Logo Teldat

• Cybersecurity Glossary

DORA Compliance Checklist: 10 Steps for Financial Entities

A DORA compliance checklist is a structured list of the steps a financial entity takes to align with the Digital Operational Resilience Act, Regulation (EU) 2022/2554. It turns DORA’s Five pillars, ICT risk management, incident reporting, resilience testing, ICT third party risk and information sharing, into concrete technical tasks. This checklist sets out 10 actionable steps, maps each one to the pillar it serves, and shows the Teldat capability that supports it, from resilient SD-WAN connectivity to be.Safe Pro security and be.Safe XDR detection, all under European jurisdiction.

What a DORA checklist is?

A DORA compliance checklist is a practical way to turn a complex regulation into a set of concrete tasks. DORA, the Digital Operational Resilience Act, sets detailed requirements for how financial entities manage technology risk, and a checklist breaks those requirements down into steps a team can plan, assign and track.

The most useful checklists do more than restate the law. They connect each obligation to the technical capability that makes it real, so that a requirement like operational resilience becomes a concrete decision about redundant connectivity, and a requirement like fast incident reporting becomes a decision about monitoring and detection. This is what turns a checklist from a summary into an actionable plan.

The checklist on this page is technical rather than legal. It focuses on the network, security and resilience building blocks that underpin DORA, and shows where Teldat, as a European infrastructure manufacturer, supports each one. It does not replace legal advice or a full compliance program, but it helps ensure the technical foundations are sound.

Checklist mapped to the five pillars

DORA is organized into five pillars, and every item on a good checklist traces back to one of them. The table shows how the ten steps that follow map onto the pillars, so nothing essential is missed.

DORA pillar Articles Checklist steps
ICT risk management 5 to 16 Steps 1, 2, 3, 4
Incident management and reporting 17 to 23 Steps 5, 6
Resilience testing 24 to 27 Step 7
ICT third party risk 28 to 30 Steps 8, 9
Information sharing 45 to 49 Step 10

The x10 step DORA checklist

These are the ten technical steps that underpin DORA compliance. Each step names the pillar it serves and the capability that delivers it, so the list works as an actionable plan rather than a summary.

1
Establish an ICT risk management framework
Put in place a documented framework governed by the management body, covering identification, protection, detection, response and recovery. This is the foundation of DORA’s first pillar and the backbone the rest of the checklist hangs from. Pillar: ICT risk management.
2
Map and classify ICT assets
Maintain an inventory of ICT assets, systems and their interdependencies so you know what supports each critical function and where risk concentrates. You cannot protect or test what you have not mapped, which makes this an early, essential step. Pillar: ICT risk management.
3
Build resilient, redundant connectivity
Keep critical services available through disruptions with redundant, self healing connectivity. Teldat SD-WAN delivers this resilience at the network layer, so a link or site failure does not become a service outage. Capability: Teldat SD-WAN. Pillar: ICT risk management.
4
Deploy layered network and cloud security
Protect how users and branches reach the internet and cloud with layered security. Teldat be.Safe Pro provides cloud security with Secure Web Gateway and Next Generation Firewall functions, a core protective control under the first pillar. Capability: Teldat be.Safe Pro. Pillar: ICT risk management.
5
Implement detection, monitoring and XDR
Deploy monitoring and extended detection and response to spot incidents fast. Teldat be.Safe XDR correlates signals across the network so incidents are detected and classified quickly enough to start the reporting clock on time. Capability: Teldat be.Safe XDR. Pillar: Incident management.
6
Define incident classification and reporting
Establish a process to classify major ICT incidents and report them on DORA’s timelines: 4 hours initial, 72 hours intermediate, one month final. Clear runbooks and timestamped records make these deadlines achievable and auditable. Pillar: Incident management and reporting.
7
Run a resilience testing program
Test resilience regularly with vulnerability assessments and, for significant entities, threat led penetration testing. Testing turns assumptions about resilience into evidence, which is exactly what DORA’s third pillar requires. Pillar: Digital operational resilience testing.
8
Manage ICT third party risk
Maintain a register of information on ICT third party providers, apply contractual controls and assess concentration risk. This is the pillar with the highest rate of compliance gaps, so it deserves close attention. Pillar: ICT third party risk management.
9
Prefer european, sovereign infrastructure
Reduce third party and concentration risk by choosing infrastructure operating under European jurisdiction. As a European manufacturer, Teldat offers a sovereign option aligned with EU oversight for connectivity and security. Capability: Teldat European portfolio. Pillar: ICT third party risk.
10
Enable information sharing and governance
Participate in cyber threat information sharing and keep the management body accountable for ICT risk. This closes DORA’s fifth pillar and reinforces the governance that ties the whole framework together. Pillar: Information sharing.

How to use this checklist: work through the steps in order, since each builds on the previous, and treat steps 3, 4, 5 and 9 as the points where infrastructure choices directly shape compliance. Teldat’s combination of SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction supports those steps as a single European portfolio.

Incident reporting deadlines

Incident reporting is the most time critical part of any DORA checklist, so it deserves its own view. The table sets out the three stages and the clock for each, all of which depend on detecting the incident fast in the first place.

Stage Deadline What it contains
Initial notification Within 4 hours of classification First alert that a major incident has occurred
Intermediate report Within 72 hours Updated detail on impact and response
Final report Within one month Root cause and remediation

Why detection drives reporting: the 4 hour initial deadline starts once an incident is classified as major, so the real constraint is how fast you can detect and classify. Without strong monitoring, the clock is already running before anyone notices. This is why steps 5 and 6 of the checklist matter so much, and where extended detection and response such as Teldat be.Safe XDR makes the 4 hour deadline realistic.

How Teldat supports each step?

Teldat is not a compliance consultancy; it is a European manufacturer whose infrastructure maps directly onto the technical steps of the checklist. The table shows which Teldat capability supports which step, so the link between the checklist and the technology is explicit.

Checklist step Teldat capability
Resilient connectivity (step 3) Teldat SD-WAN, self healing and redundant
Network and cloud security (step 4) be.Safe Pro, Secure Web Gateway and NGFW
Detection and reporting (steps 5, 6) be.Safe XDR, monitoring and detection
Third party and concentration risk (steps 8, 9) European manufacturer under European jurisdiction

One European partner across the checklist: because DORA’s technical steps span connectivity, security and detection, sourcing them from a single European manufacturer simplifies both the architecture and the third party register. Teldat combines SD-WAN, be.Safe Pro and be.Safe XDR under European jurisdiction, supporting the checklist without certifying compliance itself, which remains the entity’s responsibility.

Common compliance gaps

Even entities that take DORA seriously tend to stumble on the same points. Knowing where the common gaps are helps a checklist catch them before an auditor does.

1
Underestimating the third party register
The register of information on ICT third parties is often incomplete, yet it is central to the fourth pillar and a focus of supervision. Mapping every provider, and reducing their number where possible, is one of the highest value items on the checklist.
2
Treating reporting as a paperwork task
The 4 hour clock cannot be met by a reporting template alone; it depends on detection. Entities that focus on the report format but neglect monitoring find they simply cannot start the process in time, which is why detection sits so early in the checklist.
3
Forgetting resilience is a network property
Operational resilience is sometimes treated as an application concern, but if the underlying connectivity is not redundant, a single link failure can still take services down. Building resilience into the network with SD-WAN addresses the requirement at its root.
4
Overlooking jurisdiction in supplier choice
Where infrastructure is operated, and under whose jurisdiction, is part of third party and concentration risk. Choosing European infrastructure is an easy win the checklist can capture, and one that aligns naturally with the sovereignty goals behind DORA.

FAQ’s about the DORA checklist

❯ What is a DORA compliance checklist?

A DORA compliance checklist is a structured list of the steps a financial entity needs to take to align with the Digital Operational Resilience Act. It translates DORA’s five pillars, ICT risk management, incident reporting, resilience testing, ICT third party risk and information sharing, into concrete, actionable tasks. A good checklist links each requirement to the technical capability that supports it, such as resilient connectivity, layered security, monitoring and detection, so that compliance teams can see not only what DORA demands but how to meet it in practice. This page provides a 10 step technical checklist and shows how Teldat’s European infrastructure supports each step.

❯ Who needs to follow a DORA checklist?

Any financial entity in the scope of DORA benefits from a compliance checklist. That includes more than 22,000 entities across the EU, from banks, insurers and investment firms to payment institutions, electronic money institutions and crypto asset service providers, as well as their critical ICT third party providers. Larger entities follow the full framework, while microenterprises and certain smaller firms use a simplified ICT risk management framework under Article 16. A checklist helps all of them structure the work, but the technical fundamentals of resilient connectivity, strong security, monitoring and third party oversight apply across the board.

❯ What are the incident reporting deadlines in a DORA checklist?

Incident reporting is one of the most time sensitive items on any DORA checklist. For a major ICT related incident, DORA requires an initial notification to the competent authority within 4 hours of the incident being classified as major, an intermediate report within 72 hours, and a final report within one month. The 4 hour initial deadline is the tightest in EU regulation, which is why the checklist places so much weight on detection and monitoring: you can only report within 4 hours if you can detect and classify that fast, which is where extended detection and response such as Teldat be.Safe XDR contributes.

❯ How does Teldat support a DORA compliance checklist?

Teldat is a European infrastructure manufacturer whose portfolio maps directly onto the technical steps of a DORA checklist. Teldat SD-WAN provides the resilient, self healing connectivity behind operational resilience; be.Safe Pro delivers cloud security with Secure Web Gateway and Next Generation Firewall functions; and be.Safe XDR provides the monitoring and extended detection and response needed to meet DORA’s incident reporting clocks. Operating as a European manufacturer under European jurisdiction, Teldat also helps address the ICT third party and concentration risk pillar. Teldat does not certify compliance, but its sovereign infrastructure supports the technical steps the checklist covers.

❯ Is a DORA checklist enough to be compliant?

A checklist is a valuable tool for structuring the work, but it is not a substitute for a full compliance program or legal advice. DORA is a detailed regulation with obligations that depend on an entity’s size, risk profile and activities, and compliance ultimately rests with the entity and is assessed by competent authorities. A technical checklist like this one helps ensure the key building blocks, from resilient connectivity to incident reporting and third party oversight, are in place, but entities should combine it with governance, documentation and, where needed, specialist legal and audit support.

Work through the DORA checklist with Teldat

Teldat combines resilient SD-WAN connectivity, be.Safe Pro cloud security and be.Safe XDR detection and response as a European manufacturer under European jurisdiction, supporting the technical steps financial entities need for DORA.