In practice, a dora compliance checklist is a list of things to check and a number of days to check them in, and the second is decided by the first long before anyone opens the list. For a financial entity or its ICT provider under the EU's Digital Operational Resilience Act, the checks run over the ICT risk register, the incident reports, the resilience tests and the third-party register; every item is a sample to take, minutes to spend and a chance of a gap that costs hours to close. The compliance officer who works those figures before the audit is scoped budgets the audit and its aftermath together; the one who does not learns the aftermath's cost from the invoice. This page walks what a dora compliance checklist covers, how to size its days, its expected gaps and its all-in cost, and where the free sheets on this site do that sizing from the programme's own numbers, with no account.
What a dora compliance checklist covers
For a financial entity or its ICT provider under the EU's Digital Operational Resilience Act: the ICT risk register, the incident reports, the resilience tests and the third-party register. Each is a control with evidence behind it, and a checklist is the list of controls with a sample size and a minutes-per-sample figure attached whether or not anyone wrote them down. The audit scope sheet on this site takes systems, controls, samples and minutes and returns the samples, the hours, the days and the coverage the days available give, so the checklist has a size before it has a date.
Gaps, remediation and the all-in cost
An audit finds gaps at a rate the last audit already measured, and every gap costs remediation hours. The audit sheets on this site for HIPAA, GDPR and PCI, and the IT control-testing sheet for a framework, take the item count, the gap rate, the hours per gap and the hourly cost and return the gaps expected, the remediation hours and the cost with the aftermath in it. For DORA the sheet to start with is the incident log sheet. None of them publishes a benchmark rate; each works the programme's own.
What to do with the number
Take it to the budget conversation and to the consultant's proposal. A proposal whose audit days land far from the sheet's is sampling more or less than the programme needs, and a budget that covers the assessment and not the remediation is half a budget. The guide this page supports covers sizing compliance management consulting from the audit scope. Attestvio Pro keeps every audit with its findings and their remediation against the obligations it tested; the sheets stay free.
A checklist, with numbers attached
A checklist is a list of controls to confirm; sized, it is a number of items, minutes and days, with a gap rate and a remediation cost behind it. The audit scope sheet on this site attaches those numbers; the audit sheets attach the gaps and the cost. A checklist worked that way is an audit plan; unworked, it is a document.
Questions people ask about dora compliance checklist
How long does a dora compliance checklist take?
Items times minutes over 60 for the hours, over the hours in an audit day for the days: the audit scope sheet on this site works it from your own systems, controls, samples and minutes with no account, and publishes no benchmark.
What does a dora compliance checklist cost all in?
Assessment hours plus the expected gaps times the remediation hours per gap, times the hourly cost. The audit sheets on this site work it from your own gap rate; the worked examples run from $8,800 to $19,720 for the sizes entered.
Does Attestvio run the dora compliance checklist?
No. Attestvio sizes it and keeps the findings and their remediation against the obligations; the audit itself is your assessor's or your own team's. The sheets are free either way.