DORA Check Now Available

Public DORA Check by Scheja und Partners

Our DORA Check is now publicly available. It enables companies to obtain an initial assessment of their current level of DORA implementation. The digital assessment helps review key topics and identify potential areas for action at an early stage.

Why Is DORA Important for Companies?

DORA stands for the Digital Operational Resilience Act. This European regulation is intended to strengthen the digital resilience of the financial sector. It has applied since 17 January 2025 and establishes uniform requirements for managing information and communication technology risks.

The regulation is designed to ensure that companies are better prepared for cyberattacks, technical failures and other digital disruptions. It is not only about preventing such incidents wherever possible. Affected companies must also be able to detect disruptions quickly, respond appropriately and restore critical business processes.

DORA specifically covers the following areas:

  • ICT risk management
  • The detection and reporting of ICT-related incidents
  • Digital operational resilience testing
  • The management of ICT third-party service providers
  • Documentation and evidence requirements
  • Responsibilities within the management body

The DORA Check as a First Step

Successful DORA implementation requires cooperation between various specialist departments. Legal requirements, technical security measures and internal processes must be aligned with one another.

The DORA Check can serve as a useful first step. It provides a rapid overview and facilitates the transition to a more in-depth assessment.

Further information on the legal requirements and our advisory services is available on our DORA advisory services page. There, we explain how we support companies with governance structures, risk assessments, security requirements and organisational measures.

We are pleased to assist you with the legal analysis and practical implementation. You can contact us directly through our Contact page.

Additional information is also available in our advisory sections on cybersecurity and on our data protection and IT law services.

The Check is intended to provide initial guidance and does not replace legal advice tailored to an individual case. Its results cannot be used to make any binding determination as to whether all statutory or regulatory requirements have been fully met.

Discover more articles