Skip to content
| Marketplace
Sign in
Visual Studio Code>Linters>ECZ-ID DORA ReadinessNew to Visual Studio Code? Get it now.
ECZ-ID DORA Readiness

ECZ-ID DORA Readiness

EcoCitizenz

|
105 installs
| (0) | Free
DORA is already in force. Find the ICT resilience evidence gaps before a regulator, auditor or customer does. Free, local-first, no source upload, no sign-in.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

ECZ-ID DORA Readiness

DORA is already in force. Find the ICT resilience evidence gaps before a regulator, auditor or customer finds them.

Free, local-first evidence review. No source upload. No sign-in to run a check.

Can you produce your ICT third-party evidence today? Regulation (EU) 2022/2554 (DORA) has applied since 17 January 2025. Financial entities must maintain a register of information covering every contractual arrangement for ICT services from ICT third-party providers and make it available to their competent authority on request (Article 28(3)). Their suppliers are being asked for the evidence behind it now.

This extension answers one operational question in under a minute: what DORA-relevant ICT resilience evidence can I see in this workspace, what is not observed, and what deserves review next?

  • Surfaces the ICT third-party register first, then the operational-resilience / ICT risk policy, incident-response evidence, resilience-testing / continuity evidence, and ICT contractual arrangements / exit plans. Locally, by filename and path.
  • Gives every result a deterministic Review Priority (LOW / NORMAL / ELEVATED / HIGH) with the exact reasons. Never a score.
  • Explains, for each evidence class, what was observed, what was not, why it matters under DORA (with the article), and what to review next.
  • Shows at most three next actions matched to the result: free ECZ-ID tools and guidance first, TrustOps routes only where a resolver-verifiable result would help.

What you can do in under a minute

  1. Open a project, trust the workspace, and run ECZ-ID DORA Readiness: Review / Scan Workspace.
  2. Read the evidence review: Review Priority, observed / not observed, why it matters, review next.
  3. Run ECZ-ID DORA Readiness: Build Evidence Summary for a shareable, claim-free summary, or ECZ-ID DORA Readiness: Generate local evidence report for JSON and Markdown you can keep beside the repository.

Example result

ECZ-ID DORA Readiness: Evidence Review
Can you produce your ICT third-party evidence today?

Review Priority: HIGH
Why: 2 primary evidence classes were not observed together (threshold 2).

ICT third-party register ................ OBSERVED, REVIEW REQUIRED  registers/ict-third-party-register.csv
Operational-resilience / ICT risk policy  OBSERVED, REVIEW REQUIRED  policies/operational-resilience-policy.md
Incident-response evidence .............. NOT OBSERVED
Resilience-testing / continuity ......... NOT OBSERVED
ICT contractual arrangements / exit plans NOT OBSERVED

Review next: confirm the register distinguishes critical or important functions;
add the incident process or register; add the latest resilience test or DR record.
Next actions: free Vendor Risk + Counterparty Trust reviews; DORA guidance;
Cyber Resilience Passport (TrustOps).

What it looks for

Evidence class Why it matters Found by filename / path such as
ICT third-party register The register of information a competent authority can request in full (Article 28(3)). Usually asked for first. ict-third-party-register.csv, register-of-information.xlsx
Operational-resilience / ICT risk policy A documented ICT risk management framework and resilience strategy (Article 6). operational-resilience-policy.md, ict-risk-management-framework.pdf
Incident-response evidence An incident management process and the path by which major incidents are reported (Articles 17 and 19). incident-response-plan.md, incident-register.csv
Resilience-testing / continuity evidence The testing programme, business continuity policy and threat-led testing where required (Articles 24, 11, 26). resilience-test-2026.pdf, business-continuity-plan.md, dr-plan.md
ICT contractual arrangements / exit plans Written contracts including service levels, and exit strategies for services supporting critical or important functions (Articles 30 and 28(8)). ict-contract-schedule.xlsx, exit-plan.md

What results mean

Results use four states and a priority, never a verdict:

EVIDENCE OBSERVED, EVIDENCE NOT OBSERVED, REVIEW RECOMMENDED, REVIEW REQUIRED, plus Review Priority LOW / NORMAL / ELEVATED / HIGH.

Filename and path detection shows that a document exists where you expect it. It does not read the document and cannot judge its quality; every observed item is marked for human review. Review Priority is not a safety, approval or compliance determination. Missing evidence is neutral. Your local policy decides what is sufficient, and you should re-check before reliance.

Useful for

  • ICT third-party service providers supplying EU financial entities and being asked for their side of the register
  • Operational-resilience, ICT risk and third-party risk leads inside banks, insurers, payment and investment firms
  • Internal audit, procurement and outsourcing teams preparing for a supervisory or customer request
  • Engineering leads who keep resilience evidence next to the code

Relevant when a supervised entity asks for the evidence behind its register entry, an auditor asks for the ICT third-party register, you are preparing the yearly report on ICT third-party arrangements, or a customer questionnaire asks about incident handling and continuity testing.

Example use cases

  • A bank's procurement team asks your company for the evidence behind its register-of-information entry. Run the review, fix the gaps, send the evidence summary.
  • Before an internal audit, confirm the policy, incident register, latest continuity test and exit plans are where the auditor will look.
  • A supplier onboarding questionnaire asks how major ICT incidents reach the financial entity. Check that the incident process is present and current.

Go further, only where relevant

Each review shows at most three next actions chosen from what it observed:

  • Free ECZ-ID Vendor Risk and Counterparty Trust reviews of the suppliers behind each register entry. The ECZ-ID DORA & SBOM Pack installs them with this extension: https://marketplace.visualstudio.com/items?itemName=ecocitizenz.eczid-pack-dora-sbom (Open VSX: https://open-vsx.org/extension/ecocitizenz/eczid-pack-dora-sbom)
  • DORA guidance on the ECZ-ID Developer Gateway: https://developers.ecocitizenz.com/dora/
  • Cyber Resilience Passport and DORA vendor credentialing in TrustOps, when the evidence exists and you want a resolver-verifiable result a supervised entity can check without exchanging documents: https://trustops.ecocitizenz.com/start?flow=critical-cyber-resilience and https://trustops.ecocitizenz.com/start?flow=dora-sbom
  • Verified ECZ-ID (£19.99/month) or Assured ECZ-ID (£49.99/month): the public identity every ECZ-ID credential attaches to. Counterparties check it in Resolver: https://trustops.ecocitizenz.com/start#parent-tiers

View all relevant DORA / resilience products: https://developers.ecocitizenz.com/dora-sbom-suite/

TrustOps handles setup and checkout. This extension runs no payment, issues no ECZ-ID and creates no Resolver proof. Prices shown were read from the TrustOps catalogue on 2026-09-03; TrustOps shows the current price before any payment.

Privacy and permissions

Question Answer
Files read Filenames and paths during a scan you start
File contents read No. Detection is filename and path only
Anything uploaded No source, prompts, secrets or tool payloads leave your device
Network destinations Only links you choose to open, and an optional user-initiated public-interface refresh (HTTPS GET to an allowlisted ECZ-ID host)
Telemetry None
Retention None. Reports are written only when you ask, into your workspace
Workspace Trust Respected. No filesystem access in Restricted Mode

The privacy notice ships inside the extension: run ECZ-ID DORA Readiness: Open Privacy Notice (bundled).

Frequently asked questions

Is this extension free? Yes. Every local review is free, with no sign-in and no purchase.

Does it upload my source code? No. Detection is filename and path only. No source, prompts, secrets or tool payloads leave your device, and there is no telemetry.

Does a missing item mean something is wrong? No. "Evidence not observed" is neutral. It tells you where a reviewer will find a gap in this workspace; your local policy decides what is sufficient.

Is the register of information only for financial entities? The obligation sits with the financial entity, but the entries describe its ICT providers. Providers are asked for the underlying evidence, which is why this review puts the register first.

What happens when the public interface service is unavailable? It keeps working from a bundled contract. A refresh is optional and user-initiated.

What it does not do

  • No source, prompt or secret upload, and no telemetry.
  • Local evidence review and routing only. It does not issue ECZ-ID proof, activate services, grant access, or make approval, safety, insurance or compliance decisions.
  • Makes no safety, approval, certification or compliance claim about you or your suppliers.
  • Runs no checkout or payment. Commercial actions happen only in TrustOps.

Install and first use

  1. In your editor's Extensions view, search for ECZ-ID DORA Readiness (publisher EcoCitizenz) and install it.
  2. Open a project and trust the workspace.
  3. Run ECZ-ID DORA Readiness: Review / Scan Workspace and read the evidence review.

Python / CLI

Prefer Python, CI or terminal automation?

python -m pip install ecz-id-dora
ecz-id-dora --help
  • Matching Python package: https://pypi.org/project/ecz-id-dora/
  • All ECZ-ID Python tools: https://developers.ecocitizenz.com/python

The Python tools run locally and inspect, explain and route only, the same role boundary as this extension.

Machine-readable facts

Field Value
Product ECZ-ID DORA Readiness
Identity ecocitizenz.eczid-dora-readiness
Publisher EcoCitizenz
License Free; see the bundled LICENSE.txt
Version 0.3.0
Page family functional-extension
Purpose Find the ICT resilience evidence gaps before a regulator, auditor or customer finds them.
Regulation Regulation (EU) 2022/2554 (DORA), applied since 17 January 2025 (Article 64): https://eur-lex.europa.eu/eli/reg/2022/2554/oj
Applicable audiences ICT third-party service providers to EU financial entities; operational-resilience, ICT risk and third-party risk leads; internal audit, procurement and outsourcing teams; engineering leads
Applicable scenarios a supervised entity asks for register evidence; an auditor asks for the ICT third-party register; yearly reporting on ICT third-party arrangements; supplier questionnaires on incidents and continuity
Primary command ECZ-ID DORA Readiness: Review / Scan Workspace
Inputs ICT third-party register, operational-resilience / ICT risk policy, incident-response evidence, resilience-testing / continuity evidence, ICT contractual arrangements / exit plans
Outputs Observed / not-observed evidence with why-it-matters and review-next guidance, a deterministic Review Priority, an evidence summary, a local JSON + Markdown report, and at most three contextual routes
Result states EVIDENCE OBSERVED; EVIDENCE NOT OBSERVED; REVIEW RECOMMENDED; REVIEW REQUIRED; Review Priority LOW / NORMAL / ELEVATED / HIGH
Data handling Filenames and paths only; no source / prompt / secret upload; no telemetry; retention none
Network behaviour Only links you open, plus an optional user-initiated public-interface refresh (GET, allowlisted ECZ-ID host)
Limitations Does not read document contents, issue proof, approve, certify, insure, determine compliance, or run checkout
Canonical machine discovery https://machine.ecocitizenz.org/.well-known/ecz-machine.json
Public proof https://resolver.ecocitizenz.org
Documentation https://developers.ecocitizenz.com
Product page https://developers.ecocitizenz.com/dora/
Supported setup https://trustops.ecocitizenz.com/start
DORA flow in TrustOps https://trustops.ecocitizenz.com/start?flow=dora-sbom
Re-check Re-run before reliance

Links and support

  • Product page and guidance: https://developers.ecocitizenz.com/dora/
  • This listing on both registries: https://marketplace.visualstudio.com/items?itemName=ecocitizenz.eczid-dora-readiness and https://open-vsx.org/extension/ecocitizenz/eczid-dora-readiness
  • Resolver (read-only proof): https://resolver.ecocitizenz.org
  • TrustOps (supported setup): https://trustops.ecocitizenz.com/start
  • Questions: the Q&A tab of this listing, or https://developers.ecocitizenz.com/faq/
  • Privacy: the bundled PRIVACY.md

ECZ-ID is independent trust infrastructure. Third-party names describe compatible ecosystems only and do not imply endorsement or affiliation. Local policy decides whether the evidence you review is sufficient.

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft