The DORA Compliance Cloud Architecture Checklist is a free 35-point assessment that financial entities and ICT third-party providers use to evaluate whether their cloud infrastructure meets the EU Digital Operational Resilience Act (Regulation EU 2022/2554). It maps across six sections — workload portability and exit-readiness, concentration risk, operational resilience, sovereignty and supervisory access, third-party risk and contracting, and risk management and incident handling (the ICT risk-management framework of Articles 5-16 and incident classification and reporting under Articles 17-19). Aenix uses it during DORA-aligned readiness engagements. It pairs with Ænix Private Cloud Platform, built on Cozystack (CNCF Sandbox project, Apache 2.0), which supplies opt-in volume encryption under keys you hold, API audit logging you route and retain yourself, Tenant CRD multi-tenancy you can align with ICT risk classification, and an exit you can rehearse because workloads stay standard Kubernetes objects and virtual machines. Aenix claims no DORA certification: none exists for a platform.
A 35-point checklist for financial entities and ICT third-party providers evaluating DORA compliance posture for their cloud infrastructure. Covers the ICT risk-management framework (Articles 5-16), incident classification and reporting (Articles 17-19), resilience testing and TLPT (Articles 24-27), ICT third-party risk, exit strategies and key contractual provisions (Articles 28-30), encryption and audit-readiness. Used by Ænix during DORA-aligned readiness engagements.
Pairs with: Ænix Private Cloud Platform — built to supply the platform-side controls a DORA programme draws on: keys you hold, audit logging you retain, Tenant CRD multi-tenancy you can align with ICT risk classification, an open supplier record, and an exit you can rehearse. See the DORA evidence page for what it does and does not cover.
What’s in the checklist
6 sections covering 35 specific control checkpoints:
- Workload portability and exit-readiness (5 checkpoints) — exit strategies under Articles 28(8) and 30(3)(f)
- Concentration risk (4 checkpoints) — Articles 28 and 29
- Operational resilience (5 checkpoints) — resilience testing under Articles 24-27, including threat-led penetration testing
- Sovereignty and supervisory access (5 checkpoints)
- Third-party risk and contracting (4 checkpoints) — Articles 28-30
- Risk management and incident handling (12 checkpoints) — the ICT risk-management framework of Articles 5-16 (Article 6 in particular) and incident classification, reporting and handling under Articles 17-19
35-point self-assessmentArticles 5-16 + 17-19Free PDF
feeds
DORA-aligned readiness engagementUsed by Ænix
prepares
Supervisor dialogExit-readiness you can evidence
Who uses this
- CISOs at financial entities preparing supervisor dialog
- Cloud architects at ICT third parties serving financial sector
- Compliance teams scoping DORA-readiness engagements
- Procurement preparing RFI for DORA-aligned services
After downloading
The checklist gives you the working surface to assess your current cloud architecture against DORA. For full DORA-aligned engagement see DORA compliance services page.
Ænix is the team behind Cozystack (CNCF Project), and we offer Ænix Platform — our commercial productized offering based on Cozystack.
Frequently asked questions
What is DORA and who must comply?
DORA (the Digital Operational Resilience Act, Regulation EU 2022/2554) is EU legislation on ICT risk for the financial sector. It applies to financial entities such as banks, insurers, and payment firms, and to their critical ICT third-party providers, including cloud and infrastructure vendors.
What does the checklist cover?
It contains 35 control checkpoints across six groups: workload portability and exit-readiness (5), concentration risk (4), operational resilience (5), sovereignty and supervisory access (5), third-party risk and contracting (4), and risk management plus incident handling (12). Checkpoints carry the DORA article they map to - Articles 28(8) and 30(3)(f) for exit strategies, Article 29 for concentration risk, Articles 5-16 for the ICT risk-management framework, Articles 17-19 for incident classification and reporting, and Articles 26-27 for threat-led penetration testing.
Is the checklist free to download?
Yes. The checklist is a free PDF lead magnet. You request it through the form on this page and receive a download link. Aenix also uses the same checklist during paid DORA-aligned readiness engagements.
How does Ænix Platform help with DORA compliance?
It supplies platform-side controls a DORA programme leans on, not compliance itself — DORA binds financial entities, not platforms, and there is no DORA certificate to hold. Ænix Private Cloud Platform is built on Cozystack and gives you opt-in volume encryption under keys you hold, API audit logging you route and retain, Tenant CRD multi-tenancy you can map to ICT risk classification, an open supplier record, and an exit you can rehearse rather than one promised in a clause. The control-by-control detail, including what the platform does not provide, is on the DORA evidence page.
Does the checklist replace a formal DORA audit?
No. It is a self-assessment working surface to evaluate your current cloud architecture and prepare for supervisor dialog. For a full engagement, see the DORA compliance services page on aenix.io.
Is Cozystack open source and what is its licensing model?
Cozystack is open source under Apache 2.0 with no per-CPU or per-core licensing, and is a CNCF Sandbox project. Aenix offers Ænix Platform, a productized commercial offering, plus services on top, with tiers from Basic at 1,250 USD per month.