DORA
RTS/ITS Compliance Checklisten
Alle DORA RTS und ITS mit detaillierten Requirements, Evidence-Zuordnung und Implementierungsstatus.
Hinweis: Die RTS/ITS-Checklisten basieren auf den veröffentlichten Delegierten Rechtsakten und technischen Durchführungsstandards (Stand 2026).
8 Requirements
6 Requirements
6 Requirements
4 Requirements
5 Requirements
5 Requirements
3 Requirements
5 Requirements
5 Requirements
9
RTS/ITS Categories
47
Total Requirements
4
Applicable Scopes
7
RTS/ITS Instruments
Scope Filter:
RTS on Digital Operational Resilience Testing (Art. 24-25)
RTS 2024/1775
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| RTS-TST-01 | Testprogramm nach Art. 24 Abs. 1 | All financial entities | Testing Policy |
| RTS-TST-02 | Risikobasierte Testfrequenz | All financial entities | Frequency Matrix |
| RTS-TST-03 | Testarten nach ICT-Asset-Klasse | All financial entities | Test Matrix |
| RTS-TST-04 | TLPT-Durchführung alle 3 Jahre (EE) | Systemically important | TLPT Report |
| RTS-TST-05 | Test Coverage — kritische Systeme | All financial entities | Coverage Report |
| RTS-TST-06 | Unabhängigkeit der Tester | Systemically important | Independence Declaration |
| RTS-TST-07 | Testdokumentation und Aufbewahrung | All financial entities | Test Archive |
| RTS-TST-08 | Management-Review der Testergebnisse | All financial entities | Review Minutes |
RTS on Incident Classification (Art. 17-18)
RTS 2024/1774
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| RTS-INC-01 | Incident-Klassifikation nach DORA-Kriterien | All financial entities | Classification Matrix |
| RTS-INC-02 | Initiale Meldung innerhalb 24h | All financial entities | Incident Log |
| RTS-INC-03 | Interim-Meldung nach 72h | All financial entities | Incident Log |
| RTS-INC-04 | Abschlussmeldung nach 1 Monat | All financial entities | Final Report |
| RTS-INC-05 | Schwellenwerte für schwerwiegende Vorfälle | All financial entities | Threshold Matrix |
| RTS-INC-06 | Kundenbenachrichtigung bei wesentlichen Vorfällen | All financial entities | Customer Notification Log |
RTS on Subcontracting of Critical ICT Services (Art. 28-30)
RTS 2024/1776
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| RTS-SUB-01 | Vorherige Genehmigung für Sub-Auslagerungen | All financial entities | Approval Record |
| RTS-SUB-02 | Risikoanalyse vor Sub-Auslagerung | All financial entities | Risk Assessment |
| RTS-SUB-03 | Vertragliche Anforderungen an Sub-Provider | All financial entities | Contract Clause |
| RTS-SUB-04 | Kontinuierliches Monitoring der Sub-Provider | All financial entities | Monitoring Report |
| RTS-SUB-05 | Sub-Provider Registerführung | All financial entities | Sub-Provider Register |
| RTS-SUB-06 | Exit-Strategie bei Sub-Provider-Ausfall | All financial entities | Exit Plan |
ITS on Information Register Standardisation (Art. 28)
ITS 2024/1777
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| ITS-REG-01 | Standardisiertes Informationsregister | All financial entities | Register Export |
| ITS-REG-02 | Registerspalten nach ITS-Vorgabe | All financial entities | Register Schema |
| ITS-REG-03 | Jährliche Aktualisierung | All financial entities | Update Log |
| ITS-REG-04 | Register-Abfragbarkeit für Aufsicht | All financial entities | Access Credentials |
RTS on Threat Intelligence & Information Sharing (Art. 19-20)
RTS 2024/1778
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| RTS-TI-01 | Threat Intelligence Gathering Framework | Large entities | Threat Intel Policy |
| RTS-TI-02 | Information Sharing Arrangements | All financial entities | Sharing Agreement |
| RTS-TI-03 | Threat Intelligence Quality Assessment | Large entities | Quality Metrics |
| RTS-TI-04 | Cross-Border Intelligence Sharing | Large entities | Cross-Border Protocol |
| RTS-TI-05 | Automatisierte Bedrohungsanalyse | Large entities | Automation Report |
ITS on Penetration Testing Standards (Art. 24-25)
ITS 2024/1779
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| ITS-PT-01 | Penetration Testing Methodology | All financial entities | Testing Methodology |
| ITS-PT-02 | Test Scope Definition | All financial entities | Scope Document |
| ITS-PT-03 | Vulnerability Classification | All financial entities | Classification Scheme |
| ITS-PT-04 | Remediation Tracking | All financial entities | Remediation Log |
| ITS-PT-05 | Test Report Standards | All financial entities | Report Template |
RTS on Simplified ICT Risk Management Framework (Art. 4-5)
RTS 2024/1780
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| RTS-RMF-01 | Simplified Risk Assessment Methodology | Small entities | Risk Methodology |
| RTS-RMF-02 | Proportional Control Framework | Small entities | Control Matrix |
| RTS-RMF-03 | Simplified Incident Reporting | Small entities | Incident Template |
ITS on Threat-Led Penetration Testing (Art. 24-25)
ITS 2024/1781
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| ITS-TLPT-01 | TLPT Threat Intelligence Input | Systemically important | Threat Intel Package |
| ITS-TLPT-02 | Red Team Testing Framework | Systemically important | Red Team Charter |
| ITS-TLPT-03 | Rules of Engagement (RoE) | Systemically important | RoE Document |
| ITS-TLPT-04 | TLPT-Ergebnisbericht und Maßnahmen | Systemically important | TLPT Findings Report |
| ITS-TLPT-05 | TLPT-Wiederholungsturnus (max. 3 Jahre) | Systemically important | Test Schedule |
RTS on Digital Operational Resilience Framework (Art. 6-11)
RTS 2024/1782
| ID | Requirement | Scope | Evidence-Typ |
|---|---|---|---|
| RTS-DOPS-01 | ICT-Risikomanagement-Rahmenwerk | All financial entities | ICT Risk Policy |
| RTS-DOPS-02 | Identifikation kritischer ICT-Dienste | All financial entities | Critical Services Register |
| RTS-DOPS-03 | ICT-Business-Continuity-Pläne | All financial entities | BCP Documentation |
| RTS-DOPS-04 | Backup- und Wiederherstellungsverfahren | All financial entities | Backup Policy |
| RTS-DOPS-05 | Operationale Resilienz-Kennzahlen | Large entities | KPI Dashboard |
Referenzen
- RTS 2024/1775 — Testing (ABl. L 1775, 2024)
- RTS 2024/1774 — Incident Classification (ABl. L 1774, 2024)
- RTS 2024/1776 — Subcontracting (ABl. L 1776, 2024)
- ITS 2024/1777 — Information Register (ABl. L 1777, 2024)
- RTS 2024/1778 — Threat Intelligence (ABl. L 1778, 2024)
- ITS 2024/1779 — Penetration Testing (ABl. L 1779, 2024)
- RTS 2024/1780 — Simplified ICT Risk Management (ABl. L 1780, 2024)
- Alle RTS/ITS gelten ab 17. Januar 2025 direkt in den Mitgliedstaaten.