Cyber · DORA Year-2
DORA Year-2 Maturity
Year-2 supervisory expectations are moving from "is the register in place?" to "is it correct, complete, and does the institution actually run it?". This board records the four supervisory pivots: register completeness, critical third-party concentration, threat-led penetration testing, and incident-reporting SLA performance.
Pivot 1
ICT register completeness
Pivot 2
Critical third-party concentration
Pivot 3
TLPT (Threat-led Pen Test)
Pivot 4
Incident SLA + exit strategy
Entity feed
| Entity | Jurisdiction | Register | Top-1 conc. | Top-3 conc. | TLPT | SLA breaches | Grade |
|---|---|---|---|---|---|---|---|
| Loading… | |||||||