Questionnaire standards

The DORA questionnaire — and why you keep receiving a different one

DORA is not a questionnaire; it is a regulation that produces questionnaires. If you supply ICT services to a financial entity, you will receive them — from every client separately, each in its own shape.

In short

Unlike CAIQ or VDA ISA there is no single DORA form. Every financial entity derives its own from the regulation, and the provider answers all of them. The industry has recognised the problem itself: the Austrian Economic Chambers, with a KSÖ working group, published a modular ICT standard questionnaire explicitly so that providers would stop filling in an endless variety of forms. It has not become universal yet.

DORA at a glance

Legal basisRegulation (EU) 2022/2554, applicable across the European Union since 17 January 2025.
Who it regulatesFinancial entities. ICT providers are not themselves addressees, but are bound through contract.
Minimum contract termsArticle 30 DORA sets out what an agreement on ICT services must contain; the European supervisory authorities supplement it through regulatory technical standards.
SubcontractingDelegated Regulation (EU) 2024/1773 of 25 June 2024 governs the use of ICT services supporting critical or important functions.
Register of informationFinancial entities maintain a register of their ICT third-party services — and collect the entries for it from the provider.
FormatNo single one. Usually Excel or a client portal; increasingly also the modular ICT standard questionnaire.

How the file is put together

Because every institution builds its own form, the shape is unstable — the topics are not.

A classification usually comes first: does your service support a critical or important function? That answer sets the depth of everything after it.
One block collects master data for the client's register of information — legal entity, locations, identifiers. That is input to their reporting duty, not a security assessment.
The substantive part follows the regulation's topics and repeats itself across clients to a large degree.
A contractual section works through the Article 30 minimum terms as assurances — here you are not describing, you are undertaking.

What Compliance Concierge does with a DORA

The form is read as a workbook, no matter which institution built it.
Recurring topics are proposed from your own answer library — with DORA that is where the leverage sits, because the questions repeat across clients and only the shape changes.
Every draft carries its evidence from your uploaded documents.
Article 30 contractual assurances are never auto-affirmed but held for a human: those are legally binding undertakings, not descriptions of fact.
Approved answers are written back into the file you received.

None of this certifies you. The tool drafts answers from the documents you upload, shows the evidence behind each one, and refuses to export anything a person has not signed off. Where your documents do not cover a control, it says so instead of filling the cell.

This page provides orientation and does not replace legal advice. Whether and how a rule applies to your company depends on the individual case.

The topic blocks — and the four that hold providers up

The regulation groups its requirements into several areas: ICT risk management, handling and reporting of ICT-related incidents, testing of digital operational resilience, ICT third-party risk management, and information sharing. Four points within them cost the most time in practice.

Art. 30

Minimum contract terms

What it asks
Whether your contract carries the prescribed elements — service description, processing locations, access and audit rights, grounds for termination.
What answers it
The contract itself, usually as an annex or amendment. Where something is missing, the honest answer is a draft amendment, not an assurance.
Common mistake
Ticking assurances the running contract does not support. That is no longer a questionnaire answer but a legally binding undertaking — it belongs in front of management, not in a spreadsheet.
Subcontracting

Passing work to subcontractors

What it asks
Who you use, where they sit, and whether they support critical or important functions.
What answers it
A current list of subcontractors with service and location, plus the contractual basis for passing work on.
Common mistake
Submitting a stale list. The client carries it forward in their register of information — a discrepancy surfaces at the next reconciliation and casts doubt on everything else you stated.
Incidents

Reporting ICT-related incidents

What it asks
How fast you report, to whom, with what content — and whether you can support the client's own supervisory reporting deadlines.
What answers it
Incident process with deadlines and named contacts, evidence of an exercise or a real incident.
Common mistake
Quoting a general response time without tying it to the client's reporting deadlines. The client is under a clock of their own; they need your input before their own report falls due.
Exit

Exit strategy

What it asks
What happens when the arrangement ends: data return, format, deadlines, transition support.
What answers it
A documented exit plan with deadlines and formats, ideally as part of the contract.
Common mistake
Treating the point as theoretical. For critical or important functions, exit is among the most closely examined areas — a vague answer there delays the entire review.

The regulation has applied directly in every member state since 17 January 2025; there is no national transposition as there is with NIS2. It is supplemented on an ongoing basis by regulatory technical standards from the European supervisory authorities — Delegated Regulation (EU) 2024/1773 on subcontracting being the most consequential for providers so far. Anyone answering these questionnaires should expect questions about passing work to subcontractors to increase rather than diminish.

Frequently asked

Am I subject to DORA as an ICT provider?+

The regulation addresses financial entities. As a provider, the requirements reach you through the contract — your client must agree certain terms and collect certain data, and passes both on. One exception: providers designated critical by the European supervisory authorities fall under a dedicated oversight framework.

Why does every client send a different form?+

Because the regulation describes duties but prescribes no form. Each institution derives its own catalogue. That is precisely why the Austrian Economic Chambers, together with a KSÖ working group, published a modular ICT standard questionnaire — with the stated aim of reducing the duplicated burden on providers.

What does the critical-or-important-function classification mean for me?+

It is your client's classification of your service, and the single biggest lever in the whole form: it drives assessment depth, contractual requirements, and how precisely subcontracting and exit are probed. Ask how the client has classified you before you start filling anything in.

Does ISO 27001 help with DORA?+

For the security portion, considerably — much of the evidence carries over unchanged. For the Article 30 contractual terms, for subcontracting and for the exit strategy, it does not: those are matters of contract and organisation that no security certificate covers.

Other assessments we cover: CAIQ v4, SIG & SIG Lite, HECVAT, VSA, TISAX / VDA ISA, ISO 27001. For the process itself, see the guide to answering security questionnaires. Tools that automate this kind of workbook, compared honestly: Vanta, SafeBase and Conveyor.

Answer your DORA with evidence

Upload your policies and the workbook. Every draft is cited from your own documents, and nothing leaves until you approve it. The first questionnaire is free.