Financial services
Digital Operational Resilience Act
Published Reviewed
What is DORA?
DORA requires in-scope financial entities to manage ICT risk, report major incidents, test operational resilience and control risks arising from technology providers.
| Jurisdiction | European Union |
|---|---|
| Authority | Regulation (EU) 2022/2554 |
| Current status | Applicable since 17 January 2025 |
| Reviewed |
Why it matters operationally
DORA has been applicable law since 17 January 2025 for more than twenty categories of financial entities — banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and more. It moves ICT risk from the IT department to the management body: the board is formally responsible for the ICT risk framework. And the register of information covering every ICT third-party contract is not an internal artefact — competent authorities collect it.
Are you aware?
The dates that bind
DORA has applied in full since January 2025
ICT risk management, incident classification and reporting, resilience testing and third-party oversight are live obligations, not a programme to plan.
Register collections recur
Competent authorities collect entities’ registers of ICT third-party contracts — the first EU-wide exercise ran in April 2025, and it recurs. An incomplete register is a visible gap, not a private one.
The threat-led penetration testing cycle
Entities designated for TLPT must run threat-led penetration tests at least every three years, aligned with the TIBER-EU framework — with findings and remediation tracked to closure.
Where to start
- 1
Confirm which DORA entity category applies to you and whether the proportionality provisions change your obligations.
- 2
Build the register of information: every ICT third-party contract, mapped to the functions it supports and flagged where a critical or important function depends on it.
- 3
Stand up the incident path — classification criteria, report templates and an escalation chain fast enough for the initial-report windows.
Authority links
Read the official sources
The official text is the authority. This guide is only a short orientation for operational planning.
Common questions
Frequently asked questions
Who does DORA apply to?
More than twenty categories of financial entities listed in Article 2 — credit institutions, payment and e-money institutions, investment firms, insurers and reinsurers, fund managers, and crypto-asset service providers authorised under MiCA, among others. Critical ICT third-party providers face their own EU-level oversight regime.
What is the register of information?
A structured register of all contractual arrangements with ICT third-party providers, distinguishing those that support critical or important functions (Article 28). Competent authorities collect it — the first EU-wide exercise ran in 2025.
How fast must incidents be reported?
Major ICT-related incidents follow a three-step scheme — initial, intermediate and final reports — on tight windows set by the technical standards, with the initial notification due within hours of classification, not days.
Does cloud concentration risk matter under DORA?
Directly. DORA requires concentration-risk assessment, documented exit strategies for providers supporting critical functions, and specific contractual clauses (Article 30) including audit and access rights.
Side by side
Compared against
Operational deep dives
Work through the decision, not just the definition.
Key terms in this guide
A quick self-check
Are you ready?
- Is your register of information complete enough to submit tomorrow morning?
- Do your critical-provider contracts contain the Article 30 clauses — and is the exit strategy behind them tested or theoretical?
- Has the management body formally approved the ICT risk framework within the last year?
- Do you know the date of your last resilience test, and the scheduled date of the next one?
Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.