---
title: "DORA deadlines and compliance calendar for financial entities"
canonical_url: "https://www.sorena.io/artifacts/eu/digital-operational-resilience-act/deadlines-and-compliance-calendar"
source_url: "https://www.sorena.io/artifacts/eu/digital-operational-resilience-act/deadlines-and-compliance-calendar"
author: "Sorena AI"
description: "Calendar the official source DORA dates and recurring evidence: 17 January 2025 application, incident reporting clocks, register updates, annual reporting, TLPT cadence, and CTPP oversight milestones."
published_at: "2026-05-09"
updated_at: "2026-05-09"
keywords:
  - "EU DORA"
  - "DORA deadlines"
  - "DORA compliance calendar"
  - "major ICT incident reporting"
  - "register of information"
  - "TLPT"
  - "DORA"
  - "compliance calendar"
  - "major ICT incidents"
  - "critical ICT third-party providers"
---
**[SORENA](https://www.sorena.io/)** - AI-Powered GRC Platform

[Home](https://www.sorena.io/) | [Solutions](https://www.sorena.io/solutions) | [Artifacts](https://www.sorena.io/artifacts) | [About Us](https://www.sorena.io/about-us) | [Contact](https://www.sorena.io/contact) | [Portal](https://app.sorena.io)

---

# DORA deadlines and compliance calendar for financial entities

Calendar the official source DORA dates and recurring evidence: 17 January 2025 application, incident reporting clocks, register updates, annual reporting, TLPT cadence, and CTPP oversight milestones.

*Compliance Calendar* *EU*

## EU DORA deadlines and compliance calendar

This page helps calendar cited DORA dates and recurring evidence work for financial entities: application, incident reporting, register of information, annual reporting, TLPT, and critical ICT third-party oversight.

The dates below are based on DORA, delegated and implementing regulations, and ESA publications. They are not a substitute for the competent authority calendar that applies to a specific financial entity.

DORA calendar work should separate fixed legal dates from event-triggered clocks. The fixed anchor is 17 January 2025, when Regulation (EU) 2022/2554 applies. After that, most useful calendar entries are recurring or trigger-based: major ICT incident reporting clocks, register-of-information updates and annual reporting, TLPT cycles for identified entities, and oversight milestones for critical ICT third-party providers.

## Fixed DORA dates to put on the compliance calendar

Start the calendar with the legal application date and the implementation instruments that change how teams report or maintain evidence. DORA was published in the Official Journal on 27 December 2022, entered into force on 16 January 2023, and applies from 17 January 2025.

For evidence planning, keep separate calendar rows for the 2024 register templates, the 2025 major incident reporting RTS and ITS, the 2025 TLPT criteria RTS, and the ESA publication of the first list of designated critical ICT third-party providers. These milestones do not replace entity-specific supervisory submissions, but they explain which template, clock, or oversight framework the entity should be using.

- 27 December 2022: DORA was published in the Official Journal.
- 16 January 2023: DORA entered into force.
- 2 December 2024: Implementing Regulation (EU) 2024/2956 on register-of-information templates was published in the Official Journal.
- 17 January 2025: DORA applies.
- 20 February 2025: Delegated Regulation (EU) 2025/301 on major incident notification and report time limits, and Implementing Regulation (EU) 2025/302 on reporting forms, templates, and procedures, were published in the Official Journal.
- 13 February 2025: Delegated Regulation (EU) 2025/1190 set TLPT identification criteria and TLPT process requirements.
- 18 November 2025: the ESAs published the first list of designated critical ICT third-party providers under DORA.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Supports the DORA publication, entry-into-force, and 17 January 2025 application anchors.
- [Implementing Regulation (EU) 2024/2956 on register templates](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2956&ref=sorena.io) - Supports the 2 December 2024 register-of-information template milestone and the standard template basis for register evidence.
- [Delegated Regulation (EU) 2025/301 on incident report time limits](https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng?ref=sorena.io) - Supports the 20 February 2025 incident-reporting RTS milestone and the reporting clocks used later on this page.

## Event-triggered major ICT incident reporting clocks

Do not calendar major incident reporting as a single annual date. Calendar it as a playbook clock that starts when an ICT-related incident is detected, assessed, and classified as major under the DORA incident-classification rules.

Delegated Regulation (EU) 2025/301 sets the time limits. The initial notification is due as early as possible, within four hours from classification as major, and no later than 24 hours from when the financial entity became aware of the incident. If the entity classifies the incident as major only after the first 24 hours, the initial notification is due within four hours from that later classification. The intermediate report is due within 72 hours from the initial notification. The final report is due no later than one month after the intermediate report, or after the latest updated intermediate report.

- Calendar trigger: incident detected, awareness time recorded, classification assessment opened, and major-incident classification time recorded.
- Initial notification evidence: detection time, classification time, classification criteria, affected entity information, contact points, description, and available impact data.
- Intermediate report evidence: updated incident status, impact, mitigation and recovery actions, and any change since the initial notification.
- Final report evidence: resolution dates and times, root cause, costs and losses where applicable, resolution information, and recurring-incident information where applicable.
- Dependency to track: Implementing Regulation (EU) 2025/302 supplies the reporting templates and allows combined submissions only where recovery or root-cause analysis is complete and the Delegated Regulation (EU) 2025/301 time limits are still met.
- Exception handling: if a deadline cannot be met, record the notice to the competent authority, the reason for delay, and whether a weekend or bank-holiday rule is available for that entity type.

Sources for this answer:

- [Delegated Regulation (EU) 2025/301 on incident report time limits](https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng?ref=sorena.io) - Supports the four-hour, 24-hour, 72-hour, and one-month reporting clocks for major ICT-related incidents.
- [Implementing Regulation (EU) 2025/302 on incident reporting templates](https://eur-lex.europa.eu/eli/reg_impl/2025/302/oj/eng?ref=sorena.io) - Supports the use of standard forms, templates, secure electronic channels, outsourcing notices, reclassification notices, and combined submissions for DORA incident reporting.
- [Delegated Regulation (EU) 2024/1772 on ICT incident classification](https://eur-lex.europa.eu/eli/reg_del/2024/1772/oj/eng?ref=sorena.io) - Supports the incident-classification dependency before the major-incident reporting clocks can be applied.

## Register-of-information and third-party risk calendar

The register calendar has two layers: an always-current operational register and the reporting rhythm required by DORA. DORA requires financial entities to maintain and update, at entity level and at sub-consolidated and consolidated levels, a register of information for all contractual arrangements on the use of ICT services provided by ICT third-party service providers.

DORA also requires at least yearly reporting to competent authorities on new ICT service arrangements, provider categories, contractual arrangement types, and the ICT services and functions provided. The register should therefore be updated when a contract starts, changes, ends, a supporting function becomes critical or important, or a subcontracting chain changes, and reviewed before the annual reporting cycle.

- Standing owner: ICT third-party risk or outsourcing owner maintains the register, with legal, procurement, technology, and business-service inputs.
- Calendar triggers: new ICT service contract, contract amendment, exit or termination, supplier change, intra-group ICT service change, subcontractor change, or a function becoming critical or important.
- Annual reporting evidence: count of new arrangements, ICT third-party service provider categories, contractual arrangement types, ICT services, and supported functions.
- Template evidence: contractual arrangement reference number, financial entity LEI and country, date of last update, date of integration, start date of contractual arrangement, ICT service type, and critical-or-important function indicators where required by the template.
- Authority-request evidence: the full register, specified sections of the register, and supporting information needed for effective supervision.
- Template maintenance: track the 19 September 2025 corrigendum to Implementing Regulation (EU) 2024/2956 when validating register template fields.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Supports the obligation to maintain and update the register and report at least yearly to competent authorities.
- [Implementing Regulation (EU) 2024/2956 on register templates](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2956&ref=sorena.io) - Supports the standard register template fields and relational structure used for DORA register evidence.
- [Corrigendum to Implementing Regulation (EU) 2024/2956](https://eur-lex.europa.eu/eli/reg_impl/2024/2956/corrigendum/2025-09-19/oj/eng?ref=sorena.io) - Supports the September 2025 register-template corrigendum milestone for template maintenance checks.

## TLPT and resilience testing cadence

DORA creates both general resilience-testing cadence and advanced TLPT cadence. Financial entities other than microenterprises must ensure, at least yearly, appropriate tests on all ICT systems and applications supporting critical or important functions. Identified financial entities must also carry out advanced testing by means of TLPT at least every three years, unless the competent authority changes the frequency based on risk profile and operational circumstances.

For TLPT, the compliance calendar should start when the TLPT authority notifies the financial entity that a TLPT is to be carried out. Delegated Regulation (EU) 2025/1190 then creates planning and closure dependencies: initiation information within three months of notification, scope specification within six months of notification, active red team testing lasting at least 12 weeks, red team report within four weeks after active testing ends, blue team report and replay/purple teaming no later than 10 weeks after active testing ends, and the summary report and remediation documentation within eight weeks of the relevant TLPT authority notification.

- Annual testing row: test ICT systems and applications supporting critical or important functions, log findings, remediation ownership, validation evidence, and management review.
- Three-year TLPT row for identified entities: maintain the next TLPT due date, competent-authority frequency changes, and whether the prior test used internal or external testers.
- Authority notification trigger: open TLPT initiation tasks, project charter, control team, tester and threat-intelligence provider procurement, communication channels, and code name.
- Scope dependency: include several or all critical or important functions and live production systems supporting those functions; competent authorities validate the TLPT scope.
- Closure evidence: red team report, blue team report, replay and purple teaming outcomes, summary findings report, remediation plan, and TLPT attestation records.
- Tester dependency: DORA requires external testers at least every three tests when the entity uses internal testers.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Supports the yearly testing requirement for critical or important functions and the at-least-every-three-years TLPT cadence.
- [Delegated Regulation (EU) 2025/1190 on TLPT](https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng?ref=sorena.io) - Supports TLPT identification criteria, notification-triggered initiation, scope, testing phase, closure, remediation, and authority-validation milestones.

## Practical evidence calendar fields

A useful DORA calendar should not be a list of dates alone. Each row should show which legal source created the obligation, what event starts the clock, who owns the response, what evidence must exist, and what authority or template dependency applies.

Use separate row types for fixed milestones, event-triggered clocks, recurring reviews, authority-request items, and template-maintenance changes. That separation prevents teams from treating incident reports, register updates, and TLPT cycles as the same kind of deadline.

- Date or trigger: fixed calendar date, annual review month, authority notification, incident awareness time, major classification time, contract start or change, or template corrigendum.
- DORA area: ICT risk management, incident reporting, register of information, ICT third-party risk, TLPT, or CTPP oversight.
- Affected cohort: all in-scope financial entities, entities other than microenterprises, identified TLPT entities, entities with ICT third-party arrangements, or designated CTPPs.
- Clock rule: fixed date, at least yearly, at least every three years, within four hours, no later than 24 hours, within 72 hours, one month, three months, six months, 12-week minimum, four weeks, 10 weeks, or eight weeks.
- Evidence required: source citation, owner, approval record, template version, submission copy, authority correspondence, register extract, test report, remediation plan, or attestation.
- Reopen trigger: incident reclassification, missed reporting deadline, competent-authority request, contract change, function-criticality change, template corrigendum, TLPT authority notification, or CTPP designation update.

Sources for this answer:

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Supports the calendar categories covering ICT risk management, testing, incident reporting, and ICT third-party risk obligations.
- [ESAs designate critical ICT third-party providers under DORA](https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers?ref=sorena.io) - Supports the 18 November 2025 milestone for the first published list of designated critical ICT third-party providers.

*Recommended next step*

*Placement: before sources*

## Build a DORA calendar that tracks clocks, templates, owners, and proof

Sorena can help convert DORA incident, register, TLPT, and third-party-risk milestones into cited calendar rows with owners, evidence fields, and review triggers.

- [Open Research Copilot for EU DORA](/solutions/research-copilot.md): Ask questions tied to cited sources about DORA dates, incident reporting clocks, register evidence, TLPT cadence, and cited sources.
- [Talk through implementation](/contact.md): Review your DORA compliance calendar, evidence gaps, and authority-specific dependencies with Sorena.

## Primary sources

- [Regulation (EU) 2022/2554 (DORA)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022R2554&ref=sorena.io) - Primary DORA source for the application date, ICT resilience testing cadence, TLPT cadence, register maintenance and yearly reporting, and ICT third-party risk calendar triggers.
  - Quote: "This Regulation shall apply from 17 January 2025."
- [Delegated Regulation (EU) 2025/301 on incident report time limits](https://eur-lex.europa.eu/eli/reg_del/2025/301/oj/eng?ref=sorena.io) - Source for major ICT incident initial notification, intermediate report, final report, delay, and weekend or bank-holiday timing rules.
  - Quote: "within four hours from the classification"
- [Implementing Regulation (EU) 2025/302 on incident reporting templates](https://eur-lex.europa.eu/eli/reg_impl/2025/302/oj/eng?ref=sorena.io) - Source for standard forms, templates, secure electronic channels, outsourcing notice, reclassification notice, and aggregated reporting procedures for major ICT incidents.
  - Quote: "standard forms, templates, and procedures"
- [Delegated Regulation (EU) 2024/1772 on ICT incident classification](https://eur-lex.europa.eu/eli/reg_del/2024/1772/oj/eng?ref=sorena.io) - Source for the classification dependency that determines when a DORA ICT-related incident becomes a major ICT-related incident.
  - Quote: "criteria for the classification of ICT-related incidents"
- [Implementing Regulation (EU) 2024/2956 on register templates](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2956&ref=sorena.io) - Source for DORA register-of-information templates and fields used to calendar register updates and annual reporting evidence.
  - Quote: "standard templates for the register of information"
- [Corrigendum to Implementing Regulation (EU) 2024/2956](https://eur-lex.europa.eu/eli/reg_impl/2024/2956/corrigendum/2025-09-19/oj/eng?ref=sorena.io) - Source for the 19 September 2025 register-template corrigendum milestone.
  - Quote: "Corrigendum to Commission Implementing Regulation (EU) 2024/2956"
- [Delegated Regulation (EU) 2025/1190 on TLPT](https://eur-lex.europa.eu/eli/reg_del/2025/1190/oj/eng?ref=sorena.io) - Source for TLPT identification criteria, initiation, scope, testing, closure, remediation, and authority-validation milestones.
  - Quote: "initiate a TLPT following a notification"
- [ESAs designate critical ICT third-party providers under DORA](https://www.esma.europa.eu/press-news/esma-news/european-supervisory-authorities-designate-critical-ict-third-party-providers?ref=sorena.io) - Source for the 18 November 2025 first ESA publication of designated critical ICT third-party providers under DORA.
  - Quote: "publish today the list of designated critical ICT third-party providers"

## Related Topic Guides

- [DORA Critical or Important Functions: mapping ICT dependencies and evidence](/artifacts/eu/digital-operational-resilience-act/critical-and-important-functions.md): How DORA critical or important functions affect ICT service mapping, third-party contracts, register-of-information records, incidents, testing, and evidence.
- [DORA ICT Third-Party Contract Remediation Workflow](/artifacts/eu/digital-operational-resilience-act/contract-remediation-workflow.md): A DORA workflow for remediating ICT third-party contracts covering critical or important functions, subcontracting, audit rights, exits, register updates, and evidence.
- [DORA ICT Third-Party Contracts FAQ](/artifacts/eu/digital-operational-resilience-act/faq/ict-third-party-contracts.md): What DORA requires in ICT third-party contracts, including critical or important functions, audit and access rights, termination, exit, subcontracting, register updates, and evidence.
- [DORA ICT third-party risk and contract clauses guide](/artifacts/eu/digital-operational-resilience-act/third-party-risk-and-contract-clauses.md): Official source DORA guide for financial entities in scope, ICT third-party risk, contract clauses, subcontracting controls, register evidence, audit rights, exit planning, and oversight.
- [DORA incident classification forms: criteria, fields, and reporting clocks](/artifacts/eu/digital-operational-resilience-act/incident-classification-forms.md): Official source guide to DORA ICT incident classification forms: major-incident criteria, significant cyber-threat notifications, report fields, time limits, evidence, and reclassification records.
- [DORA incident clock workflow: classification, reports, deadlines, and evidence](/artifacts/eu/digital-operational-resilience-act/incident-clock-workflow.md): Official source DORA workflow for starting the major-incident reporting clock, classifying ICT incidents, submitting initial, intermediate, and final reports, and preserving authority evidence.
- [DORA major ICT incident reporting: classification, reports, and timing](/artifacts/eu/digital-operational-resilience-act/major-incident-reporting.md): Official source DORA guide to major ICT-related incident classification, initial notifications, intermediate and final reports, competent authority routing, and significant cyber threat notifications.
- [DORA major ICT incident thresholds: what triggers reporting?](/artifacts/eu/digital-operational-resilience-act/faq/major-incident-thresholds.md): FAQ on DORA major ICT-related incident classification thresholds, recurring incidents, reporting triggers, and evidence inputs based on EU DORA RTS and ITS texts.
- [DORA Register of Information FAQ: ICT Third-Party Arrangements](/artifacts/eu/digital-operational-resilience-act/faq/register-of-information.md): FAQ on the DORA register of information: who maintains it, which ICT third-party arrangements it covers, template fields, critical functions, reporting, data quality, and evidence.
- [DORA Register of Information Import and Build Workflow](/artifacts/eu/digital-operational-resilience-act/roi-import-and-build-workflow.md): Build a DORA register of information from procurement, vendor, contract, service, function, and subcontractor data using the official register templates and validation checks.
- [DORA Register of Information Template: ICT Provider Fields and Evidence](/artifacts/eu/digital-operational-resilience-act/dora-register-of-information-template.md): An official source DORA register of information template for ICT third-party contracts, provider hierarchy, critical functions, dates, statuses, reporting, and evidence.
- [DORA TLPT selection: who can be required to test?](/artifacts/eu/digital-operational-resilience-act/faq/tlpt-selection.md): FAQ on DORA threat-led penetration testing selection: who identifies financial entities, what criteria are used, what the TLPT authority validates, and what evidence to keep.
- [DORA vs EBA outsourcing guidelines: ICT third-party risk comparison](/artifacts/eu/digital-operational-resilience-act/dora-vs-eba-outsourcing-guidelines.md): Compare binding DORA ICT third-party risk duties with the EBA/ESA outsourcing baseline for registers, critical functions, contracts, subcontracting, exit, incident reporting, and evidence.
- [DORA vs ISO 22301: ICT resilience and business continuity compared](/artifacts/eu/digital-operational-resilience-act/dora-vs-iso-22301.md): Compare DORA's binding ICT operational resilience duties for financial entities with ISO 22301's business continuity management system requirements.
- [DORA vs ISO/IEC 27001: legal ICT resilience obligations and ISMS controls](/artifacts/eu/digital-operational-resilience-act/dora-vs-iso-27001.md): Compare EU DORA and ISO/IEC 27001 across scope, governance, incident reporting, testing, ICT third-party risk, certification, evidence, overlap, and gaps.
- [DORA vs NIS2: financial-sector obligations, overlap, and evidence](/artifacts/eu/digital-operational-resilience-act/dora-vs-nis2.md): Compare DORA and NIS2 for financial entities, ICT providers, incident reporting, management accountability, third-party risk, supervisory routes, and reusable evidence.
- [DORA vs PSD2 incident reporting: major ICT and payment incidents](/artifacts/eu/digital-operational-resilience-act/dora-vs-psd2-incident-reporting.md): Compare DORA major ICT-related incident reporting with PSD2 major operational or security payment incident reporting, including scope, triggers, report stages, recipients, and evidence.
- [EU DORA Applicability Test for Financial Entities and ICT Providers](/artifacts/eu/digital-operational-resilience-act/applicability-test.md): An official source DORA applicability test for financial-entity scope, ICT third-party services, critical or important functions, exclusions, proportionality, and evidence.
- [EU DORA Compliance Checklist for Financial Entities](/artifacts/eu/digital-operational-resilience-act/checklist.md): An official source DORA checklist covering ICT risk governance, major incident reporting, resilience testing, TLPT, ICT third-party contracts, register-of-information records, and audit evidence.
- [EU DORA Compliance Obligations and Evidence Guide](/artifacts/eu/digital-operational-resilience-act/compliance.md): An official source DORA compliance guide covering ICT risk management, incident reporting, resilience testing, TLPT, ICT third-party risk, registers, governance, oversight, and evidence.
- [EU DORA FAQ: scope, incidents, ICT contracts, testing, and evidence](/artifacts/eu/digital-operational-resilience-act/faq.md): Concise DORA FAQ covering who is in scope, proportionality, ICT third-party contracts, register-of-information records, major ICT incident thresholds and reporting, TLPT, testing, enforcement, and evidence.
- [EU DORA ICT risk management control baseline](/artifacts/eu/digital-operational-resilience-act/ict-risk-management-control-baseline.md): An official source DORA control baseline for ICT risk governance, asset and dependency mapping, protection, detection, response, recovery, testing, third-party risk, and evidence.
- [EU DORA ICT subcontracting chain controls for critical functions](/artifacts/eu/digital-operational-resilience-act/subcontracting-chain-controls.md): DORA guide to ICT subcontracting chains for critical or important functions: prior assessment, contract conditions, register fields, monitoring, exit rights, and evidence.
- [EU DORA penalties and fines: enforcement powers and limits](/artifacts/eu/digital-operational-resilience-act/penalties-and-fines.md): Official source guide to DORA enforcement: competent-authority powers, administrative penalties, remedial measures, publication rules, and Lead Overseer penalty payments for critical ICT third-party providers.
- [EU DORA Register of Information Data Model: templates, fields, and evidence](/artifacts/eu/digital-operational-resilience-act/register-of-information-data-model.md): Field-level guide to the EU DORA register of information data model: templates B_01 to B_07, provider identifiers, contract links, subcontracting chains, critical-function assessments, dates, and export evidence.
- [EU DORA Requirements Overview: ICT risk, incidents, testing, and third-party risk](/artifacts/eu/digital-operational-resilience-act/requirements.md): An official source overview of the main EU DORA requirements for financial entities: governance, ICT risk management, incident reporting, resilience testing, TLPT, ICT third-party risk, register of information, oversight, proportionality, and evidence.
- [EU DORA Scope and Covered Entities: financial entities and ICT providers](/artifacts/eu/digital-operational-resilience-act/scope-and-covered-entities.md): Classify whether DORA applies to a financial entity, ICT third-party provider, group arrangement, branch, or critical ICT service dependency.
- [EU DORA Scope and Proportionality Workflow](/artifacts/eu/digital-operational-resilience-act/scope-and-proportionality-workflow.md): Classify DORA covered entities, simplified-framework status, critical or important functions, ICT dependencies, evidence records, and governance approvals.
- [EU DORA testing and TLPT readiness guide](/artifacts/eu/digital-operational-resilience-act/testing-and-tlpt-readiness.md): An official source DORA guide for resilience testing, TLPT eligibility, authority interaction, test evidence, remediation plans, and avoiding unsupported testing cadence.
- [EU DORA TLPT eligibility workflow for financial entities](/artifacts/eu/digital-operational-resilience-act/tlpt-eligibility-workflow.md): Check how DORA TLPT authorities identify financial entities for threat-led penetration testing and what evidence supports scope, readiness, providers, and governance.
- [EU DORA TLPT Runbook: scope, providers, reports, and remediation](/artifacts/eu/digital-operational-resilience-act/tlpt-runbook.md): Build a DORA threat-led penetration testing runbook around authority coordination, scope validation, provider controls, active testing, closure reports, remediation, and attestation.
- [How does proportionality work under EU DORA?](/artifacts/eu/digital-operational-resilience-act/faq/proportionality.md): An official source FAQ on DORA proportionality: what can be scaled, who may use the simplified ICT risk framework, what evidence supports the decision, and which duties cannot be waived.
- [How to build a DORA register of information](/artifacts/eu/digital-operational-resilience-act/register-of-information-how-to-build.md): Build a DORA register of information from contracts, ICT services, providers, functions, subcontractors, risk assessments, audit evidence, exit plans, and export checks.


---

[Privacy Policy](https://www.sorena.io/privacy) | [Terms of Use](https://www.sorena.io/terms-of-use) | [DMCA](https://www.sorena.io/dmca) | [About Us](https://www.sorena.io/about-us)

(c) 2026 Sorena AB (559573-7338). All rights reserved.

Source: https://www.sorena.io/artifacts/eu/digital-operational-resilience-act/deadlines-and-compliance-calendar
