dora
Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: \"DORA gap analysis\", \"DORA readiness\", \"Art. 6 ICT risk fram
npx skills add lawve-ai/awesome-legal-skills --skill dora-tanaji-hemant-naik --agent claude-code
Same command for any agent — swap --agent for codex, cursor, copilot.
Weekly change comes from our own snapshots, not the repository page — it measures attention, not adoption.
What it does
The skill acts as a DORA compliance advisor for EU financial entities, ICT third-party providers, and their risk/tech teams. It covers DORA chapters and articles, RTS/ITS references, and cross-regulatory distinctions to guide ICT risk management, incident classification/reporting, TLPT scoping, and third-party risk provisions.
How it works
- Emphasizes governance of ICT risk under Chapter II (Art. 5–16) and incident management under Chapter III (Art. 17–23).
- References article numbers when describing obligations (e.g., Art. 6(1) for RMF, Art. 18(1) for incident classification, Art. 19 for major incident reporting).
- Distinguishes Chapter II from Chapter III and notes relevant RTS/ITS (e.g., CDR EU 2024/1774 for RMF, CDR EU 2024/1772 for classification, CIR EU 2025/302 for reporting templates).
- Outlines TLPT requirements under Art. 26 with TLPT timing (every 3 years) and live production scope, tied to CDR EU 2025/1190.
- Describes ICT third-party risk management provisions (Arts. 28–30), including Register of Information and contractual provisions per Art. 30.
When to use it
Use when a user asks about DORA compliance, ICT risk management frameworks, incident classification or reporting, TLPT, ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, or oversight of critical TPSPs, or any DORA RTS/ITS obligation. It also triggers for specific phrases listed in the skill description (e.g., "DORA gap analysis", "DORA readiness").
What it can touch
- ICT risk management framework guidance (Art. 5–16) with references to CDR EU 2024/1774.
- Incident management and reporting mechanics (Arts. 17–23) and related RTS/ITS (CDR EU 2025/301; CIR EU 2025/302).
- TLPT scope and requirements (Art. 26) aligned with CDR EU 2025/1190 and TLPT concepts (aligned with TIBER-EU).
- Third-party risk policy, Register of Information, concentration risk, exit strategies, and contractual provisions (Arts. 28–30; CIR EU 2024/2956; RTS CDR EU 2024/1773).
Caveats
- The guidance relies on Article-level citations and RTS/ITS references; misinterpretation outside the specified articles is not provided.
- It maintains strict separation between Chapter II (ICT risk management) and Chapter III (incident management) per the rules in the material.
- Does not extrapolate beyond the stated obligations, thresholds, or timelines (e.g., it notes thresholds as defined in CDR RTS but does not recite them beyond what is in the skill).
# DORA — Digital Operational Resilience Act Skill > **Last verified:** 2026-07-03 You are an expert DORA compliance advisor assisting **financial entities, ICT third-party service providers, and their compliance, risk, and technology teams**. Your knowledge covers the full text of **Regulation (EU) 2022/2554**, all adopted **Regulatory Technical Standards (RTS)** and **Implementing Technical Standards (ITS)** issued by EBA, ESMA, and EIOPA (ESAs), and the distinction between DORA and related regulations (NIS2, EMIR, MiCA, CRR). **Application date: 17 January 2025.** --- ## Foundational Rules 1. **Never conflate DORA with NIS2.** DORA is lex specialis for the financial sector under Art. 1 DORA; NIS2 applies where DORA does not. Financial entities subject to DORA are exempt from equivalent NIS2 obligations (NIS2 Art. 4(2)). 2. **Never cite legacy EBA ICT/security Risk guidelines** (EBA/GL/2019/04) as the current standard. Those guidelines applied pre-DORA. Since 17 January 2025, DORA is the governing framework for in-scope EU financial entities. 3. **Always use DORA's own chapter structure.** DORA has 9 **Chapters** (not "Titles"). Callers sometimes say "Title II" or "Title III" — cl
- Foundational Rules
- How to Respond
- DORA Structure at a Glance
- In-Scope Financial Entities (Art. 2)
- Chapter II — ICT Risk Management Framework (Art. 5–16)
- Art. 5 — Governance and Organisation
- Art. 6 — ICT Risk Management Framework
- Art. 7 — ICT Systems, Protocols and Tools
- Art. 8 — Identification
- Art. 9 — Protection and Prevention
- Art. 10 — Detection
- Art. 11 — Response and Recovery
- Art. 12 — Backup Policies and Procedures
- Art. 13 — Learning and Evolving
What does the dora skill do?
Expert DORA (Regulation (EU) 2022/2554 — Digital Operational Resilience Act) compliance advisor for EU financial entities. Use this skill whenever a user asks about DORA compliance, ICT risk management frameworks, ICT incident classification or reporting, threat-led penetration testing (TLPT), ICT third-party risk management, Register of Information, contractual provisions with ICT providers, ICT concentration risk, oversight of critical ICT third-party service providers (CTPPs), or any DORA RTS/ITS obligation. Also trigger for: \"DORA gap analysis\", \"DORA readiness\", \"Art. 6 ICT risk fram
How do I install it?
Run `npx skills add lawve-ai/awesome-legal-skills --skill dora-tanaji-hemant-naik --agent claude-code` — it drops the skill into your project so the agent can pick it up. Swap the --agent value for codex, cursor or copilot if you use one of those.
Where does this skill come from?
From lawve-ai/awesome-legal-skills, a repository with 618 stars. We read it straight from the repository tree rather than a submitted listing, so what you see here is what is actually published.
Is a popular skill a good skill?
Not necessarily. Stars measure attention, not adoption — a repository can trend for a week and be abandoned. That is why we show the weekly change from our own snapshots next to the total, instead of a single flattering number.
