agentsclimarketplace

Eu dora compliance

Skill BuilderCed/agent-skills/skills/compliance/eu-dora-compliance

31 cross-platform AI agent skills for regulated industries & underserved markets. EU compliance (AI Act, NIS2, DORA, GDPR), French professional (accounting, tax, notary, real estate), security audit, agent evaluation, Africa mobile money, offline-first.

Install
npx -y skills add BuilderCed/agent-skills --skill eu-dora-compliance

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Implement DORA Regulation (2022/2554) digital operational resilience for financial entities — ICT risk management, incident reporting, resilience testing, third-party risk.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

4.4 KB, as published. Nobody here has run it

EU DORA Compliance (Digital Operational Resilience Act)

DISCLAIMER: This skill provides guidance only. It does not constitute legal or financial advice. Always verify with qualified professionals.

When to Use

  • Building software for financial institutions in the EU
  • Assessing ICT risk management for fintech
  • Setting up ICT incident reporting for financial entities
  • Designing resilience testing programs
  • Managing third-party ICT service provider relationships

Scope — Who Is Affected?

DORA applies to virtually all EU financial entities:

CategoryEntities
BankingCredit institutions, payment institutions, e-money institutions
InvestmentInvestment firms, trading venues, central securities depositories
InsuranceInsurance/reinsurance undertakings, intermediaries
PensionIORPs (Institutions for Occupational Retirement Provision)
CryptoCrypto-asset service providers (MiCA-regulated)
InfrastructureCCPs, trade repositories, securitization repositories
OtherCredit rating agencies, crowdfunding providers, data reporting services
ICT providersThird-party ICT service providers to the above (critical designation)

5 Pillars of DORA

Pillar 1: ICT Risk Management (Articles 5-16)

Establish an ICT risk management framework:

  • Identify all ICT assets, risks, dependencies
  • Protect through security policies, access controls, encryption
  • Detect anomalies and incidents via continuous monitoring
  • Respond with incident response and crisis communication plans
  • Recover with backup policies, restoration procedures, lessons learned

Pillar 2: ICT Incident Reporting (Articles 17-23)

Classify and report major ICT-related incidents:

CriterionThreshold for Major
Clients affected> 10% of clients or significant clients
Duration> 2 hours for critical services
Geographic spread> 2 member states
Data lossIntegrity, confidentiality, or availability compromised
Economic impactMaterial financial loss
Criticality of servicesCore banking, payment processing, trading

Reporting timeline:

  • Initial notification: within 4 hours of classification as major
  • Intermediate report: within 72 hours
  • Final report: within 1 month

Pillar 3: Digital Operational Resilience Testing (Articles 24-27)

Test TypeFrequencyWho
Vulnerability assessmentsAt least annuallyAll entities
Network security testingAt least annuallyAll entities
Scenario-based testingAt least annuallyAll entities
Threat-Led Penetration Testing (TLPT)At least every 3 yearsSignificant entities only

TLPT must be conducted by qualified external testers following the TIBER-EU framework.

Pillar 4: Third-Party ICT Risk (Articles 28-44)

For all ICT third-party service providers:

  • Maintain a register of all ICT service agreements
  • Conduct pre-contract due diligence
  • Include mandatory contractual clauses (audit rights, exit strategies, data location)
  • Monitor ongoing compliance
  • Have exit plans for critical providers

Critical ICT third-party providers (designated by ESAs) face direct EU oversight.

Pillar 5: Information Sharing (Article 45)

Financial entities may participate in voluntary information-sharing arrangements on:

  • Cyber threat intelligence
  • Indicators of compromise
  • Tactics, techniques, and procedures (TTPs)
  • Security alerts and configuration tools

Key Date

  • 17 January 2025: DORA fully applicable

What This Skill Does NOT Do

  • Does not conduct penetration testing or TLPT
  • Does not configure ICT security tools
  • Does not manage third-party provider contracts
  • Does not replace compliance officer or legal counsel

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.