ECZ-ID DORA Readiness
DORA is already in force. Find the ICT resilience evidence gaps before a regulator, auditor or customer finds them.
Free, local-first evidence review. No source upload. No sign-in to run a check.
Can you produce your ICT third-party evidence today? Regulation (EU) 2022/2554 (DORA) has applied since 17 January 2025. Financial entities must maintain a register of information covering every contractual arrangement for ICT services from ICT third-party providers and make it available to their competent authority on request (Article 28(3)). Their suppliers are being asked for the evidence behind it now.
This extension answers one operational question in under a minute: what DORA-relevant ICT resilience evidence can I see in this workspace, what is not observed, and what deserves review next?
- Surfaces the ICT third-party register first, then the operational-resilience / ICT risk policy, incident-response evidence, resilience-testing / continuity evidence, and ICT contractual arrangements / exit plans. Locally, by filename and path.
- Gives every result a deterministic Review Priority (LOW / NORMAL / ELEVATED / HIGH) with the exact reasons. Never a score.
- Explains, for each evidence class, what was observed, what was not, why it matters under DORA (with the article), and what to review next.
- Shows at most three next actions matched to the result: free ECZ-ID tools and guidance first, TrustOps routes only where a resolver-verifiable result would help.
What you can do in under a minute
- Open a project, trust the workspace, and run
ECZ-ID DORA Readiness: Review / Scan Workspace.
- Read the evidence review: Review Priority, observed / not observed, why it matters, review next.
- Run
ECZ-ID DORA Readiness: Build Evidence Summary for a shareable, claim-free summary, or ECZ-ID DORA Readiness: Generate local evidence report for JSON and Markdown you can keep beside the repository.
Example result
ECZ-ID DORA Readiness: Evidence Review
Can you produce your ICT third-party evidence today?
Review Priority: HIGH
Why: 2 primary evidence classes were not observed together (threshold 2).
ICT third-party register ................ OBSERVED, REVIEW REQUIRED registers/ict-third-party-register.csv
Operational-resilience / ICT risk policy OBSERVED, REVIEW REQUIRED policies/operational-resilience-policy.md
Incident-response evidence .............. NOT OBSERVED
Resilience-testing / continuity ......... NOT OBSERVED
ICT contractual arrangements / exit plans NOT OBSERVED
Review next: confirm the register distinguishes critical or important functions;
add the incident process or register; add the latest resilience test or DR record.
Next actions: free Vendor Risk + Counterparty Trust reviews; DORA guidance;
Cyber Resilience Passport (TrustOps).
What it looks for
| Evidence class |
Why it matters |
Found by filename / path such as |
| ICT third-party register |
The register of information a competent authority can request in full (Article 28(3)). Usually asked for first. |
ict-third-party-register.csv, register-of-information.xlsx |
| Operational-resilience / ICT risk policy |
A documented ICT risk management framework and resilience strategy (Article 6). |
operational-resilience-policy.md, ict-risk-management-framework.pdf |
| Incident-response evidence |
An incident management process and the path by which major incidents are reported (Articles 17 and 19). |
incident-response-plan.md, incident-register.csv |
| Resilience-testing / continuity evidence |
The testing programme, business continuity policy and threat-led testing where required (Articles 24, 11, 26). |
resilience-test-2026.pdf, business-continuity-plan.md, dr-plan.md |
| ICT contractual arrangements / exit plans |
Written contracts including service levels, and exit strategies for services supporting critical or important functions (Articles 30 and 28(8)). |
ict-contract-schedule.xlsx, exit-plan.md |
What results mean
Results use four states and a priority, never a verdict:
EVIDENCE OBSERVED, EVIDENCE NOT OBSERVED, REVIEW RECOMMENDED, REVIEW REQUIRED, plus Review Priority LOW / NORMAL / ELEVATED / HIGH.
Filename and path detection shows that a document exists where you expect it. It does not read the document and cannot judge its quality; every observed item is marked for human review. Review Priority is not a safety, approval or compliance determination. Missing evidence is neutral. Your local policy decides what is sufficient, and you should re-check before reliance.
Useful for
- ICT third-party service providers supplying EU financial entities and being asked for their side of the register
- Operational-resilience, ICT risk and third-party risk leads inside banks, insurers, payment and investment firms
- Internal audit, procurement and outsourcing teams preparing for a supervisory or customer request
- Engineering leads who keep resilience evidence next to the code
Relevant when a supervised entity asks for the evidence behind its register entry, an auditor asks for the ICT third-party register, you are preparing the yearly report on ICT third-party arrangements, or a customer questionnaire asks about incident handling and continuity testing.
Example use cases
- A bank's procurement team asks your company for the evidence behind its register-of-information entry. Run the review, fix the gaps, send the evidence summary.
- Before an internal audit, confirm the policy, incident register, latest continuity test and exit plans are where the auditor will look.
- A supplier onboarding questionnaire asks how major ICT incidents reach the financial entity. Check that the incident process is present and current.
Go further, only where relevant
Each review shows at most three next actions chosen from what it observed:
View all relevant DORA / resilience products: https://developers.ecocitizenz.com/dora-sbom-suite/
TrustOps handles setup and checkout. This extension runs no payment, issues no ECZ-ID and creates no Resolver proof. Prices shown were read from the TrustOps catalogue on 2026-09-03; TrustOps shows the current price before any payment.
Privacy and permissions
| Question |
Answer |
| Files read |
Filenames and paths during a scan you start |
| File contents read |
No. Detection is filename and path only |
| Anything uploaded |
No source, prompts, secrets or tool payloads leave your device |
| Network destinations |
Only links you choose to open, and an optional user-initiated public-interface refresh (HTTPS GET to an allowlisted ECZ-ID host) |
| Telemetry |
None |
| Retention |
None. Reports are written only when you ask, into your workspace |
| Workspace Trust |
Respected. No filesystem access in Restricted Mode |
The privacy notice ships inside the extension: run ECZ-ID DORA Readiness: Open Privacy Notice (bundled).
Frequently asked questions
Is this extension free? Yes. Every local review is free, with no sign-in and no purchase.
Does it upload my source code? No. Detection is filename and path only. No source, prompts, secrets or tool payloads leave your device, and there is no telemetry.
Does a missing item mean something is wrong? No. "Evidence not observed" is neutral. It tells you where a reviewer will find a gap in this workspace; your local policy decides what is sufficient.
Is the register of information only for financial entities? The obligation sits with the financial entity, but the entries describe its ICT providers. Providers are asked for the underlying evidence, which is why this review puts the register first.
What happens when the public interface service is unavailable? It keeps working from a bundled contract. A refresh is optional and user-initiated.
What it does not do
- No source, prompt or secret upload, and no telemetry.
- Local evidence review and routing only. It does not issue ECZ-ID proof, activate services, grant access, or make approval, safety, insurance or compliance decisions.
- Makes no safety, approval, certification or compliance claim about you or your suppliers.
- Runs no checkout or payment. Commercial actions happen only in TrustOps.
Install and first use
- In your editor's Extensions view, search for ECZ-ID DORA Readiness (publisher EcoCitizenz) and install it.
- Open a project and trust the workspace.
- Run
ECZ-ID DORA Readiness: Review / Scan Workspace and read the evidence review.
Python / CLI
Prefer Python, CI or terminal automation?
python -m pip install ecz-id-dora
ecz-id-dora --help
The Python tools run locally and inspect, explain and route only, the same role boundary as this extension.
Machine-readable facts
| Field |
Value |
| Product |
ECZ-ID DORA Readiness |
| Identity |
ecocitizenz.eczid-dora-readiness |
| Publisher |
EcoCitizenz |
| License |
Free; see the bundled LICENSE.txt |
| Version |
0.3.0 |
| Page family |
functional-extension |
| Purpose |
Find the ICT resilience evidence gaps before a regulator, auditor or customer finds them. |
| Regulation |
Regulation (EU) 2022/2554 (DORA), applied since 17 January 2025 (Article 64): https://eur-lex.europa.eu/eli/reg/2022/2554/oj |
| Applicable audiences |
ICT third-party service providers to EU financial entities; operational-resilience, ICT risk and third-party risk leads; internal audit, procurement and outsourcing teams; engineering leads |
| Applicable scenarios |
a supervised entity asks for register evidence; an auditor asks for the ICT third-party register; yearly reporting on ICT third-party arrangements; supplier questionnaires on incidents and continuity |
| Primary command |
ECZ-ID DORA Readiness: Review / Scan Workspace |
| Inputs |
ICT third-party register, operational-resilience / ICT risk policy, incident-response evidence, resilience-testing / continuity evidence, ICT contractual arrangements / exit plans |
| Outputs |
Observed / not-observed evidence with why-it-matters and review-next guidance, a deterministic Review Priority, an evidence summary, a local JSON + Markdown report, and at most three contextual routes |
| Result states |
EVIDENCE OBSERVED; EVIDENCE NOT OBSERVED; REVIEW RECOMMENDED; REVIEW REQUIRED; Review Priority LOW / NORMAL / ELEVATED / HIGH |
| Data handling |
Filenames and paths only; no source / prompt / secret upload; no telemetry; retention none |
| Network behaviour |
Only links you open, plus an optional user-initiated public-interface refresh (GET, allowlisted ECZ-ID host) |
| Limitations |
Does not read document contents, issue proof, approve, certify, insure, determine compliance, or run checkout |
| Canonical machine discovery |
https://machine.ecocitizenz.org/.well-known/ecz-machine.json |
| Public proof |
https://resolver.ecocitizenz.org |
| Documentation |
https://developers.ecocitizenz.com |
| Product page |
https://developers.ecocitizenz.com/dora/ |
| Supported setup |
https://trustops.ecocitizenz.com/start |
| DORA flow in TrustOps |
https://trustops.ecocitizenz.com/start?flow=dora-sbom |
| Re-check |
Re-run before reliance |
Links and support
ECZ-ID is independent trust infrastructure. Third-party names describe compatible ecosystems only and do not imply endorsement or affiliation. Local policy decides whether the evidence you review is sufficient.