Readiness assessments
The first step to compliance is a current state assessment and gap analysis. This aims to understand the level of maturity of ICT and cyber risk management and identify gaps in compliance with the regulation. In many cases, organisations will be leveraging—or have implemented—existing frameworks or guidelines such as NIS2 or the EBA’s Guidelines on Operational Resilience and Cross-Industry Guidance on Outsourcing, which provide a starting point for compliance. However, DORA is more prescriptive than the existing operational resilience and cybersecurity guidelines. So, while these will be a useful starting point, they will not guarantee compliance with DORA.