Agent skill · Security

dora

Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: \"DORA gap analysis\", \"DORA readiness\", \"Art. 6 ICT risk fram

lawve-aigithub.com/lawve-aiGitHub ↗
claude-codeNOASSERTION
Install
npx skills add lawve-ai/awesome-legal-skills --skill dora-tanaji-hemant-naik --agent claude-code

Same command for any agent — swap --agent for codex, cursor, copilot.

Facts
Files in the skill folder: 7
SKILL.md size: 25 KB
Bundled scripts: none
Path: skills/dora-tanaji-hemant-naik/SKILL.md
Open the folder on GitHub →
Where it comes from
Stars: 618
Language: Python

Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.

Review
written from the skill's own SKILL.md · Aug 5, 2026

What it does

The skill acts as a DORA compliance advisor for EU financial entities, ICT third-party providers, and their risk/tech teams. It covers DORA chapters and articles, RTS/ITS references, and cross-regulatory distinctions to guide ICT risk management, incident classification/reporting, TLPT scoping, and third-party risk provisions.

How it works

  • Emphasizes governance of ICT risk under Chapter II (Art. 5–16) and incident management under Chapter III (Art. 17–23).
  • References article numbers when describing obligations (e.g., Art. 6(1) for RMF, Art. 18(1) for incident classification, Art. 19 for major incident reporting).
  • Distinguishes Chapter II from Chapter III and notes relevant RTS/ITS (e.g., CDR EU 2024/1774 for RMF, CDR EU 2024/1772 for classification, CIR EU 2025/302 for reporting templates).
  • Outlines TLPT requirements under Art. 26 with TLPT timing (every 3 years) and live production scope, tied to CDR EU 2025/1190.
  • Describes ICT third-party risk management provisions (Arts. 28–30), including Register of Information and contractual provisions per Art. 30.

When to use it

Use when a user asks about DORA compliance, ICT risk management frameworks, incident classification or reporting, TLPT, ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, or oversight of critical TPSPs, or any DORA RTS/ITS obligation. It also triggers for specific phrases listed in the skill description (e.g., "DORA gap analysis", "DORA readiness").

What it can touch

  • ICT risk management framework guidance (Art. 5–16) with references to CDR EU 2024/1774.
  • Incident management and reporting mechanics (Arts. 17–23) and related RTS/ITS (CDR EU 2025/301; CIR EU 2025/302).
  • TLPT scope and requirements (Art. 26) aligned with CDR EU 2025/1190 and TLPT concepts (aligned with TIBER-EU).
  • Third-party risk policy, Register of Information, concentration risk, exit strategies, and contractual provisions (Arts. 28–30; CIR EU 2024/2956; RTS CDR EU 2024/1773).

Caveats

  • The guidance relies on Article-level citations and RTS/ITS references; misinterpretation outside the specified articles is not provided.
  • It maintains strict separation between Chapter II (ICT risk management) and Chapter III (incident management) per the rules in the material.
  • Does not extrapolate beyond the stated obligations, thresholds, or timelines (e.g., it notes thresholds as defined in CDR RTS but does not recite them beyond what is in the skill).
From the SKILL.md

# DORA — Digital Operational Resilience Act Skill > **Last verified:** 2026-07-03 You are an expert DORA compliance advisor assisting **financial entities, ICT third-party service providers, and their compliance, risk, and technology teams**. Your knowledge covers the full text of **Regulation (EU) 2022/2554**, all adopted **Regulatory Technical Standards (RTS)** and **Implementing Technical Standards (ITS)** issued by EBA, ESMA, and EIOPA (ESAs), and the distinction between DORA and related regulations (NIS2, EMIR, MiCA, CRR). **Application date: 17 January 2025.** --- ## Foundational Rules 1. **Never conflate DORA with NIS2.** DORA is lex specialis for the financial sector under Art. 1 DORA; NIS2 applies where DORA does not. Financial entities subject to DORA are exempt from equivalent NIS2 obligations (NIS2 Art. 4(2)). 2. **Never cite legacy EBA ICT/security Risk guidelines** (EBA/GL/2019/04) as the current standard. Those guidelines applied pre-DORA. Since 17 January 2025, DORA is the governing framework for in-scope EU financial entities. 3. **Always use DORA's own chapter structure.** DORA has 9 **Chapters** (not "Titles"). Callers sometimes say "Title II" or "Title III" — cl

What's inside
Steps it walks through
  1. Foundational Rules
  2. How to Respond
  3. DORA Structure at a Glance
  4. In-Scope Financial Entities (Art. 2)
  5. Chapter II — ICT Risk Management Framework (Art. 5–16)
  6. Art. 5 — Governance and Organisation
  7. Art. 6 — ICT Risk Management Framework
  8. Art. 7 — ICT Systems, Protocols and Tools
  9. Art. 8 — Identification
  10. Art. 9 — Protection and Prevention
  11. Art. 10 — Detection
  12. Art. 11 — Response and Recovery
  13. Art. 12 — Backup Policies and Procedures
  14. Art. 13 — Learning and Evolving
Ships with 6 files
  • LICENSE
  • README.md
  • references/article-reference.md
  • references/incident-classification.md
  • references/rts-its-guide.md
  • references/third-party-risk.md
More from awesome-legal-skills
All skills →
About this skill
What does the dora skill do?

Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: \"DORA gap analysis\", \"DORA readiness\", \"Art. 6 ICT risk fram

How do I install it?

Run `npx skills add lawve-ai/awesome-legal-skills --skill dora-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.

Where does this skill come from?

From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.

Is a popular skill a good skill?

Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.

Keep going