Compliance / DORA
DORA asks you to manage ICT risk, report major incidents and keep a register of every ICT arrangement. RegNext works from the text itself: the criteria that classify an incident, the tests that make a function critical, the templates your register must follow.
What it asks
DORA rests on a few pillars. Here is what each one asks of a financial entity, in plain words — and what RegNext does about it.
A framework to identify, protect, detect, respond and recover, owned by the management body — with the functions your business depends on, and the ICT assets behind them, identified and classified.
Articles 5–16Start from a set of controls and readiness questions drawn from DORA, for the full or the simplified regime. Record your business functions and ICT assets, test your controls, and see which risks rely on a control that isn’t shown to work.
Record and classify ICT-related incidents against the criteria the rules set, and report the major ones to your authority: an initial notification, an intermediate report and a final report.
Articles 17–23Answer the classification criteria one by one. RegNext proposes the verdict, a person confirms it, and the three reports are dated — their content prepared in the template’s fields.
A testing programme for your ICT systems and tools — and, for the firms their authority designates, advanced threat-led penetration testing.
Articles 24–27RegNext doesn’t plan or run resilience tests. The DORA starter controls include your testing programme, so you can follow it like any other control.
A strategy for ICT third-party risk, contracts that carry the provisions the regulation lists, exit strategies, and a register of information on every arrangement with an ICT provider.
Articles 28–30Each ICT contract carries the fields of the register and a check of the provisions DORA requires — met, partial or missing. Critical functions are assessed, and the register of information is exported in the EBA templates.
Major incidents
Answer the seven criteria one by one: clients affected, reputational impact, duration, geographical spread, data losses, critical services and economic impact. RegNext proposes the verdict, says “undetermined” when a missing answer could change it, and dates each report once a person confirms.
Register of information
Your ICT contracts, the functions they support and whether those functions are critical feed the register, template by template. RegNext checks mandatory fields, formats, code lists and the links between templates, lists what still needs fixing, and exports the register in the EBA formats.
Critical or important functions
For each business function, answer the regulation’s own tests, quoted word for word. RegNext gives the verdict with your reasons and the date, and maps the function to the ICT assets and providers behind it.
ICT risk management
Install a starter set of controls and readiness questions drawn from DORA — for the full or the simplified regime. Each control carries its status, its applicability and its tests, and a risk that relies on a control not shown to work is flagged.
Questions
No. It classifies incidents, dates each report, prepares its content and exports the register of information in the EBA formats. You submit them through your authority’s own channel.
You declare the regime that applies to you — full, or simplified under Article 16 — and RegNext shows the matching starter set. The article’s list of eligible entities is shown word for word; the eligibility call stays yours.
Not for the same incident. For financial entities under DORA, DORA’s rules on ICT risk management and incident reporting apply instead of NIS2’s, and RegNext doesn’t ask you to report twice.
From DORA and the technical standards that complete it. Each criterion and test quotes its text, and every requirement cites the article it comes from.
Recorded once
An ICT provider can also be a processor under GDPR or a supplier under NIS2, and a major incident can also be a personal-data breach. RegNext records each once and shows it under every framework that applies.
Significant incidents, the measures of Article 21 and your supply chain.
NIS2 AI ActAn inventory, a risk class you confirm and the duties that follow.
AI Act GDPRRecords of processing, DPIA screening, requests and breaches.
GDPR OverviewRisks, controls, policies, incidents and suppliers, shared across every framework.
Compliance
Explore how RegNext supports regulatory intelligence and compliance execution in your industry.