
Admin Every DORA permission — read, update, classify and report — so every control on every page.
Manager Read everything, configure the profile, add and edit assets and providers, classify incidents, and — holding dora:report — export the registers to CSV.
Contributor The same, apart from dora:report — so the Export CSV button does not appear on any of the registers.
Viewer Read-only. Every page opens, but Add, row Edit, the profile Edit control and Export CSV are all hidden. The classify action on the DORA incidents list is still drawn, but the request behind it is refused without dora:classify.

What's on this screen

Open /compliance/dora from the Compliance group in the left sidebar. The screenshot below was captured as a Contributor, so every write control is visible. The header reads DORA Compliance, with the page's only primary action — AI Register Readiness — on the right. Below it, the DORA Readiness bar scores four areas at 25% each: a configured profile, at least one ICT asset, at least one third-party provider, and at least one resilience test. It is red below 25%, amber from 25% and green from 75%. In the capture it reads 25% in amber, captioned "Complete all four areas to achieve full readiness."

Under the bar sit four cards: DORA Profile, showing Configured with a small Edit button in its corner, then ICT Assets, Third-Party Providers and Resilience Tests, each with a count — all 0 here. Three navigation cards below carry the same names, a one-line description and their DORA article, and open the matching register.

Two panels close the page. Saved AI insights lists narratives you have kept — the capture shows one, saved on 7/15/2026, tagged Medium Confidence 57%, carrying the actions Show more, Create action item, Edit and Delete. Below it, Action items from AI is empty and says where items come from.

  1. Select AI Register Readiness. A modal opens explaining what the action reads, with a Run Register Readiness button; the narrative then streams into the modal.
  2. Select Edit on the DORA Profile card. The Set up DORA Profile dialog opens with the entity fields, pre-filled if a profile already exists.
  3. Read the Saved AI insights panel: each entry shows its save date, a confidence badge and the opening lines. Show more expands it.
  4. Select Create action item on a saved insight. There is no form: Aegis creates the item straight away, taking its title from the insight's first line and its description from the whole narrative, and confirms with a short message.
  5. Check Action items from AI below, where the new item appears without a page reload. In the capture it is still empty and explains where items come from.
The DORA Compliance dashboard — readiness bar, profile and count cards, register links, and the saved-insight and action-item panels — /compliance/dora.
The DORA Compliance dashboard — readiness bar, profile and count cards, register links, and the saved-insight and action-item panels — /compliance/dora.
Readiness measures presence, not assurance

Each 25% only confirms that an area has been started — a profile exists, and each register holds at least one record. It says nothing about whether your asset inventory is complete, your tests passed, or your providers have been assessed. Read it as a setup checklist.

Configure the DORA profile

The profile records who you are under DORA and is the first 25% of readiness. It is set from the dashboard card, not a separate page.

  1. Select Edit on the DORA Profile card — the button reads Configure when no profile exists yet. The Set up DORA Profile dialog opens.
  2. Enter the Entity Type. This is the only required field; the Save profile button stays disabled until it has a value.
  3. Choose an Entity Category (Financial entity or ICT service provider), type your Financial Sector, and pick a Proportionality TierSimplified, Standard or Enhanced, the lighter or fuller regime that matches your size and risk.
  4. Add the supervisory details that apply: tick ESA Designated if a European Supervisory Authority has designated you, then fill in Competent Authority and its URL, Lead Overseer Authority, and the Applicable Since and Last Assessment dates. All of these are optional.
  5. Select Save profile. The dialog closes and the card refreshes to Configured, adding 25% to the readiness bar if it was not set before.

Register ICT assets (Article 8)

This is your information-asset inventory under Article 8: the hardware, software, network, data, services and cloud systems behind your critical business functions. Open it from the ICT Assets navigation card.

The header carries Export CSV (with dora:report) and Add ICT Asset (with dora:update). The columns are Name, Type, Criticality, Status, Business Function and Actions, with a view (eye) action on every row and an edit (pencil) action for writers. Twenty-five rows fit a page. An empty register reads "No ICT assets registered yet."

  1. Select Add ICT Asset. The Add ICT Asset dialog opens.
  2. Enter the Asset Name — the placeholder suggests "e.g. Core Banking Platform" — then pick the Asset Type: Hardware, Software, Network, Data, Service, Cloud or Other.
  3. Set the Criticality — the form offers Low, Medium, High and Critical, and new records start at Medium — then the Business Function it supports and its Location. The form has no status field; a new asset is saved as Active.
  4. Select Save. A confirmation appears, the table reloads with the new row at status Active, and the dashboard's ICT Assets count rises.

Register third-party providers (Articles 28–44)

This register tracks the ICT suppliers you depend on and the concentration risk they carry — the exposure that builds when too much rests on one provider. Open it from the Third-Party Providers card.

The columns are Name, Type, Critical, Headquarters, Contract End, Substitutability and Actions; a contract ending within 90 days is flagged in its cell. The header offers Export CSV (with dora:report) and Add Provider (with dora:update).

  1. Select Add Provider. The Add Provider dialog opens.
  2. Enter the Provider Name and choose the Provider Type, then tick Critical Provider if the supplier underpins a critical or important function.
  3. Pick the Headquarters country from the list — it is stored as the two-letter code shown beside each name — set the Contract End date, and choose the Substitutability: Easy, Moderate, Difficult or Not Possible, meaning how hard the provider would be to replace.
  4. Select Save. The provider joins the table and the dashboard's Third-Party Providers count rises.
  5. Select the view (eye) action on a row to open the provider detail dialog, which includes a Concentration Risk (DORA Art. 29) section: the overall concentration risk, this provider's risk, the contributing factors and recommendations.

Read the resilience-testing register (Articles 24–27)

This holds your testing programme, from vulnerability assessments and penetration tests up to a TLPT (Threat-Led Penetration Test, the advanced red-team exercise DORA expects of larger entities). Open it from the Resilience Tests card.

  1. Read the table: Name (with the test type as a badge beneath it), ICT Asset, Status, Last Run, Next Scheduled, Findings and History. Statuses are Planned, In Progress, Completed or Overdue — Overdue is derived, not stored: it is shown when the next scheduled date has passed and the test is not yet completed.
  2. Check the Findings cell for pass, fail and open counts, and the History dots for recent runs.
  3. Use Refresh to re-read the register, or — holding dora:reportExport CSV to download dora-resilience-tests-register.csv.
This register is read-only in the app

The page has no add or edit control — it lists tests that already exist, with export, refresh and pagination. Tests are created through the DORA resilience-tests API by an account holding dora:update. The dashboard still counts the first test as the fourth 25% of readiness, however it was created.

Classify an ICT-related incident (Article 18)

Article 18 decides when an ICT incident counts as major and starts the reporting clock: an initial notification within 4 hours, an intermediate report within 72 hours, and a final report within one month. The page at /compliance/dora/incidents lists the incidents flagged as DORA incidents — classified or not yet — with a column for each of the three deadlines, reading Sent, Due, Overdue or N/A. Nothing in the app links to the page: there is no dashboard card and no sidebar entry, so reach it by typing the URL. A Back to DORA link at the top returns you to the dashboard.

  1. Open the incidents list and select the classify action on the row you want — the warning-triangle button beside the view action, which appears only while the incident has no classification. The DORA Article 18 Classification dialog opens, with an amber note at the top saying the result is a recommendation only.
  2. Fill in the impact fields — Affected Clients (%), Affected Transactions (%), Duration (hours), Member States Affected and Economic Impact (EUR) — then tick Data Loss or Integrity Breach, Critical Function Impacted or Significant Cyber Threat where they apply.
  3. Select Classify. The dialog answers with a single line — Classification: Major, Significant Cyber Threat or Not Applicable. The matched criteria and the confidence level are computed and stored with the incident, but the dialog itself does not list them.
  4. Confirm the classification yourself. Aegis writes the result to the incident as you submit — and for a Major it stamps the three deadlines — so the amber note asks you to review what has just been recorded, not to approve it first. A Not Applicable result clears the DORA flag, and the incident drops out of this list.
A person confirms every classification

The Article 18 check is a fixed rule test, not AI: it compares your figures against seven thresholds — 10% of clients, 10% of transactions, two hours of unavailability, two member states, any data loss, a critical-function impact, or €100,000 of cost — and reports which were crossed. It records the outcome on the incident and starts the deadline clocks, but it files nothing with a supervisor and settles nothing on your behalf. Per DORA Article 18 and EU AI Act Article 14, the dialog states that a human must confirm the final classification.

The AI assist

One AI action lives here: AI Register Readiness. Aegis first scores your Register of Information (Article 28(3)) itself — the profile, the three counts, and a fixed list of gaps ranked by severity and tied to DORA articles. Only then does the model narrate that picture: where you stand, plus three to five next steps drawn from your worst gaps. It never recomputes the score, reorders the gaps, or invents a provider, an asset or an article.

  1. Select AI Register Readiness. The modal explains what will be read, and notes that the narrative summarises gaps Aegis has already detected.
  2. Select Run Register Readiness. Progress lines appear as it reads the register, checks the counts, scores the gaps and drafts the narrative.
  3. Choose Save as record to keep it. The narrative then appears in Saved AI insights, where you can expand, edit or delete it, or turn it into an action item.

The run is billable: it consumes one AI credit and is written to your AI usage log. Anyone with dora:read can run it, a Viewer included. Nothing it produces changes a record — the output is a read, and the decisions stay with you.

Tips and limits

Where this connects

For framework coverage in general, see Compliance frameworks and Control mapping. Article 18 classification builds on Incidents and Incident reporting. Provider work overlaps with Vendors, and ICT assets have a wider home in Assets (CMDB). Follow-ups are worked in Action items, AI runs are listed in the AI dashboard, and Roles overview confirms who can reach these pages.