Agent skill · Security

dora

Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: "DORA gap analysis", "DORA readiness", "Art. 6 ICT risk framework

Sushegaadgithub.com/SushegaadGitHub ↗
claude-codeMIT
Install
npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dora --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 5
SKILL.md size: 25 KB
Bundled scripts: none
Path: plugins/dora/skills/dora/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 801
Language: HTML

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

Guides an AI to function as a DORA compliance advisor for EU financial entities, covering ICT risk management, incident classification and reporting, TLPT, third-party risk, Register of Information, contractual provisions with ICT providers, ICT concentration risk, and oversight of critical ICT TPSPs, aligned to DORA RTS/ITS and Article references.

How it works

Instructional scope includes: using DORA’s chapter structure (Chapter II for ICT risk management, Chapter III for incident management, Chapter IV for testing, Chapter V for ICT third-party risk); citing articles and paragraphs (e.g., Art. 6(1), Art. 18(1), Art. 28(1), Art. 30(2)); applying RTS/ITS designations (CDR numbers and CIR templates) when relevant; providing gap analyses, risk assessments, incident classification checklists, and contractual provisions checklists as specified in the task-output mapping. The skill emphasizes avoiding conflating DORA with NIS2 and adhering to Article-level citations.

When to use it

Triggered for inquiries about DORA compliance, ICT risk management frameworks, incident classification or reporting, TLPT, ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of CTPPs, or any DORA RTS/ITS obligation. Also activates for phrases like "DORA gap analysis", "DORA readiness", or "Art. 6 ICT risk framework".

What it can touch

Touchpoints include ICT risk management framework elements, asset identification, incident classification processes, reporting timelines, TLPT scope, and contractual provisions requirements as described in Art. 30 and related RTS/ITS references (CDR and CIR numbers referenced within the skill). The content instructs generation of structured outputs such as gap analyses, risk registers, and policy templates aligned to specific articles.

Caveats

Cites article numbers and RTS/ITS numbers as required; does not speculate beyond explicit Schedules and criteria (e.g., Art. 6, Art. 18, Art. 26, Art. 28, Art. 30). No claims about outcomes beyond stated obligations and templates. License: MIT.

From the SKILL.md

# DORA — Digital Operational Resilience Act Skill > **Last verified:** 2026-07-03 You are an expert DORA compliance advisor assisting **financial entities, ICT third-party service providers, and their compliance, risk, and technology teams**. Your knowledge covers the full text of **Regulation (EU) 2022/2554**, all adopted **Regulatory Technical Standards (RTS)** and **Implementing Technical Standards (ITS)** issued by EBA, ESMA, and EIOPA (ESAs), and the distinction between DORA and related regulations (NIS2, EMIR, MiCA, CRR). **Application date: 17 January 2025.** --- ## Foundational Rules 1. **Never conflate DORA with NIS2.** DORA is lex specialis for the financial sector under Art. 1 DORA; NIS2 applies where DORA does not. Financial entities subject to DORA are exempt from equivalent NIS2 obligations (NIS2 Art. 4(2)). 2. **Never cite legacy EBA ICT/security Risk guidelines** (EBA/GL/2019/04) as the current standard. Those guidelines applied pre-DORA. Since 17 January 2025, DORA is the governing framework for in-scope EU financial entities. 3. **Always use DORA's own chapter structure.** DORA has 9 **Chapters** (not "Titles"). Callers sometimes say "Title II" or "Title III" — cl

What's inside
Steps it walks through
  1. Foundational Rules
  2. How to Respond
  3. DORA Structure at a Glance
  4. In-Scope Financial Entities (Art. 2)
  5. Chapter II — ICT Risk Management Framework (Art. 5–16)
  6. Art. 5 — Governance and Organisation
  7. Art. 6 — ICT Risk Management Framework
  8. Art. 7 — ICT Systems, Protocols and Tools
  9. Art. 8 — Identification
  10. Art. 9 — Protection and Prevention
  11. Art. 10 — Detection
  12. Art. 11 — Response and Recovery
  13. Art. 12 — Backup Policies and Procedures
  14. Art. 13 — Learning and Evolving
Ships with 4 files
  • references/article-reference.md
  • references/incident-classification.md
  • references/rts-its-guide.md
  • references/third-party-risk.md
More from Claude-Skills-Governance-Risk-and-Compliance
All skills →
About this skill
What does the dora skill do?

Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: "DORA gap analysis", "DORA readiness", "Art. 6 ICT risk framework

How do I install it?

Run `npx skills add Sushegaad/Claude-Skills-Governance-Risk-and-Compliance --skill dora --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, a repository with 801 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going