Updated 2026-07-22
What belongs on a DORA readiness checklist?
Use this as a conversation starter with compliance, security, and engineering. It is indicative planning input — not certification criteria and not legal advice.
How do you check governance and ownership?
Confirm someone at management-body level is accountable for ICT risk oversight, with a recurring reporting slot and policies that match how you actually operate.
- Named ICT risk owner with a recurring reporting slot
- Policies and standards that match how you actually operate
- Risk register reviewed on a known cadence
How do you check incidents and communication?
Make sure detection and escalation do not depend on heroics: written severity criteria, a single incident log, and drafted notification paths for major scenarios.
- Written severity / classification criteria
- Single incident log with root cause and resolution fields
- Draft notification and communications paths for major scenarios
How do you check testing and learning?
Schedule resilience tests and close the loop on findings: documented scope and outcomes for each exercise, plus tracked follow-ups owned by named teams.
- Annual (or more frequent) scenario / tabletop exercises
- Documented scope and outcomes for each test
- Tracked follow-ups owned by named teams
How do you check third parties and evidence?
Know critical ICT dependencies before someone asks: inventory, criticality classification, contract gap list, and a central place for core evidence packs.
- Inventory of ICT providers and subcontracting chains
- Criticality classification tied to business impact
- Contract gaps list for audit rights, incident notice, and exit
- Central place for policies, registers, test reports, and incident history
How do you turn the checklist into a scored baseline?
Take the free CodeGeeks DORA readiness self-assessment for an indicative overall score, pillar breakdown, and top gaps in one sitting — then unlock a remediation roadmap when you are ready.