DORAFree Resource

EU DORA Compliance Decision Map

A fast way to answer the DORA questions that block execution. Use this decision map to confirm scope, choose the right implementation track, and translate DORA into incident reporting, testing, and third-party risk controls your team can operate.

This map is a snapshot. Regulations evolve, Level 2 acts and corrigenda land, and your organisation changes. Our Copilot keeps it current and tailored to your context. Our Autopilot evaluates where you stand and acts on the gaps.

Stop chasing compliance
What you can decide faster
In scope or not
Check Art. 2 scope, exclusions, and Member State option.
Implementation track
Full vs Art. 16 simplified; financial entity vs ICT provider.
Operational plan
Incident reporting, testing (TLPT), and ICT third-party controls.
By Sorena AIUpdated Feb 2026No sign-up required
Incident reporting (DORA)
RTS/ITS
Initial
Notification
Submit initial notification using ITS templates.
Intermediate
Report(s)
Update on significant status changes and progress.
Final
Report
Root cause analysis and actual impact figures.
Use the map to connect scope and proportionality to evidence and owners.
20Entity types
Ch. II-VCore duties
TLPTThreat-led tests
17 Jan 2025Applies from
Full vs simplified ICT
Register of ICT contracts
DORA Timeline

Key dates for DORA implementation

Track DORA's core milestones, Level 2 delegated and implementing acts, corrigenda, and supervisory deliverables that affect operational readiness.

Loading timeline...
DORA Compliance Decision Map

What does DORA require for your role?

Trace your path from Article 2 scope to a clear outcome: out of scope, DORA full framework, simplified ICT framework, or ICT third-party provider (including potential CTPP oversight).

EU DORA compliance decision map by Sorena AI
Go further

Turn DORA into an evidence-ready program

This decision map is a strong baseline. Sorena Research Copilot can tailor it to your entity type, group structure, outsourced ICT stack, and regulators, then turn it into deliverables your team can actually use.

  • Confirm scope and exclusions against your entity profile and group structure
  • Generate incident reporting workflows with templates, roles, and escalation paths
  • Operationalise register-of-information and third-party contract requirements
  • Plan testing, TLPT readiness, and evidence collection by stakeholder
Customize with Copilot
Tailor scope, controls, and evidence to your organisation.
Talk to an expert
Get a guided scoping session and implementation plan.