Knowledge BaseOperating ModelTemplatesServicesAboutWork With Me
← All Templates
Operational Resilience

DORA Readiness Assessment

DORA is an operating-model regulation that got handed to IT. This assessment redistributes it: 62 requirements in plain language a COO can read, owned across the organization, with readiness percentages that compute from your honest statuses.

$299one-time · instant download · free updates
Get the Assessment See the Bundles
What you get
  • 62 requirements across all five pillars, cited to DORA articles
  • Plain-language paraphrases — readable by the executives who must own them
  • Proportionality built in: mark rows out of scope with reasons; the math excludes them
  • Per-pillar readiness % with Strong / Developing / At Risk bands
  • 200-row gap register with owners, target dates, and overdue flags
  • Excel (.xlsx) · no macros · also opens in Google Sheets & LibreOffice
Why this assessment

If every requirement is owned by the CISO, that's your first gap.

DORA reaches governance, incident reporting, resilience testing, and third-party contracts — most of which no IT function can implement alone. This workbook decomposes the regulation into requirements that route to their natural owners: the board obligations to the corporate secretary, the register of information to procurement, the testing program to resilience, the notification clocks to compliance. The worked example state deliberately spans COO, Legal, Procurement, Compliance, and Risk — because that's what a credible answer looks like.

What's inside

Five pillars, one honest number each.

Requirements Assessment

ICT risk management (Art. 5–14), incident management & reporting (Art. 17–23), resilience testing (Art. 24–27), third-party risk incl. the register of information (Art. 28–30), and information sharing (Art. 45).

Proportionality Scoping

Not every requirement applies to every entity. Mark rows out of scope with a documented reason — they gray out and leave the math, defensibly.

Readiness Dashboard

Per-pillar readiness percentages (partial credit for partial implementation), the not-implemented list, and gap counts — computed, not asserted.

Gap Register

Every gap gets an owner, an action, a target date, and an overdue flag — the same remediation discipline as the rest of the PivotRisk line.

Accuracy Discipline

Citations at article level only — specific enough to navigate the regulation, stable enough not to rot as technical standards evolve.

Start Here & Glossary

The walkthrough, the readiness math documented, and every column defined.

The thinking: DORA Is Not an IT Problem and The Vendor Behind Your Vendor.

FAQ

Before you buy

What format is it?

A single Microsoft Excel workbook (.xlsx). No macros; recalculates on open; also opens in Google Sheets and LibreOffice.

Is this legal advice or a complete compliance program?

Neither. It's a structured, article-cited self-assessment that shows you where you stand and what to fix first. Scope determinations — especially proportionality and TLPT designation — belong with your compliance function and regulator.

Does it cover the technical standards (RTS/ITS)?

Deliberately not below article level — sub-regulatory detail changes faster than any template should pretend to track. The workbook gets you organized at the level that endures; your compliance monitoring handles the moving parts.

Can I use it with clients?

Yes — internally or in client engagements. You can't resell the template itself as a template.

Know where you stand before the examiner asks

Five pillars, honest statuses, owned gaps — one workbook.

Get the Assessment — $299 Or get it in a Bundle