• Cybersecurity Glossary
DORA Compliance Checklist: 10 Steps for Financial Entities
A DORA compliance checklist is a structured list of the steps a financial entity takes to align with the Digital Operational Resilience Act, Regulation (EU) 2022/2554. It turns DORA’s Five pillars, ICT risk management, incident reporting, resilience testing, ICT third party risk and information sharing, into concrete technical tasks. This checklist sets out 10 actionable steps, maps each one to the pillar it serves, and shows the Teldat capability that supports it, from resilient SD-WAN connectivity to be.Safe Pro security and be.Safe XDR detection, all under European jurisdiction.
What a DORA checklist is?
A DORA compliance checklist is a practical way to turn a complex regulation into a set of concrete tasks. DORA, the Digital Operational Resilience Act, sets detailed requirements for how financial entities manage technology risk, and a checklist breaks those requirements down into steps a team can plan, assign and track.
The most useful checklists do more than restate the law. They connect each obligation to the technical capability that makes it real, so that a requirement like operational resilience becomes a concrete decision about redundant connectivity, and a requirement like fast incident reporting becomes a decision about monitoring and detection. This is what turns a checklist from a summary into an actionable plan.
The checklist on this page is technical rather than legal. It focuses on the network, security and resilience building blocks that underpin DORA, and shows where Teldat, as a European infrastructure manufacturer, supports each one. It does not replace legal advice or a full compliance program, but it helps ensure the technical foundations are sound.
Checklist mapped to the five pillars
DORA is organized into five pillars, and every item on a good checklist traces back to one of them. The table shows how the ten steps that follow map onto the pillars, so nothing essential is missed.
| DORA pillar | Articles | Checklist steps |
|---|---|---|
| ICT risk management | 5 to 16 | Steps 1, 2, 3, 4 |
| Incident management and reporting | 17 to 23 | Steps 5, 6 |
| Resilience testing | 24 to 27 | Step 7 |
| ICT third party risk | 28 to 30 | Steps 8, 9 |
| Information sharing | 45 to 49 | Step 10 |
The x10 step DORA checklist
These are the ten technical steps that underpin DORA compliance. Each step names the pillar it serves and the capability that delivers it, so the list works as an actionable plan rather than a summary.
How to use this checklist: work through the steps in order, since each builds on the previous, and treat steps 3, 4, 5 and 9 as the points where infrastructure choices directly shape compliance. Teldat’s combination of SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction supports those steps as a single European portfolio.
Incident reporting deadlines
Incident reporting is the most time critical part of any DORA checklist, so it deserves its own view. The table sets out the three stages and the clock for each, all of which depend on detecting the incident fast in the first place.
| Stage | Deadline | What it contains |
|---|---|---|
| Initial notification | Within 4 hours of classification | First alert that a major incident has occurred |
| Intermediate report | Within 72 hours | Updated detail on impact and response |
| Final report | Within one month | Root cause and remediation |
Why detection drives reporting: the 4 hour initial deadline starts once an incident is classified as major, so the real constraint is how fast you can detect and classify. Without strong monitoring, the clock is already running before anyone notices. This is why steps 5 and 6 of the checklist matter so much, and where extended detection and response such as Teldat be.Safe XDR makes the 4 hour deadline realistic.
How Teldat supports each step?
Teldat is not a compliance consultancy; it is a European manufacturer whose infrastructure maps directly onto the technical steps of the checklist. The table shows which Teldat capability supports which step, so the link between the checklist and the technology is explicit.
| Checklist step | Teldat capability |
|---|---|
| Resilient connectivity (step 3) | Teldat SD-WAN, self healing and redundant |
| Network and cloud security (step 4) | be.Safe Pro, Secure Web Gateway and NGFW |
| Detection and reporting (steps 5, 6) | be.Safe XDR, monitoring and detection |
| Third party and concentration risk (steps 8, 9) | European manufacturer under European jurisdiction |
One European partner across the checklist: because DORA’s technical steps span connectivity, security and detection, sourcing them from a single European manufacturer simplifies both the architecture and the third party register. Teldat combines SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction, supporting the checklist without certifying compliance itself, which remains the entity’s responsibility.
Common compliance gaps
Even entities that take DORA seriously tend to stumble on the same points. Knowing where the common gaps are helps a checklist catch them before an auditor does.
FAQ’s about the DORA checklist
❯ What is a DORA compliance checklist?
A DORA compliance checklist is a structured list of the steps a financial entity needs to take to align with the Digital Operational Resilience Act. It translates DORA’s five pillars, ICT risk management, incident reporting, resilience testing, ICT third party risk and information sharing, into concrete, actionable tasks. A good checklist links each requirement to the technical capability that supports it, such as resilient connectivity, layered security, monitoring and detection, so that compliance teams can see not only what DORA demands but how to meet it in practice. This page provides a 10 step technical checklist and shows how Teldat’s European infrastructure supports each step.
❯ Who needs to follow a DORA checklist?
Any financial entity in the scope of DORA benefits from a compliance checklist. That includes more than 22,000 entities across the EU, from banks, insurers and investment firms to payment institutions, electronic money institutions and crypto asset service providers, as well as their critical ICT third party providers. Larger entities follow the full framework, while microenterprises and certain smaller firms use a simplified ICT risk management framework under Article 16. A checklist helps all of them structure the work, but the technical fundamentals of resilient connectivity, strong security, monitoring and third party oversight apply across the board.
❯ What are the incident reporting deadlines in a DORA checklist?
Incident reporting is one of the most time sensitive items on any DORA checklist. For a major ICT related incident, DORA requires an initial notification to the competent authority within 4 hours of the incident being classified as major, an intermediate report within 72 hours, and a final report within one month. The 4 hour initial deadline is the tightest in EU regulation, which is why the checklist places so much weight on detection and monitoring: you can only report within 4 hours if you can detect and classify that fast, which is where extended detection and response such as Teldat be.Safe XDR contributes.
❯ How does Teldat support a DORA compliance checklist?
Teldat is a European infrastructure manufacturer whose portfolio maps directly onto the technical steps of a DORA checklist. Teldat SD-WAN provides the resilient, self healing connectivity behind operational resilience; be.Safe Pro delivers cloud security with Secure Web Gateway and Next Generation Firewall functions; and be.Safe XDR provides the monitoring and extended detection and response needed to meet DORA’s incident reporting clocks. Operating as a European manufacturer under European jurisdiction, Teldat also helps address the ICT third party and concentration risk pillar. Teldat does not certify compliance, but its sovereign infrastructure supports the technical steps the checklist covers.
❯ Is a DORA checklist enough to be compliant?
A checklist is a valuable tool for structuring the work, but it is not a substitute for a full compliance program or legal advice. DORA is a detailed regulation with obligations that depend on an entity’s size, risk profile and activities, and compliance ultimately rests with the entity and is assessed by competent authorities. A technical checklist like this one helps ensure the key building blocks, from resilient connectivity to incident reporting and third party oversight, are in place, but entities should combine it with governance, documentation and, where needed, specialist legal and audit support.
Work through the DORA checklist with Teldat
Teldat combines resilient SD-WAN connectivity, be.Safe Pro cloud security and be.Safe XDR detection and response as a European manufacturer under European jurisdiction, supporting the technical steps financial entities need for DORA.







