Skip to main content
DORA Auditor

DORA blog

Practical guides, regulatory news, and analysis for compliance teams working through DORA. Sourced and dated, like everything else on this site.

11 articles

guideLatest

DORA Article 30: Key Contractual Provisions Checklist

DORA Article 30 lists the mandatory clauses every ICT contract needs, with a stricter tier for critical or important functions. Updated August 2026.

Read guide
guideAugust 17, 2026

DORA Article 45 Information Sharing: A Practical Guide

DORA Article 45 allows cyber threat intel sharing, but only within trusted arrangements with a notification duty and GDPR basis. Updated August 2026.

guideAugust 10, 2026

DORA Article 5: Management Body Duties Explained

DORA Article 5 puts personal accountability for ICT risk on the management body: approval duties, training, and liability exposure. Updated August 2026.

guideAugust 3, 2026

DORA CTPP Oversight: Designation, Fees, and Appeals

DORA charges designated critical ICT providers annual oversight fees and gives them a right of appeal. How it works. Updated August 2026.

guideJuly 27, 2026

DORA Subcontracting Rules: What the RTS Requires

DORA subcontracting rules require ten checks before a critical ICT service is subcontracted, plus notice-and-objection rights. Updated July 2026.

guideJuly 20, 2026

DORA Concentration Risk: What Article 29 Requires

DORA Article 29 requires assessing ICT concentration risk before outsourcing critical functions. What it covers and how to assess it. Updated July 2026.

guideJuly 13, 2026

DORA TLPT Requirements: Who Needs Testing, and When

DORA's threat-led penetration testing rules (Articles 26-27, RTS 2025/1190): who must test, how often, and what testers need to meet. Updated July 2026.