{
  "attribution": {
    "source": "legal.exploreworldai.com",
    "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora",
    "cite_as": "NovaCopilot, legal.exploreworldai.com (https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora)",
    "license": "https://legal.exploreworldai.com/revision",
    "version": "legal-2026-10-09",
    "fingerprint": "ewai:se:4e88a1",
    "proof": "sha256:2f7069501fb9f8b7a5e177cc2d392217340a1359395c2b930d1fe847c7217ccd",
    "jurisdiction": "se",
    "lang": "en",
    "publisher": "NovaCopilot by ExploreWorld Legal",
    "terms": "https://legal.exploreworldai.com/om"
  },
  "brand_source": "Source: NovaCopilot",
  "object_type": "sme_kit",
  "object_id": "sme_kit:eu:dora",
  "schema_version": "1",
  "schema": "https://legal.exploreworldai.com/api/public/v1/schemas/sme_kit",
  "url": "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora",
  "source": "NovaCopilot",
  "item": {
    "coverage": {
      "complete": 8,
      "total": 10,
      "label": "8 of 10 answers ready",
      "reasons": {
        "precedents": "insufficient_cases",
        "outcome_patterns": "insufficient_cases"
      }
    },
    "subject": "eu:dora",
    "act": "dora",
    "article": null,
    "answers": [
      {
        "key": "obligations",
        "status": "ready",
        "ids": [
          "obligation:eu:dora-art-11-financial-entity",
          "obligation:eu:dora-art-17-financial-entity",
          "obligation:eu:dora-art-19-financial-entity",
          "obligation:eu:dora-art-24-financial-entity",
          "obligation:eu:dora-art-26-financial-entity",
          "obligation:eu:dora-art-28-financial-entity",
          "obligation:eu:dora-art-30-financial-entity",
          "obligation:eu:dora-art-5-financial-entity",
          "obligation:eu:dora-art-6-financial-entity"
        ],
        "sha256": "ef5dfdd0a3e287a43ff469208d2da38a417f21436aec5ee34c23937fa70a1c00"
      },
      {
        "key": "responsibility",
        "status": "ready",
        "ids": [
          "obligation:eu:dora-art-11-financial-entity",
          "obligation:eu:dora-art-17-financial-entity",
          "obligation:eu:dora-art-19-financial-entity",
          "obligation:eu:dora-art-24-financial-entity",
          "obligation:eu:dora-art-26-financial-entity",
          "obligation:eu:dora-art-28-financial-entity",
          "obligation:eu:dora-art-30-financial-entity",
          "obligation:eu:dora-art-5-financial-entity",
          "obligation:eu:dora-art-6-financial-entity"
        ],
        "sha256": "83d3b63c88a211f58f2427f5c54dde2ea3cf9968ca57116fa2dce7171afdea28"
      },
      {
        "key": "sanctions",
        "status": "ready",
        "ids": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "sha256": "c1949045e8d7b5c2a5bd647366ad5532d0e34bced050dade64b0cd07f8228976"
      },
      {
        "key": "risks",
        "status": "ready",
        "ids": [
          "risk_chain:eu:dora--financial-entity"
        ],
        "sha256": "738e21eae5d66f16f71f9d1ca074429e149423435feee41f1497e33bb70077a6"
      },
      {
        "key": "exceptions",
        "status": "ready",
        "ids": [
          "exception:eu:dora-microenterprise"
        ],
        "sha256": "2c476763074be36389da0fcde222bf714ed6186b99fe561277bdbe6435d27795"
      },
      {
        "key": "documentation",
        "status": "ready",
        "ids": [
          "documentation_requirement:eu:dora"
        ],
        "sha256": "4805a41eef27c5445f01dc907fcdfce189209072df1872ad2444b468a907e9c6"
      },
      {
        "key": "checklist",
        "status": "ready",
        "ids": [
          "obligation:eu:dora-art-11-financial-entity",
          "obligation:eu:dora-art-17-financial-entity",
          "obligation:eu:dora-art-19-financial-entity",
          "obligation:eu:dora-art-24-financial-entity",
          "obligation:eu:dora-art-26-financial-entity",
          "obligation:eu:dora-art-28-financial-entity",
          "obligation:eu:dora-art-30-financial-entity",
          "obligation:eu:dora-art-5-financial-entity",
          "obligation:eu:dora-art-6-financial-entity"
        ],
        "sha256": "e987ecb0be10d791d945cf4ddbf2b2694a7bf322c8c38f7cbc4f9ba96e33a97f"
      },
      {
        "key": "precedents",
        "status": "gap",
        "ids": [],
        "sha256": null
      },
      {
        "key": "provision_links",
        "status": "ready",
        "ids": [
          "provision_link:eu:dora"
        ],
        "sha256": "e77d30c7d924357da2d25985d1fdd57d72f02a23d4c91d2ade401af8d9061ad7"
      },
      {
        "key": "outcome_patterns",
        "status": "gap",
        "ids": [],
        "sha256": null
      }
    ],
    "answers_full": [
      {
        "question": "Which obligations apply?",
        "key": "obligations",
        "status": "ready",
        "answer": "9 obligations: The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it.; Maintain a sound, comprehensive and documented ICT risk management framework.; Put in place an ICT business continuity policy with response and recovery plans. …",
        "ids": [
          "obligation:eu:dora-art-11-financial-entity",
          "obligation:eu:dora-art-17-financial-entity",
          "obligation:eu:dora-art-19-financial-entity",
          "obligation:eu:dora-art-24-financial-entity",
          "obligation:eu:dora-art-26-financial-entity",
          "obligation:eu:dora-art-28-financial-entity",
          "obligation:eu:dora-art-30-financial-entity",
          "obligation:eu:dora-art-5-financial-entity",
          "obligation:eu:dora-art-6-financial-entity"
        ],
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-11-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-17-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-19-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-24-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-26-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-28-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-30-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-5-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/obligation/eu:dora-art-6-financial-entity"
        ],
        "sha256": "ef5dfdd0a3e287a43ff469208d2da38a417f21436aec5ee34c23937fa70a1c00",
        "reason": null
      },
      {
        "question": "Who is responsible?",
        "key": "responsibility",
        "status": "ready",
        "answer": "Responsible roles: financial-entity.",
        "ids": [
          "obligation:eu:dora-art-11-financial-entity",
          "obligation:eu:dora-art-17-financial-entity",
          "obligation:eu:dora-art-19-financial-entity",
          "obligation:eu:dora-art-24-financial-entity",
          "obligation:eu:dora-art-26-financial-entity",
          "obligation:eu:dora-art-28-financial-entity",
          "obligation:eu:dora-art-30-financial-entity",
          "obligation:eu:dora-art-5-financial-entity",
          "obligation:eu:dora-art-6-financial-entity"
        ],
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-11-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-17-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-19-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-24-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-26-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-28-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-30-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-5-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/compliance_effect/eu:dora-art-6-financial-entity"
        ],
        "sha256": "83d3b63c88a211f58f2427f5c54dde2ea3cf9968ca57116fa2dce7171afdea28",
        "reason": null
      },
      {
        "question": "Which sanctions can be triggered?",
        "key": "sanctions",
        "status": "ready",
        "answer": "2 sanctions, up to 1 % of global turnover.",
        "ids": [
          "sanction:eu:dora-art-35-6",
          "sanction:eu:dora-art-50"
        ],
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/sanction/eu:dora-art-35-6",
          "https://legal.exploreworldai.com/api/public/v1/obj/sanction/eu:dora-art-50"
        ],
        "sha256": "c1949045e8d7b5c2a5bd647366ad5532d0e34bced050dade64b0cd07f8228976",
        "reason": null
      },
      {
        "question": "What are the risks?",
        "key": "risks",
        "status": "ready",
        "answer": "Risk level medium across 1 roles.",
        "ids": [
          "risk_chain:eu:dora--financial-entity"
        ],
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/risk_chain/eu:dora--financial-entity"
        ],
        "sha256": "738e21eae5d66f16f71f9d1ca074429e149423435feee41f1497e33bb70077a6",
        "reason": null
      },
      {
        "question": "Which exceptions apply?",
        "key": "exceptions",
        "status": "ready",
        "answer": "1 exceptions, e.g. Small and non-interconnected investment firms, certain payment and e-money institutions exempted under PSD2/EMD, and other entities listed in art. 16.1.",
        "ids": [
          "exception:eu:dora-microenterprise"
        ],
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-11-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-17-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-19-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-24-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-26-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-28-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-30-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-5-financial-entity",
          "https://legal.exploreworldai.com/api/public/v1/obj/exception/eu:dora-art-6-financial-entity"
        ],
        "sha256": "2c476763074be36389da0fcde222bf714ed6186b99fe561277bdbe6435d27795",
        "reason": null
      },
      {
        "question": "Which documentation is required?",
        "key": "documentation",
        "status": "ready",
        "answer": "Keep: Written policy or plan, Report to authority, Written agreement.",
        "ids": [
          "documentation_requirement:eu:dora"
        ],
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/documentation_requirement/eu:dora"
        ],
        "sha256": "4805a41eef27c5445f01dc907fcdfce189209072df1872ad2444b468a907e9c6",
        "reason": null
      },
      {
        "question": "What does a compliance checklist look like?",
        "key": "checklist",
        "status": "ready",
        "answer": "9 checks across 1 roles.",
        "ids": [
          "obligation:eu:dora-art-11-financial-entity",
          "obligation:eu:dora-art-17-financial-entity",
          "obligation:eu:dora-art-19-financial-entity",
          "obligation:eu:dora-art-24-financial-entity",
          "obligation:eu:dora-art-26-financial-entity",
          "obligation:eu:dora-art-28-financial-entity",
          "obligation:eu:dora-art-30-financial-entity",
          "obligation:eu:dora-art-5-financial-entity",
          "obligation:eu:dora-art-6-financial-entity"
        ],
        "urls": [],
        "sha256": "e987ecb0be10d791d945cf4ddbf2b2694a7bf322c8c38f7cbc4f9ba96e33a97f",
        "reason": null
      },
      {
        "question": "Which precedents support the answer?",
        "key": "precedents",
        "status": "gap",
        "answer": null,
        "ids": [],
        "urls": [],
        "sha256": null,
        "reason": "insufficient_cases"
      },
      {
        "question": "How are the rules linked to other rules?",
        "key": "provision_links",
        "status": "ready",
        "answer": "Provision relations for dora.",
        "ids": [
          "provision_link:eu:dora"
        ],
        "urls": [
          "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/eu:dora"
        ],
        "sha256": "e77d30c7d924357da2d25985d1fdd57d72f02a23d4c91d2ade401af8d9061ad7",
        "reason": null
      },
      {
        "question": "How do courts usually rule in similar situations?",
        "key": "outcome_patterns",
        "status": "gap",
        "answer": null,
        "ids": [],
        "urls": [],
        "sha256": null,
        "reason": "insufficient_cases"
      }
    ],
    "checklist": [
      {
        "step": 1,
        "role": "financial-entity",
        "check": "The management body defines, approves and oversees the ICT risk management framework and bears ultimate responsibility for it.",
        "provision": "dora 5",
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      },
      {
        "step": 2,
        "role": "financial-entity",
        "check": "Maintain a sound, comprehensive and documented ICT risk management framework.",
        "provision": "dora 6",
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      },
      {
        "step": 3,
        "role": "financial-entity",
        "check": "Put in place an ICT business continuity policy with response and recovery plans.",
        "provision": "dora 11",
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      },
      {
        "step": 4,
        "role": "financial-entity",
        "check": "Define and implement an ICT-related incident management process.",
        "provision": "dora 17",
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      },
      {
        "step": 5,
        "role": "financial-entity",
        "check": "Report major ICT-related incidents to the competent authority.",
        "provision": "dora 19",
        "deadline": "24 hours",
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      },
      {
        "step": 6,
        "role": "financial-entity",
        "check": "Establish a digital operational resilience testing programme.",
        "provision": "dora 24",
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      },
      {
        "step": 7,
        "role": "financial-entity",
        "check": "Carry out threat-led penetration testing where identified by the competent authority.",
        "provision": "dora 26",
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      },
      {
        "step": 8,
        "role": "financial-entity",
        "check": "Manage ICT third-party risk and keep a register of information on all ICT service contracts.",
        "provision": "dora 28",
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      },
      {
        "step": 9,
        "role": "financial-entity",
        "check": "Include the key contractual provisions in contracts with ICT third-party service providers.",
        "provision": "dora 30",
        "deadline": null,
        "if_not": [
          "sanction:eu:dora-art-50",
          "sanction:eu:dora-art-35-6"
        ],
        "done": false
      }
    ],
    "links": {
      "act_kit": null,
      "provisions": [
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-5",
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-6",
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-11",
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-17",
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-19",
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-24",
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-26",
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-28",
        "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora--art-30"
      ],
      "case_kits": [],
      "documentation": "https://legal.exploreworldai.com/api/public/v1/obj/documentation_requirement/eu:dora",
      "list": "https://legal.exploreworldai.com/api/public/v1/sme-kits",
      "changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes?type=sme_kit"
    },
    "method": "Ten fixed business questions answered from existing deterministic registers. Gaps carry fixed reason codes. No model writes anything.",
    "hash": "fdc345fedfd146622e232a447c373c68f99414d7b0d683aab80cd6b3a853baf6"
  },
  "links": {
    "provisions": "https://legal.exploreworldai.com/api/public/v1/obj/provision_link/eu:dora",
    "case_law": {
      "outcome": "https://legal.exploreworldai.com/api/public/v1/obj/outcome/eu:dora",
      "outcome_pattern": "https://legal.exploreworldai.com/api/public/v1/obj/outcome_pattern/eu:dora"
    },
    "evidence": {
      "provenance": null,
      "chain_verify": "https://legal.exploreworldai.com/api/public/v1/changes/verify",
      "object_changes": "https://legal.exploreworldai.com/api/public/v1/objects/changes"
    },
    "compact": "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora?view=compact",
    "representations": {},
    "machine_languages": [
      "en",
      "sv"
    ],
    "ref": "eu:dora"
  },
  "watch": {
    "changes": "https://legal.exploreworldai.com/api/public/v1/changes",
    "whats_new": "https://legal.exploreworldai.com/api/public/v1/whats-new?jurisdiction=eu",
    "conditional": "Send If-None-Match with the ETag; unchanged objects return 304 without body.",
    "recheck_after_seconds": 86400
  },
  "hash": "sha256:2f7069501fb9f8b7a5e177cc2d392217340a1359395c2b930d1fe847c7217ccd",
  "version": "legal-2026-10-09",
  "expires": "2026-10-10T00:00:00.000Z",
  "dependency": {
    "index_version": "legal-2026-10-09+legal-2026-10-09+2026-10-09T21:48:48",
    "content_hash": "sha256:2f7069501fb9f8b7a5e177cc2d392217340a1359395c2b930d1fe847c7217ccd",
    "revalidate_after": "2026-10-10T00:58:38.278Z",
    "max_copy_age_seconds": 3600,
    "policy": "revalidate-required; attribution-preferred",
    "changelog": "https://legal.exploreworldai.com/api/public/v1/dependency",
    "verify": "https://legal.exploreworldai.com/api/public/v1/verify",
    "stale_copy_invalid": true
  },
  "canonical": "https://legal.exploreworldai.com/api/public/v1/obj/sme_kit/eu:dora",
  "disclaimer": "Source reference with official identifier. Not legal advice and not a compliance decision.",
  "content_notice": {
    "legal_advice": false,
    "nature": "Source register. Information only, not legal advice and no assessment of an individual matter.",
    "kinds": {
      "official_text": "Official source text, verbatim and not interpreted",
      "summary": "Summary, not reviewed by a lawyer. Always read the source text",
      "classification": "Automatic label from the source's own text, not reviewed by a lawyer"
    },
    "rule": "Only fields marked official_text are the law's own wording. Everything else points to it.",
    "report_error": "https://legal.exploreworldai.com/api/public/v1/corrections",
    "ai_act_declaration": "https://legal.exploreworldai.com/api/public/v1/ai-act-declaration"
  },
  "usageInfo": "https://legal.exploreworldai.com/citering"
}