Compliance / DORA

Operational resilience, shown article by article.

DORA asks you to manage ICT risk, report major incidents and keep a register of every ICT arrangement. RegNext works from the text itself: the criteria that classify an incident, the tests that make a function critical, the templates your register must follow.

Regulation (EU) 2022/2554Applies since 17 January 2025Financial entities and their ICT providers
From the criteriamajor or not, decided by the tests the rules set
Datedeach report’s deadline worked out from the rules
EBA templatesthe register of information, checked before you export it
A person decidesevery verdict is confirmed; an override needs a note

What it asks

What DORA asks of you — and where RegNext takes it on.

DORA rests on a few pillars. Here is what each one asks of a financial entity, in plain words — and what RegNext does about it.

01

ICT risk management

A framework to identify, protect, detect, respond and recover, owned by the management body — with the functions your business depends on, and the ICT assets behind them, identified and classified.

Articles 5–16
In RegNext

Start from a set of controls and readiness questions drawn from DORA, for the full or the simplified regime. Record your business functions and ICT assets, test your controls, and see which risks rely on a control that isn’t shown to work.

02

ICT-related incidents

Record and classify ICT-related incidents against the criteria the rules set, and report the major ones to your authority: an initial notification, an intermediate report and a final report.

Articles 17–23
In RegNext

Answer the classification criteria one by one. RegNext proposes the verdict, a person confirms it, and the three reports are dated — their content prepared in the template’s fields.

03

Resilience testing

A testing programme for your ICT systems and tools — and, for the firms their authority designates, advanced threat-led penetration testing.

Articles 24–27
Not covered yet

RegNext doesn’t plan or run resilience tests. The DORA starter controls include your testing programme, so you can follow it like any other control.

04

ICT third-party risk

A strategy for ICT third-party risk, contracts that carry the provisions the regulation lists, exit strategies, and a register of information on every arrangement with an ICT provider.

Articles 28–30
In RegNext

Each ICT contract carries the fields of the register and a check of the provisions DORA requires — met, partial or missing. Critical functions are assessed, and the register of information is exported in the EBA templates.

Major incidents

Major or not — decided by the criteria the rules set.

Answer the seven criteria one by one: clients affected, reputational impact, duration, geographical spread, data losses, critical services and economic impact. RegNext proposes the verdict, says “undetermined” when a missing answer could change it, and dates each report once a person confirms.

Each criterion quotedWith the legal text it comes from.
Three reports, datedInitial, intermediate and final.
In the template’s fieldsEach report’s content prepared stage by stage.
GDPR on the same incidentIf personal data is involved, a breach assessment with its own clock.

Register of information

A register of information built from what you already record.

Your ICT contracts, the functions they support and whether those functions are critical feed the register, template by template. RegNext checks mandatory fields, formats, code lists and the links between templates, lists what still needs fixing, and exports the register in the EBA formats.

Built, not retypedFrom your suppliers, contracts and functions.
CheckedErrors, missing values and points to review, listed.
ExportedOne file per template, or the EBA reporting package.
Contract provisionsWhat DORA requires in each contract, marked met, partial or missing.

Critical or important functions

Which functions are critical — and what they rely on.

For each business function, answer the regulation’s own tests, quoted word for word. RegNext gives the verdict with your reasons and the date, and maps the function to the ICT assets and providers behind it.

The legal testsQuoted from the regulation.
Reasons keptEach verdict dated, with why.
Assets and recoveryThe ICT assets behind each function, and its recovery objectives.
Into the registerCriticality flows into the register of information.

ICT risk management

Start from the regulation, not from a blank page.

Install a starter set of controls and readiness questions drawn from DORA — for the full or the simplified regime. Each control carries its status, its applicability and its tests, and a risk that relies on a control not shown to work is flagged.

Full or simplifiedThe set that matches the regime you declare.
Status per frameworkNot in place, untested, effective or not effective.
TestsPlanned, recorded and flagged when overdue.
When the law changesControls tied to a changed requirement are flagged.

Questions

Questions DORA teams ask.

Does RegNext submit our reports or our register?

No. It classifies incidents, dates each report, prepares its content and exports the register of information in the EBA formats. You submit them through your authority’s own channel.

Can we use the simplified regime?

You declare the regime that applies to you — full, or simplified under Article 16 — and RegNext shows the matching starter set. The article’s list of eligible entities is shown word for word; the eligibility call stays yours.

Do we still need to report under NIS2?

Not for the same incident. For financial entities under DORA, DORA’s rules on ICT risk management and incident reporting apply instead of NIS2’s, and RegNext doesn’t ask you to report twice.

Where do the criteria and tests come from?

From DORA and the technical standards that complete it. Each criterion and test quotes its text, and every requirement cites the article it comes from.

image of brainstorming session for a productivity tools business

Transform compliance.
Accelerate outcomes.

Explore how RegNext supports regulatory intelligence and compliance execution in your industry.