Executive self-assessment

DORA Readiness Assessment

Measure whether ICT risk and operational resilience are governed and evidenced well enough to meet DORA-driven expectations.

Result logic

What this tool evaluates

Evaluates ICT risk, incidents, resilience testing, continuity, third parties, contracts, evidence, and governance.

ICT risk governance 22%
Incident governance 18%
Resilience testing 22%
ICT third parties 23%
Evidence & oversight 15%
0 / 10
0%
01 Is ICT risk governed through a defined framework with accountable executive ownership?
02 Are critical ICT services, assets, dependencies, and risk scenarios identified and reviewed?
03 Are ICT incidents classified, escalated, investigated, and recorded using defined criteria?
04 Are incident exercises and lessons linked to corrective actions and ownership?
05 Are business continuity and disaster recovery plans tested against realistic service dependencies?
06 Is resilience testing risk-based, scheduled, evidenced, and reviewed by accountable leadership?
07 Are critical ICT providers inventoried, tiered, risk-reviewed, and connected to business services?
08 Do critical-provider contracts address security, resilience, incidents, audit/access, subcontracting, and exit needs?
09 Are concentration and substitutability risks understood for critical ICT dependencies?
10 Can management demonstrate current ICT risk, resilience, incidents, third-party exposure, and remediation status?