DORA Compliance Checklist | Sonatype Guide

DORA Compliance Checklist

Download the Checklist

DORA, an EU-wide requirement passed in 2024 and to be enforced starting in January 2025, requires financial entities to put measures in place to protect against cybersecurity threats and disruptions to ICT services. Two elements of DORA stand out: the ICT Risk Management Framework and Regulation 56, which emphasises the importance of open source analysis.

This guide can help you determine how prepared your organisation is to comply with DORA’s key components.

DORA Compliance Checklist: Navigate New Cybersecurity Measures

ICT Risk Management

Incident Reporting

Information Security

Business Continuity and Disaster Recovery

Resilience Testing

SBOM Creation and Maintenance

How Sonatype Can Help

Monitoring the health and policy compliance of open source components is essential to meeting these DORA requirements. Sonatype is the industry’s only comprehensive, proactive solution for end-to-end software supply chain security, with more than 300 million open source components catalogued. Sonatype also provides constant updates for third-party policies, and an easy-to-use administrative UI simplifies policy management.

DORA is just one part of the global trend of cybersecurity requirements. To learn more about how we can help you ensure compliance, check out our DORA User's Guide to Compliance.