DORA (Digital Operational Resilience Act)

DORA is the EU regulation that sets ICT risk, incident reporting, resilience testing and ICT third-party rules for financial entities.

The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, sets uniform rules on information and communication technology (ICT) risk for banks, insurers, investment firms, payment and e-money institutions, crypto-asset service providers and most other EU financial entities. It entered into force on 16 January 2023 and has applied since 17 January 2025.

EIOPA's DORA page groups the regulation into six areas:

  • ICT risk management, with the management body accountable for the framework.
  • Classification and reporting of major ICT-related incidents.
  • Digital operational resilience testing, including threat-led penetration testing for the firms that supervisors select.
  • ICT third-party risk management, including a register of information covering every contractual arrangement for ICT services (Article 28(3)), kept in the format set by Implementing Regulation (EU) 2024/2956.
  • Voluntary sharing of cyber threat information between financial entities.
  • An oversight framework under which the European Supervisory Authorities oversee critical ICT third-party service providers directly.

Much of the operational detail sits in regulatory technical standards and implementing standards adopted after the Level 1 text, which is why DORA work did not end on the application date. The subcontracting RTS, Delegated Regulation (EU) 2025/532, only entered into force on 22 July 2025, and our impact assessment template works through it end to end.

For financial entities, DORA's ICT rules apply in place of the equivalent requirements of the NIS2 Directive, so a group with both financial and non-financial entities can face two regimes for the same systems.

This entry is general information, not legal advice.

Sources

  1. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), EUR-Lex accessed 30 Sep 2026
  2. EIOPA, Digital Operational Resilience Act (DORA) accessed 30 Sep 2026
  3. Commission Implementing Regulation (EU) 2024/2956, ITS on the register of information, EUR-Lex accessed 30 Sep 2026

Know which changes apply to your business.

RegWatch reads the regulators you choose and explains every change it surfaces.

Book a demo