DORA
Digital Operational Resilience Act — EU Regulation (EU) 2022/2554
Standard Introduction
The Digital Operational Resilience Act (DORA) is an EU regulation that strengthens the IT security and operational resilience of financial entities. Fully applicable since January 17, 2025, DORA establishes uniform requirements for ICT risk management, incident reporting, resilience testing, and third-party risk management across the entire EU financial sector.
DORA represents a paradigm shift in EU financial regulation by directly overseeing critical ICT service providers and mandating harmonized resilience standards. It covers over 22,000 financial entities and their technology suppliers, ensuring the financial system can withstand, respond to, and recover from severe operational disruptions and cyber threats.
Five Pillars of Resilience
Establishes a harmonized framework across five pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk management, and information sharing.
Third-Party Oversight
Introduces a direct oversight framework for critical ICT third-party service providers (including cloud providers) by European Supervisory Authorities — a first in EU financial regulation.
Incident Reporting
Mandates classification and reporting of major ICT-related incidents to competent authorities, with initial notification within 4 hours and detailed reports within 72 hours.
list_alt Five Key Pillars
- ICT Risk Management — comprehensive framework and governance
- ICT Incident Reporting — classification, notification, and analysis
- Digital Operational Resilience Testing — threat-led penetration testing (TLPT)
- ICT Third-Party Risk Management — due diligence and exit strategies
- Information Sharing — voluntary threat intelligence exchange
- Oversight of critical third-party ICT providers by ESAs
- Proportionality principle based on entity size and risk profile
- Annual review and board-level accountability
Who Needs to Comply?
All EU-regulated financial entities including banks, insurance companies, investment firms, payment institutions, crypto-asset service providers, and their critical ICT service providers. Applies to over 22,000 financial entities and ICT providers in the EU.
Key Requirements
ICT Risk Management Framework
Implement a comprehensive ICT risk management framework including identification, protection, detection, response, and recovery capabilities. Board of directors bears ultimate responsibility.
Incident Classification & Reporting
Classify ICT incidents using defined criteria (data loss, duration, geographic spread, etc.). Report major incidents to competent authorities with initial notification, intermediate, and final reports.
Resilience Testing
Conduct regular digital operational resilience testing including vulnerability assessments, network security reviews, and — for significant entities — threat-led penetration testing (TLPT) at least every three years.
Third-Party Risk Management
Maintain a register of all ICT third-party arrangements. Conduct due diligence, include mandatory contract clauses, and establish exit strategies for critical service providers.
Information Sharing
Participate in voluntary arrangements for sharing cyber threat intelligence and vulnerability information with other financial entities and authorities to strengthen collective resilience.
Implementation Roadmap
Prepare scope, governance & accountability
Confirm which EU financial entities, branches, ICT services, and outsourced providers are in scope. Assign management-body accountability, define the ICT risk governance model, and align legal, risk, security, procurement, resilience, and vendor-management teams around the DORA program.
Gap analysis against DORA pillars
Assess current ICT risk management, incident reporting, resilience testing, third-party risk management, register-of-information, and information-sharing practices against DORA and the applicable technical standards. Prioritize gaps that affect enforceability, reporting deadlines, and critical ICT dependencies.
Implement resilience controls and contracts
Update ICT policies, incident classification, resilience testing, backup and recovery, vulnerability management, and third-party due diligence. Amend critical ICT contracts with DORA-required clauses, exit rights, audit rights, location controls, and cooperation obligations.
Audit, test & maintain operational resilience
Run recurring control testing, scenario exercises, supplier reviews, and management reporting. Maintain the ICT third-party register, rehearse major-incident reporting, and update controls after incidents, regulatory guidance, or major vendor changes.
Compliance Checklist
checklist Governance & ICT risk management
checklist Incidents, testing & continuity
checklist Third-party ICT risk
DORA vs NIS2 vs ISO 27001
DORA is a financial-sector regulation, while NIS2 is a cross-sector cybersecurity directive and ISO 27001 is a certifiable management-system standard.
| Aspect | DORA | NIS2 | ISO 27001 |
|---|---|---|---|
| Nature | EU regulation directly applicable to financial entities | EU directive transposed into national law | International voluntary certification standard |
| Primary focus | ICT operational resilience and third-party ICT risk | Cybersecurity risk management for essential and important entities | Information security management system |
| Incident reporting | Financial-sector ICT incident reporting rules | 24-hour early warning, 72-hour notification, and final report model | No statutory reporting timeline by itself |
| Third-party risk | Detailed ICT contract, register, oversight, and exit requirements | Supply-chain cybersecurity risk measures | Supplier control through ISMS risk treatment |
Common Misconceptions
DORA is only an IT security regulation.
DORA covers operational resilience across governance, risk, legal, procurement, outsourcing, continuity, incident reporting, testing, and technology controls.
ISO 27001 certification is enough for DORA.
ISO 27001 helps with many controls, but DORA adds specific regulatory obligations such as incident reporting, ICT registers, contract clauses, and third-party oversight.
Only banks need to care about DORA.
DORA applies across a wide set of EU financial entities and affects ICT providers that serve those entities.
Penalties & Enforcement
Financial entities face fines up to 2% of total annual worldwide turnover or 1% of average daily global turnover. Critical third-party ICT providers face fines up to EUR 5 million (EUR 500,000 for individuals). Member States may impose criminal penalties for severe violations.
Frequently Asked Questions
When did DORA become applicable?
expand_more
DORA entered into force in January 2023 and became applicable on 17 January 2025 after a two-year implementation period. From that date, in-scope financial entities must comply with the regulation and related regulatory technical standards as they apply.
Who is in scope for DORA?
expand_more
DORA applies broadly to EU financial entities, including banks, insurers, investment firms, payment institutions, trading venues, central securities depositories, crypto-asset service providers, and other regulated financial entities. It also creates oversight for critical ICT third-party service providers.
What are the main DORA pillars?
expand_more
The core pillars are ICT risk management, ICT-related incident reporting, digital operational resilience testing, ICT third-party risk management, and voluntary information sharing. The third-party oversight framework is especially important for critical ICT providers such as major cloud and technology suppliers.
What is the register of information?
expand_more
The register of information is an inventory of ICT third-party arrangements. It records providers, services, functions supported, contractual details, locations, sub-outsourcing, and criticality so regulators and management can understand dependencies and concentration risk.
How does DORA affect ICT contracts?
expand_more
Contracts for ICT services must include DORA-required terms, especially for services supporting critical or important functions. Typical clauses cover service levels, audit and access rights, data location, incident cooperation, termination rights, exit assistance, and sub-outsourcing controls.
What is TLPT under DORA?
expand_more
Threat-led penetration testing is an advanced resilience test using realistic threat scenarios. Only designated financial entities must perform TLPT, generally every three years, with coordination by competent authorities and strict scoping and remediation expectations.
How does DORA relate to NIS2?
expand_more
DORA is the sector-specific operational-resilience regulation for financial entities. Where both DORA and NIS2 could apply, DORA generally operates as the more specific rule for ICT risk matters in the financial sector, while NIS2 may still matter for areas not fully covered.
Do ICT providers become directly regulated under DORA?
expand_more
Critical ICT third-party providers can be designated for direct EU-level oversight. Other ICT providers are not regulated in the same way, but financial customers will impose DORA contract, evidence, incident, audit, and exit requirements on them.
Official Documentation
DORA Regulation (EU) 2022/2554
PDF • EUR-Lex • Full Regulation Text
DORA Official Journal
External Link • eur-lex.europa.eu • Legislative Text
DORA Implementation Guide
External Link • digital-operational-resilience-act.com • Compliance Resources