This free checklist walks Irish firms through the practical steps of DORA readiness across all five pillars. It is a starting point for prioritisation — not a substitute for a proper gap assessment or legal advice.
Use this checklist to get an at-a-glance sense of where you stand and what needs attention.
How to use this checklist
Work through each area and mark where you are confident, partial, or not yet started. Concentrate first on the areas the Central Bank has flagged for early attention: incident reporting and the register of information.
Governance
Management body has approved and oversees the ICT risk framework
Board-level ICT risk on the agenda, with training in place
ICT risk management
Documented framework covering identify / protect / detect / respond / recover
Critical or important functions identified and mapped
Incident reporting
Process to detect, classify and report major incidents
Registered for the Central Bank of Ireland Portal
Testing
Proportionate testing programme in place; CIF systems tested at least annually
Clarity on whether you are identified for TLPT
Third-party risk
Register of information built and maintained
Article 30 clauses in CIF-supporting contracts
Get the full, detailed checklist as a document you can work through. Download the DORA checklist.
Turn your checklist into a plan. Book a readiness assessment.