dora-compliance-expert
DORA (EU 2022/2554) digital operational resilience compliance automation for financial entities. Assesses readiness against all 5 DORA pillars, classifies ICT incidents, validates third-party risk management, and generates resilience testing plans. Use for DORA compliance assessments, ICT risk management, incident classification, third-party ICT oversight, and digital operational resilience testing.
What this skill does
# DORA Compliance Expert Tools and guidance for Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (Digital Operational Resilience Act — DORA). --- ## Table of Contents - [DORA Overview](#dora-overview) - [Scope](#scope) - [Five Pillars Deep-Dive](#five-pillars-deep-dive) - [Penalties and Enforcement](#penalties-and-enforcement) - [DORA Implementation Roadmap](#dora-implementation-roadmap) - [Infrastructure Checks](#infrastructure-checks) - [Tools](#tools) - [Reference Guides](#reference-guides) --- ## DORA Overview The **Digital Operational Resilience Act (Regulation EU 2022/2554)** establishes a comprehensive framework for ICT risk management in the EU financial sector. It entered into force on January 16, 2023, and has been **applicable since January 17, 2025**. **Key objectives:** - Ensure financial entities can withstand, respond to, and recover from all types of ICT-related disruptions and threats - Harmonize ICT risk management requirements across the financial sector - Establish an oversight framework for critical ICT third-party service providers - Promote information sharing on cyber threats within the financial sector **Legal nature:** Unlike NIS2 (a directive requiring national transposition), DORA is a **regulation** — directly applicable in all EU Member States without transposition. **Relationship to other frameworks:** | Framework | Relationship | |-----------|-------------| | NIS2 Directive | DORA is lex specialis (specific law) for financial sector; NIS2 applies residually | | GDPR | DORA complements GDPR for security of ICT systems processing personal data | | EBA Guidelines on ICT | DORA supersedes prior EBA guidelines on ICT and security risk management | | PSD2 | DORA enhances and extends PSD2 operational resilience requirements | | MiCA | Crypto-asset service providers are in scope of both MiCA and DORA | | ISO 27001 | DORA requirements map to ISO 27001 controls; certification supports compliance | **Regulatory Technical Standards (RTS) and Implementing Technical Standards (ITS):** DORA is supplemented by detailed RTS/ITS developed by the European Supervisory Authorities (ESAs: EBA, ESMA, EIOPA). Key RTS/ITS cover: - ICT risk management framework details - Incident classification criteria and reporting formats - Threat-led penetration testing (TLPT) methodology - ICT third-party register format - Oversight framework procedures --- ## Scope DORA applies to **20 types of financial entities** and their **critical ICT third-party service providers**. ### Financial Entities in Scope | # | Entity Type | Examples | |---|------------|---------| | 1 | Credit institutions | Banks, building societies | | 2 | Payment institutions | Payment service providers | | 3 | Account information service providers | Open banking providers | | 4 | Electronic money institutions | E-money issuers | | 5 | Investment firms | Broker-dealers, portfolio managers | | 6 | Crypto-asset service providers | Crypto exchanges, custodians | | 7 | Issuers of asset-referenced tokens | Stablecoin issuers | | 8 | Central securities depositories | CSDs | | 9 | Central counterparties | CCPs | | 10 | Trading venues | Stock exchanges, MTFs, OTFs | | 11 | Trade repositories | Transaction reporting repositories | | 12 | Managers of alternative investment funds | Hedge fund managers, PE managers | | 13 | Management companies (UCITS) | Mutual fund managers | | 14 | Data reporting service providers | ARMs, APAs | | 15 | Insurance and reinsurance undertakings | Insurance companies | | 16 | Insurance intermediaries | Insurance brokers (except SMEs) | | 17 | Institutions for occupational retirement provision | Pension funds | | 18 | Credit rating agencies | S&P, Moody's, Fitch, etc. | | 19 | Administrators of critical benchmarks | LIBOR/EURIBOR administrators | | 20 | Crowdfunding service providers | Investment crowdfunding platforms | ### Proportionality Principle DORA applies proportionately based on the entity's: - Size and overall risk profile - Nature, scale, and complexity of services, activities, and operations - Systemic importance **Simplified ICT risk management framework** is available for: - Small and non-interconnected investment firms - Payment institutions exempted under PSD2 - Institutions exempted under Directive 2013/36/EU - Electronic money institutions exempted under EMD2 - Small IORPs ### Critical ICT Third-Party Service Providers The ESAs designate **critical ICT third-party service providers (CTPPs)** based on: - Systemic impact of the services on financial entities - Systemic character or importance of financial entities relying on the provider - Degree of substitutability of the provider - Number of Member States in which the provider operates CTPPs are subject to the **Direct Oversight Framework** by the Lead Overseer (one of the ESAs). --- ## Five Pillars Deep-Dive ### Pillar 1: ICT Risk Management (Chapter II, Articles 5–16) The cornerstone of DORA. Financial entities must establish a comprehensive ICT risk management framework. #### Governance and Organization (Article 5) The **management body** bears ultimate responsibility for ICT risk management: - Define, approve, oversee, and be responsible for the implementation of the ICT risk management framework - Define appropriate risk tolerance level for ICT risk - Approve the digital operational resilience strategy - Allocate adequate budget for ICT risk management - Approve and review the ICT business continuity policy and ICT response and recovery plans - Be informed at least once a year on findings of ICT risk reviews **Organizational requirements:** - Designate an ICT risk management function (second line of defense) - Ensure adequate separation of ICT risk management, control, and internal audit functions - Establish clear roles and responsibilities for all ICT-related functions - Implement reporting lines ensuring the management body receives timely information #### ICT Risk Management Framework (Article 6) Entities must establish, maintain, and implement a sound, comprehensive, and well-documented ICT risk management framework that: - Ensures a high level of digital operational resilience - Is documented and reviewed at least annually (or after major ICT incidents) - Includes a digital operational resilience strategy - Defines how the framework supports the entity's business strategy - Sets clear information security objectives - Defines ICT risk tolerance levels - Commits to a continuous improvement process **Digital Operational Resilience Strategy must include:** - Methods for addressing ICT risk - Explanation of how the ICT risk management framework supports the business strategy - ICT risk tolerance level - Key information security objectives - Overview of ICT reference architecture and changes needed - Mechanisms for detecting ICT anomalies - ICT third-party risk strategy - Digital operational resilience testing approach - Communication strategy for incident disclosure #### ICT Systems, Protocols, and Tools (Article 7) Requirements for ICT systems and infrastructure: - Use and maintain updated ICT systems, protocols, and tools that are adequate to support critical operations - Monitor effectiveness of ICT systems - Identify all sources of ICT risk (including environmental risks and physical threats) - Ensure appropriate network security management - Implement mechanisms for detecting anomalous activities #### Identification (Article 8) - Identify, classify, and adequately document all ICT-supported business functions, information assets, and ICT assets - Identify all sources of ICT risk, particularly cyber threats - Map the interconnections and interdependencies with ICT third-party providers - Perform ICT risk assessments at least annually (and after major changes) - Identify assets and systems critical to business operations #### Protection and Prevention (Article 9) - Implement ICT security policies, procedures, pr
Related in General
modeling-omnistudio-epc-catalog
IncludedSalesforce Industries CME EPC product-modeling skill for Product2-based catalog creation. Use when creating EPC products, configuring product attributes, building offer bundles with Product Child Items, or reviewing EPC DataPack JSON metadata for product catalog changes. TRIGGER when: user creates or updates Product2 EPC records, AttributeAssignment payloads, AttributeMetadata/AttributeDefaultValues, Offer bundles, or ProductChildItem relationships. DO NOT TRIGGER when: designing OmniScripts/FlexCards/Integration Procedures (use building-omnistudio-omniscript, building-omnistudio-flexcard, or building-omnistudio-integration-procedure), implementing Apex business logic (use generating-apex), or troubleshooting deployment pipelines (use deploying-metadata).
relationship-science-coach
IncludedUse this skill for direct, practical adult relationship coaching: couples conflict, repair, trust, marriage, dating, flirting, attachment patterns, emotional connection, sex, desire differences, eroticism, kink negotiation, affection, love languages, breakups, and long-term passion. Draw on Gottman, EFT and Hold Me Tight, attachment science, modern sex research, Perel, Nagoski, Kerner, Schnarch, Love and Stosny, and flexible love-language tools. Be concrete and low-hedge. Redirect only for imminent danger, abuse, coercive control, minors, non-consent, self-harm, stalking, or medical/legal/psychiatric decisions.
building-sf-integrations
IncludedSalesforce integration architecture and runtime plumbing with 120-point scoring. Use this skill to set up Named Credentials, External Credentials, External Services, REST/SOAP callout patterns, Platform Events, and Change Data Capture. TRIGGER when: user sets up Named Credentials, External Services, REST/SOAP callouts, Platform Events, CDC, or touches .namedCredential-meta.xml files. DO NOT TRIGGER when: Connected App/OAuth config (use configuring-connected-apps), Apex-only logic (use generating-apex), or data import/export (use handling-sf-data).
venue-templates
IncludedAccess comprehensive LaTeX templates, formatting requirements, and submission guidelines for major scientific publication venues (Nature, Science, PLOS, IEEE, ACM), academic conferences (NeurIPS, ICML, CVPR, CHI), research posters, and grant proposals (NSF, NIH, DOE, DARPA). This skill should be used when preparing manuscripts for journal submission, conference papers, research posters, or grant proposals and need venue-specific formatting requirements and templates.
let-fate-decide
IncludedDraws the 12 Houses of the Zodiac Tarot spread to inject entropy into planning when prompts are vague, ambiguous, or casually delegated. Interprets the spread to guide next steps. Use when the user says 'let fate decide', 'YOLO', 'whatever', 'idk', or other nonchalant phrases, makes Yu-Gi-Oh references, or when you are about to arbitrarily pick between multiple reasonable approaches. Prefer over ask-questions-if-underspecified when the user's tone is casual or playful rather than precision-seeking.
net-ops
IncludedCross-platform network troubleshooting (Windows, macOS, Linux) via local or remote shell. Use for: DNS broken, can't resolve hostnames, nslookup/dig works but apps fail, NRPT, WFP, scutil, /etc/resolver, systemd-resolved, /etc/resolv.conf, NetworkManager, VPN DNS leak residue (ProtonVPN/Mullvad/WireGuard/AnyConnect), AV/firewall blocking DNS or DoH, Tailscale DNS interaction, intermittent connectivity, remote diagnostics over SSH.