Financial services

Digital Operational Resilience Act

Regulation (EU) 2022/2554 European Union Applicable since 17 January 2025

Published Reviewed

What is DORA?

DORA requires in-scope financial entities to manage ICT risk, report major incidents, test operational resilience and control risks arising from technology providers.

At a glance
JurisdictionEuropean Union
AuthorityRegulation (EU) 2022/2554
Current statusApplicable since 17 January 2025
Reviewed

Why it matters operationally

DORA has been applicable law since 17 January 2025 for more than twenty categories of financial entities — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and more. It moves ICT risk from the IT department to the management body: the board is formally responsible for the ICT risk framework. And the register of information covering every ICT third-party contract is not an internal artefact — competent authorities collect it.

Are you aware?

The dates that bind

17 Jan 2025

DORA has applied in full since January 2025

ICT risk management, incident classification and reporting, resilience testing and third-party oversight are live obligations, not a programme to plan.

April 2025

Register collections recur

Competent authorities collect entities’ registers of ICT third-party contracts — the first EU-wide exercise ran in April 2025, and it recurs. An incomplete register is a visible gap, not a private one.

Every 3 years

The threat-led penetration testing cycle

Entities designated for TLPT must run threat-led penetration tests at least every three years, aligned with the TIBER-EU framework — with findings and remediation tracked to closure.

Where to start

  1. 1

    Confirm which DORA entity category applies to you and whether the proportionality provisions change your obligations.

  2. 2

    Build the register of information: every ICT third-party contract, mapped to the functions it supports and flagged where a critical or important function depends on it.

  3. 3

    Stand up the incident path — classification criteria, report templates and an escalation chain fast enough for the initial-report windows.

Authority links

Read the official sources

The official text is the authority. This guide is only a short orientation for operational planning.

Common questions

Frequently asked questions

Who does DORA apply to?

More than twenty categories of financial entities listed in Article 2 — credit institutions, payment and e-money institutions, investment firms, insurers and reinsurers, fund managers, and crypto-asset service providers authorised under MiCA, among others. Critical ICT third-party providers face their own EU-level oversight regime.

What is the register of information?

A structured register of all contractual arrangements with ICT third-party providers, distinguishing those that support critical or important functions (Article 28). Competent authorities collect it — the first EU-wide exercise ran in 2025.

How fast must incidents be reported?

Major ICT-related incidents follow a three-step scheme — initial, intermediate and final reports — on tight windows set by the technical standards, with the initial notification due within hours of classification, not days.

Does cloud concentration risk matter under DORA?

Directly. DORA requires concentration-risk assessment, documented exit strategies for providers supporting critical functions, and specific contractual clauses (Article 30) including audit and access rights.

Side by side

Operational deep dives

Work through the decision, not just the definition.

Key terms in this guide

A quick self-check

Are you ready?

  • Is your register of information complete enough to submit tomorrow morning?
  • Do your critical-provider contracts contain the Article 30 clauses — and is the exit strategy behind them tested or theoretical?
  • Has the management body formally approved the ICT risk framework within the last year?
  • Do you know the date of your last resilience test, and the scheduled date of the next one?

Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.

This guide is general information about public law, not legal advice, and does not create a client relationship. Rules change and apply differently by situation. Verify the current official source and seek qualified advice where needed.