EU Regulation 2022/2554 · DORA in force since 17 Jan 2025

DORA Assessment: structured proof of digital operational resilience

Demonstrate compliance with the five DORA pillars — ICT risk management, incident reporting, resilience testing, third-party risk and information sharing. SCMC covers 10 areas with around 60 control questions, on a 0–4 maturity scale with the defined target level ‘Managed’.

Go to assessment
Cover the five DORA pillars
10 areas, around 60 control questions
0–4 maturity scale with target level ‘Managed’

Your benefits at a glance

Our platform turns the DORA requirements into a practical framework for ICT resilience, incident management and third-party governance.

  • Cover all five DORA pillars in a structured way
  • Document ICT incidents and tests robustly
  • Score maturity against the ‘Managed’ target level
fromCHF 175/ month
Swiss Made Software
18+ companies trust SCMC
Data stored exclusively in Switzerland

Simple, transparent pricing

Monthly

CHF 175

/ month

Recommended

Annual

CHF 1'750

≈ CHF 146 / month

2 months free

From regulation text to a robust implementation

The Digital Operational Resilience Act (DORA, EU 2022/2554) obliges financial entities and their critical ICT third-party providers to implement concrete measures for digital operational resilience. SCMC consolidates the requirements along the five DORA pillars — ICT risk management, incident reporting, resilience testing, third-party risk and information sharing — into 10 areas with around 60 control questions. Every requirement is scored on a uniform 0–4 maturity scale with a clear ‘Managed’ target level — structured, documented and audit-ready.

Sound familiar?

The Challenge

DORA obligations are clear — implementation stays diffuse

You know DORA applies to your organisation, but the path from the regulation text and RTS/ITS to concrete measures in daily operations remains hard to grasp. A robust position assessment across all five pillars is missing.

Our Solution

Our platform translates the DORA requirements into 10 areas with around 60 control questions and makes the implementation status visible along a uniform maturity scale.

Why digital instead of Excel or Word?

Classic approach

  • scattered DORA mappings
  • manual maintenance
  • incident and test evidence hard to retrieve
  • inconsistent maturity scoring

With our platform

  • digital workflow
  • central assessment across all five pillars
  • uniform 0–4 maturity scale
  • audit-ready supervisor and incident evidence

How does SCMC support DORA?

Work online and structured

Process the DORA requirements in a clear digital workflow instead of Excel mappings, Word documents and scattered evidence.

Team collaboration

Create a shared working basis for ICT, IT Security, Risk Management, Compliance, Management and third-party owners.

Central documentation

Keep assessments, evidence, incident reports, test results and third-party contracts in one place.

Maturity vs. target level

Score every DORA requirement on the 0–4 maturity scale and see at a glance how far you still are from the ‘Managed’ target level.

Third parties and critical ICT providers

Capture requirements for cloud providers, outsourcing partners and critical ICT third-party providers in a structured, traceable way — including mandatory contractual clauses.

Incident reporting and resilience testing

Document reporting paths, classification logic, deadlines and escalation steps for ICT incidents, plus results from resilience tests and TLPT — robust for supervisors and management.

Audit-ready evidence

Build a solid foundation for supervisory authorities, internal audits and management reporting under DORA.

Versioning and traceability

Keep an eye on changes, developments and prior assessments and document progress cleanly over time.

Repeatable assessments

Use the DORA assessment not as a one-off but as a repeatable process for ongoing compliance and continuous improvement.

Start online right away

Register for free on our platform and try the entry-level free Cyber-Security Basis Check.

DORA Digital Operational Resilience Assessment
DORA Digital Operational Resilience Assessment
DORA Assessment Demonstrate alignment with DORA's five pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk and information sharing. 10 areas, ~60 control questions, maturity scale 0-4. Threshold: Managed.
Recommended Annual
CHF 1'750≈ CHF 146 / month
2 months free
Monthly
CHF 175/ month

Make DORA finally workable

Our platform turns DORA requirements, ICT risk management, incident reporting, resilience testing and third-party risk into a clear, digital and traceable working process.

Contact us

Frequently asked questions about DORA