DORA — Digital Operational Resilience Act

DORA — Digital Operational Resilience Act — 86% of in-scope requirements covered.

73 requirements · 73 in scope (59 enforced · 14 advisory). The 86% is weighted over the in-scope base.

Source: Regulation (EU) 2022/2554 of 14 December 2022 on digital operational resilience for the financial sector + accompanying RTS/ITS

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
ICT Risk Management Framework (Articles 5-15)2525000100%
ICT-Related Incident Management & Reporting (Articles 17-23)131102088%
Digital Operational Resilience Testing (Articles 24-27)10901093%
ICT Third-Party Risk Management (Articles 28-44)2514011067%

Every requirement → the KYE™ artefact that enforces it

IDTitleStatusKYE™ enforcement
dora.A5Article 5 — Sound, comprehensive, well-documented ICT risk-management framework integrated into overall risk managementenforcedaudit_events: kye.compliance.attestation.v1, kye.risk_assessment.v1, kye.evidence.decision_map.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/30-AUDIT-WORM-RETENTION.md
dora.A5.2Article 5(2) — Internal governance and control framework — proportionality, three lines of defenceenforced 1 unverified citationaudit_events: kye.authority.grant.v1, kye.authority.delegation.v1 unverified citation, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A6Article 6 — ICT risk-management framework — implements governance, defines roles, integrated with overall risk policyenforced 1 unverified citationaudit_events: kye.authority.grant.v1, kye.authority.delegation.v1 unverified citation, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A6.2.bArticle 6(2)(b) — ICT risk-management framework includes systems, protocols, tools to minimise ICT risk impactenforcedaudit_events: kye.purpose.permission.v1, kye.compliance.attestation.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/25-EDGE-GOVERNANCE.md
dora.A6.6Article 6(6) — ICT risk-management framework reviewed at least once a year and upon major incidentsenforcedaudit_events: kye.compliance.attestation.v1, kye.risk_assessment.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A6.8Article 6(8) — Documentation of the ICT risk-management framework available to authorities upon requestenforcedaudit_events: kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/30-AUDIT-WORM-RETENTION.md
dora.A7Article 7 — ICT systems, protocols, and tools — appropriate, reliable, resilient, well-documentedenforcedaudit_events: kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md, constitution/51-NO-SPOF.md
dora.A8Article 8 — Identification — inventory of all ICT-supported business functions, information assets, and ICT assets including dependenciesenforcedaudit_events: kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md, constitution/51-NO-SPOF.md
dora.A8.4Article 8(4) — Classification of information + ICT assets by criticalityenforcedaudit_events: kye.compliance.attestation.v1, kye.risk_assessment.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md, constitution/51-NO-SPOF.md
dora.A8.6Article 8(6) — Risk assessment of all ICT-supported business functions ≥annually + upon major changeenforcedaudit_events: kye.risk_assessment.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A9Article 9 — Protection and prevention — appropriate security policies, procedures, protocols, toolsenforcedaudit_events: kye.purpose.permission.v1, kye.evidence.tool_call_pin.v1, kye.evidence.decision_map.v1
engines: internal, internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/25-EDGE-GOVERNANCE.md
dora.A9.3Article 9(3) — Use of state-of-the-art technologies + processes ensuring security and protection of ICT systemsenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A9.4.cArticle 9(4)(c) — Network and infrastructure management — segmentation, secured configurationenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/16-EDGE-RUNTIME.md
dora.A9.4.dArticle 9(4)(d) — Identity and access management policiesenforcedaudit_events: kye.authority.grant.v1, kye.purpose.permission.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
dora.A9.4.eArticle 9(4)(e) — ICT change management including software / hardware / firmware / configurationenforced 1 unverified citationaudit_events: kye.resilience.drift.detected.v1 unverified citation, kye.signal.drift.detected.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A10Article 10 — Detection — mechanisms to promptly detect anomalous activities; logged + monitoredenforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.incident.opened.v1, kye.audit.event.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/35-STREAMING-LOGS.md
dora.A10.2Article 10(2) — Multiple layers of control, alert mechanisms, automatic triggering of responseenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.drift.detected.v1, kye.signal.revocation.cascaded.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A11Article 11 — Response and recovery — ICT business-continuity policy, response/recovery plans, tested annuallyenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.compliance.attestation.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/51-NO-SPOF.md
dora.A11.2.aArticle 11(2)(a) — Business-continuity objectives ≤ pre-defined RTO/RPOenforcedaudit_events: kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/51-NO-SPOF.md
dora.A11.5Article 11(5) — Annual testing of ICT business-continuity plansenforcedaudit_events: kye.compliance.attestation.v1, kye.assurance.audit_replay_report.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A12Article 12 — Backup policies and restoration procedures — separated from production, tested, and time-boundenforcedaudit_events: kye.compliance.attestation.v1, kye.evidence.pack.v1
engines: internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md, constitution/51-NO-SPOF.md
dora.A12.3Article 12(3) — Geographical separation of backup sites + productionenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md, constitution/51-NO-SPOF.md
dora.A13Article 13 — Learning and evolving — post-incident review feeds back into the ICT risk-management frameworkenforcedaudit_events: kye.resilience.loop_iteration.v1, kye.resilience.improvement_record.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A14Article 14 — Communication — incident-related comms procedure with employees, customers, peers, publicenforcedaudit_events: kye.comms.dispatched.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md
dora.A15Article 15 — Further harmonisation of ICT risk-management tools, methods, processes, policies via RTSenforcedconstitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A17Article 17 — ICT-related incident management process — detection, recording, classification, responseenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A17.2Article 17(2) — Recording of all ICT-related incidents + significant cyber threatsenforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.drift.detected.v1, kye.audit.event.v1
engines: internal, internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md
dora.A17.3Article 17(3) — Procedures for identification, tracking, logging, classification of incidentsenforcedaudit_events: kye.signal.incident.opened.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A18Article 18 — Classification of ICT-related incidents — based on impact, criticality of affected services, duration, geographic spread, data-lossenforcedaudit_events: kye.signal.incident.opened.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A18.2Article 18(2) — Materiality thresholds for classifying incidents as majorenforcedaudit_events: kye.signal.incident.opened.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A19Article 19 — Reporting of major ICT-related incidents to competent authoritiesenforcedaudit_events: kye.signal.incident.opened.v1, kye.compliance.attestation.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/38-COMMS-RAIL.md
dora.A19.1Article 19(1) — Initial notification within mandated time-windows (early notification ≤4h after classification)enforcedaudit_events: kye.signal.incident.opened.v1, kye.compliance.attestation.v1, kye.evidence.pack.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/38-COMMS-RAIL.md
dora.A19.4Article 19(4) — Intermediate and final reports — structured updates within mandated intervals; complete root-cause analysis in final reportenforcedaudit_events: kye.signal.incident.closed.v1, kye.resilience.improvement_record.v1, kye.evidence.pack.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A19.6Article 19(6) — Notification to clients when affected by a major incidentenforcedaudit_events: kye.comms.dispatched.v1, kye.signal.incident.opened.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md
dora.A20Article 20 — Harmonisation of reporting content + templates via RTS / ITSenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A21Article 21 — Centralisation of reporting via the EBA + ESMA + EIOPA central hubadvisoryconstitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A22Article 22 — Reporting of significant cyber threats (voluntary basis) — competent authority + ESAsadvisoryaudit_events: kye.signal.drift.detected.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A23Article 23 — Operational and security payment-related incidents reporting — coordinated with PSD2/PSD3 Article 96enforcedaudit_events: kye.signal.incident.opened.v1, kye.payments.intent.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A24Article 24 — Digital operational resilience testing program — risk-based, proportionate, covering vulnerability and scenario testingenforcedaudit_events: kye.compliance.attestation.v1, kye.risk_assessment.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A24.2Article 24(2) — Test program covers vulnerability assessments + scans, open-source analyses, network security assessments, gap analyses, performance testing, penetration testing, source-code reviewsenforcedaudit_events: kye.signal.drift.detected.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A24.4Article 24(4) — Tests conducted by independent parties (internal or external)enforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/49-UNIVERSAL-ENGAGEMENT-RAIL.md
dora.A25Article 25 — Testing of ICT tools and systems — annually for critical, on independent test environment, all important systemsenforcedaudit_events: kye.compliance.attestation.v1, kye.assurance.audit_replay_report.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A25.bisArticle 25 — Vulnerability assessments and scans — performed regularly on important ICT systemsenforcedaudit_events: kye.signal.drift.detected.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A26Article 26 — Threat-Led Penetration Testing (TLPT) — every 3 years for critical financial entities, TIBER-EU alignedenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A26.2Article 26(2) — Identification of critical functions for TLPT scopeenforcedaudit_events: kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md, constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A26.3Article 26(3) — TLPT testing scenarios based on real-world threat intelligenceenforcedaudit_events: kye.signal.drift.detected.v1, kye.assurance.audit_replay_report.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
dora.A26.8Article 26(8) — Reporting of TLPT results to competent authority + summary findingsenforcedaudit_events: kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A27Article 27 — Requirements for testers — independent, sufficiently qualified, certified or with documented expertiseadvisoryconstitution_refs: constitution/10-PARTNER.md, constitution/49-UNIVERSAL-ENGAGEMENT-RAIL.md
dora.A28Article 28 — ICT third-party risk as integral part of ICT risk management; principle of proportionalityenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.compliance.attestation.v1, kye.risk_assessment.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/51-NO-SPOF.md
dora.A28.2Article 28(2) — Policy on use of ICT services supporting critical functionsenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.subprocessor.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/51-NO-SPOF.md
dora.A28.3Article 28(3) — Register of information on all contractual arrangements with ICT third-party providersenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.subprocessor.v1
engines: internal, internal
constitution_refs: constitution/51-NO-SPOF.md, constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A28.4Article 28(4) — Assessment before entering into contractual arrangement including ICT concentration riskenforcedaudit_events: kye.risk_assessment.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
dora.A28.5Article 28(5) — Identification and assessment of conflicts of interestenforcedaudit_events: kye.compliance.attestation.v1, kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
dora.A29Article 29 — Preliminary assessment of ICT concentration risk at entity level before entering into a contractual arrangementenforcedaudit_events: kye.compliance.attestation.v1, kye.risk_assessment.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
dora.A30Article 30 — Key contractual provisions — description of services, locations, data-processing, sub-contracting, exit strategy, access rightsenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.evidence.tool_call_pin.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/31-DATA-GOVERNANCE-PACK.md
dora.A30.2.aArticle 30(2)(a) — Description of all functions + ICT services providedenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.subprocessor.v1
engines: internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
dora.A30.2.bArticle 30(2)(b) — Locations of data processing + storageenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.subprocessor.v1
engines: internal, internal
constitution_refs: constitution/31-DATA-GOVERNANCE-PACK.md
dora.A30.2.fArticle 30(2)(f) — Sub-contracting clausesenforcedaudit_events: kye.subprocessor.v1, kye.federation.cross_org_delegation.v1
engines: internal
constitution_refs: constitution/51-NO-SPOF.md
dora.A30.3Article 30(3) — Exit strategies in case of failure / terminationenforcedaudit_events: kye.compliance.attestation.v1, kye.spof.path_to_full.v1
engines: internal, internal
constitution_refs: constitution/51-NO-SPOF.md
dora.A31Article 31 — Designation of critical ICT third-party service providers (CTPPs) by the ESAs — direct EU-level oversightadvisoryconstitution_refs: constitution/51-NO-SPOF.md
dora.A32Article 32 — Tasks of the Lead Overseer in respect of CTPPsadvisoryconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A33Article 33 — Register of information on all contractual arrangements with ICT third-party providers — maintained, classified, reportable on demandenforcedaudit_events: kye.federation.cross_org_delegation.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/51-NO-SPOF.md, constitution/40-IMPLEMENTATION-CANONICAL.md
dora.A34Article 34 — Coordination among competent authorities + Lead Overseeradvisoryconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A35Article 35 — Powers of the Lead Overseer — request information, conduct general investigations, on-site inspectionsenforcedaudit_events: kye.evidence.pack.v1
engines: internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A36Article 36 — Exercise of Lead Overseer powers outside the Unionadvisoryconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A37Article 37 — Requests for information by Lead Overseerenforcedaudit_events: kye.evidence.pack.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A38Article 38 — General investigations conducted by Lead Overseeradvisoryaudit_events: kye.evidence.pack.v1
engines: internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A39Article 39 — On-site inspections — Lead Overseer's powersadvisoryconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A40Article 40 — Oversight framework for critical ICT third-party providers — Lead Overseer powers, joint examination team, recommendationsadvisoryconstitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/21-DELEGATED-AUDITABILITY.md
dora.A41Article 41 — Follow-up by competent authorities on Lead Overseer recommendationsadvisoryconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A42Article 42 — Cooperation among ESAs + competent authorities on third-party-risk mattersadvisoryconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
dora.A43Article 43 — Oversight fees levied on CTPPsadvisoryconstitution_refs: constitution/26-COMMERCIAL.md
dora.A44Article 44 — International cooperation — third-country regulator coordinationadvisoryconstitution_refs: constitution/21-DELEGATED-AUDITABILITY.md

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.