npx claudepluginhub abnejllc/grc --plugin dora# DORA Assessment Evaluates organizational readiness for Digital Operational Resilience Act (DORA) compliance. ## Arguments - `$1` - Assessment scope (required: full, pillar-specific, entity-type) - `$2` - Entity classification (optional: credit-institution, payment-institution, investment-firm, crypto-asset-provider, ict-provider) ## DORA Overview **Regulation**: EU Regulation 2022/2554 **Effective Date**: January 17, 2025 **Applicability**: EU financial entities and ICT third-party service providers **Enforcement**: National competent authorities (NCAs) ## Entity Types Subject to DO...
/assessAssesses code, designs, or approaches across dimensions like correctness, maintainability, security, performance; rates 0-10 with pros/cons and recommendations.
/assessAssesses a local repo against a wiki's research and market landscape, producing gap analysis, opportunities, and competitive insights.
/assessAssesses CIS Controls v8 compliance for specified Implementation Group (IG1/IG2/IG3), with optional full, gap-analysis, or specific-control scope.
/assessAssesses HITRUST CSF readiness for specified type (i1, r2, e1) and optional scope, producing readiness score, domain breakdowns, gap analysis, and remediation roadmap.
/assessAssesses US ITAR and EAR export controls compliance readiness across 7 controls each plus jurisdiction determination. Supports itar/ear/both scopes and quick/detailed depths.
/assessAssesses Protected B (PBMM) compliance readiness against ITSG-33 controls, evaluating data residency, access control, MFA, auditing, and encryption in AWS, Azure, GCP regions. Supports classification levels and assessment types.
Evaluates organizational readiness for Digital Operational Resilience Act (DORA) compliance.
$1 - Assessment scope (required: full, pillar-specific, entity-type)$2 - Entity classification (optional: credit-institution, payment-institution, investment-firm, crypto-asset-provider, ict-provider)Regulation: EU Regulation 2022/2554 Effective Date: January 17, 2025 Applicability: EU financial entities and ICT third-party service providers Enforcement: National competent authorities (NCAs)
| Entity Type | Examples | Key Requirements |
|---|---|---|
| Credit Institutions | Banks, lending institutions | Full DORA compliance, advanced testing |
| Payment Institutions | Payment processors, e-money institutions | Digital resilience testing, incident reporting |
| Investment Firms | Broker-dealers, asset managers | ICT risk management, third-party oversight |
| Crypto-Asset Service Providers | Exchanges, wallet providers | Enhanced monitoring, security controls |
| Insurance/Reinsurance | Insurers, reinsurance undertakings | Business continuity, resilience testing |
| ICT Third-Party Providers | Cloud providers, data centers, critical service providers | Oversight framework, contractual requirements |
Comprehensive framework for managing ICT risks across the organization.
Key Requirements:
Detection, management, and reporting of major ICT-related incidents.
Key Requirements:
Major Incident Criteria:
Regular testing to ensure systems can withstand cyber threats and operational disruptions.
Key Requirements:
Testing Types:
Oversight of risks from ICT service providers, especially critical providers.
Key Requirements:
Critical ICT Third-Party Providers:
Voluntary sharing of cyber threat information and intelligence.
Key Requirements:
Overall Readiness Score: Compliance percentage across 5 pillars
Pillar-by-Pillar Analysis:
Gap Identification:
Entity-Specific Requirements: Tailored to organization type
Competent Authority Expectations: NCA-specific guidance
Remediation Roadmap: Phased approach to compliance
Timeline to Compliance: Based on current state
Budget Estimates: Investment needed for compliance
| Deadline | Requirement |
|---|---|
| January 17, 2025 | DORA becomes applicable |
| Within 6 months | Initial risk assessment complete |
| Within 12 months | Full ICT risk management framework |
| Ongoing | Incident reporting (within timelines) |
| Annual | Resilience testing (minimum) |
| Every 3 years | TLPT for significant entities |
European Banking Authority (EBA): Focus on credit institutions European Securities and Markets Authority (ESMA): Investment firms European Insurance and Occupational Pensions Authority (EIOPA): Insurance National Competent Authorities: Country-specific supervision
Inspection Focus Areas:
# Full DORA readiness assessment
/dora:assess full
# Assessment for credit institution
/dora:assess full credit-institution
# Pillar-specific assessment (Third-Party Risk)
/dora:assess pillar-specific
# Assessment by entity type
/dora:assess entity-type payment-institution